top of page
perceptive_background_267k.jpg

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Published:

29 July 2026 at 14:55:57

Alert date:

29 July 2026 at 15:01:32

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Critical Infrastructure, Network Infrastructure, Mobile & IoT

Hackers launched a coordinated cyberattack targeting more than 30 community water systems across Minnesota. The Minnesota IT Services (MNIT) agency activated its full cybersecurity incident response capabilities in response to the attack. The attack focused on operational technology (OT) systems used by water utilities. The scale and coordination of the attack prompted a statewide response. This incident highlights the ongoing vulnerability of critical water infrastructure to cyber threats. The attack affected community-level water systems, raising concerns about public safety and service continuity. MNIT's involvement suggests state-level coordination is required to manage the incident effectively.

Technical details

On July 26-27, 2025, unknown hackers conducted a coordinated cyberattack targeting operational technology (OT) systems at more than 30 community water utilities across Minnesota. The City of Braham reported its water plant went offline due to a malicious cyber-attack on computerized operating systems. The plant was restored within approximately three hours. Other affected communities reported temporary equipment malfunctions and switched to manual operations or contingency plans to maintain services. MNIT activated its cybersecurity incident response capabilities statewide. The attack vector and threat actor remain unidentified. The incident bears similarities to prior attacks by Iranian-linked cyber actors who exploited exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) in critical infrastructure since March of the same year, though no direct attribution has been made. CISA issued guidance titled 'CI Fortify – Advice for isolating vital systems' recommending isolation of key OT systems during cyberattacks, co-authored with the Australian Signals Directorate's ACSC, the FBI, and international partners.

Mitigation steps:

1. Activate cybersecurity incident response capabilities and coordinate with federal, state, local, Tribal, and private-sector partners. 2. Isolate key OT systems from IT networks to ensure continuity of critical services during a cyberattack, per CISA's 'CI Fortify – Advice for isolating vital systems' guidance. 3. Switch to manual operations or implement contingency plans if automated systems are compromised. 4. Share threat intelligence with MNIT and relevant agencies for situational awareness. 5. Review and secure internet-exposed PLCs, particularly Rockwell Automation/Allen-Bradley devices, by restricting remote access and applying vendor patches. 6. Implement network segmentation between IT and OT environments. 7. Monitor OT systems for unauthorized access or anomalous behavior. 8. Follow CISA guidance for critical infrastructure protection and engage with CISA for incident response support. 9. Ensure water safety monitoring continues via manual processes if automated systems are offline.

Affected products:

Operational Technology (OT) systems at Minnesota community water utilities
Rockwell Automation / Allen-Bradley Programmable Logic Controllers (PLCs) - referenced in related Iranian actor advisory

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page