


Perceptive Security
SOC/SIEM Consultancy

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
Published:
29 juli 2026 om 13:48:36
Alert date:
29 juli 2026 om 15:01:32
Source:
thehackernews.com
Critical Infrastructure, Mobile & IoT, Network Infrastructure
A coordinated cyberattack struck operational technology (OT) systems at more than 30 Minnesota community water systems on July 26-27, 2026. The attack triggered a statewide cybersecurity response. Braham's water treatment plant went completely offline, prompting city officials to ask residents to minimize water usage. Other affected cities include Plymouth, South St. Paul, and Maple Plain, which reported communications failures and disruptions to automated controls. The incident represents a significant attack on critical public infrastructure affecting multiple municipalities simultaneously. Authorities have not yet publicly attributed the attack to a specific threat actor or group. The coordinated nature of the attack across dozens of systems suggests a sophisticated and possibly well-planned campaign targeting water utility OT environments.
Technical details
A coordinated cyberattack targeted operational technology (OT) at more than 30 Minnesota community water systems on July 26–27, 2026. Affected cities include Braham (water plant went offline), Plymouth (cellular communications failures at water towers and wastewater lift stations), South St. Paul, and Maple Plain (automated utility controls affected). The attack targeted internet-facing programmable logic controllers (PLCs) and human-machine interfaces (HMIs) as well as SCADA systems. Tactics observed in the broader related campaign (linked to Iranian-affiliated actors) included exfiltration and modification of PLC project files, manipulation of data displayed through HMIs and SCADA systems, and disabling of shutdown and alarm logic. Cellular modem communications were also disrupted. The attack pattern and timing are consistent with CyberAv3ngers and IRGC-CEC affiliated tradecraft, though no official attribution has been made. PLC manufacturers targeted in the related advisory include Rockwell Automation, Schneider Electric, and Siemens.
Mitigation steps:
1. Log all cellular modem connections to detect unauthorized access attempts. 2. Restrict controller (PLC/HMI) access to only authorized systems. 3. Inspect running PLC project files for unauthorized changes or modifications. 4. Validate backups before using them for restoration. 5. Where a controller has a physical mode switch, place it in run mode only after validating its project files. 6. Coordinate with CISA, EPA, FBI, and relevant state agencies for threat intelligence sharing and incident response. 7. Follow CISA advisory AA26-097a for sector-wide defensive guidance on internet-facing ICS/OT devices. 8. Minimize internet exposure of PLCs, HMIs, and SCADA systems. 9. Implement network segmentation to isolate OT environments from IT and internet-facing networks. 10. Monitor for unauthorized changes to shutdown and alarm logic in control systems.
Affected products:
Rockwell Automation Programmable Logic Controllers (PLCs)
Schneider Electric Programmable Logic Controllers (PLCs)
Siemens Programmable Logic Controllers (PLCs)
Human-Machine Interface (HMI) systems
SCADA systems
Cellular modem communications systems at water utilities
Related links:
https://brahammn.gov/index.asp?DE=091B3CB2-4CCA-4EEC-85BF-C62DBE73211A&SEC=85B95912-1C4A-4539-8110-1EFC88EE7C31
https://www.plymouthmn.gov/Home/Components/News/News/8977/542
https://www.southstpaulmn.gov/m/newsflash/home/detail/900
https://www.mapleplainmn.gov/administration/page/press-release-cyber-security-incident
https://mn.gov/mnit/media/blog/?id=38-761869
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
https://thehackernews.com/2026/04/iran-linked-hackers-disrupt-us-critical.html
https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know
https://thehackernews.com/2023/11/iranian-hackers-exploit-plcs-in-attack.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
