Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. The attack caused a plant outage, communications failures, or affected automated controls in sever…
Intelligence analysis by Llama

A coordinated cyberattack targeted Minnesota's community water systems, causing a plant outage, communications failures, or affected automated controls in several cities. The state's cybersecurity response is ongoing.
Imagine a group of hackers trying to break into a water treatment plant's computer system. They were able to get in and cause problems, like making the plant shut down or making it hard for the workers to communicate. This is like a big game of 'hack the water plant' and it's not good for anyone.
Analysis
A Coordinated Attack on Minnesota's Water Systems
The recent cyberattack on Minnesota's community water systems has sent shockwaves across the state. On July 26 and 27, a coordinated attack targeted operational technology at more than 30 water systems, triggering a statewide cybersecurity response. The attack caused a plant outage, communications failures, or affected automated controls in several cities, including Braham, Plymouth, South St. Paul, and Maple Plain.
The investigation is still ongoing, but officials have confirmed that the incidents shared common characteristics, including their timing, methods of access, and the type of infrastructure targeted. Those similarities supported the state's description of the activity as coordinated. The agency said the similarities were consistent with activity observed by federal partners in other states and industries, but investigators could not yet determine whether a single actor was responsible for all the incidents.
The Investigation Continues
The investigation is still active, and responders are continuing to assess affected systems. Officials have not publicly identified the attacker, affected products, exploited vulnerability, or whether data was stolen. However, they have confirmed that the incidents shared common characteristics, including their timing, methods of access, and the type of infrastructure targeted.
A Warning from U.S. Agencies
Four days before the Minnesota attacks, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens, and potentially other manufacturers. Investigators in that campaign observed attackers exfiltrate and modify project files, manipulate data shown through human-machine interfaces and supervisory control and data acquisition systems, and disable shutdown and alarm logic.
Connection to the CyberAv3ngers Threat Ecosystem
Tenable said the timing and operational pattern were consistent with the broader CyberAv3ngers threat ecosystem, while noting that the incident has not been officially attributed. Scott Caveza, senior staff research engineer at Tenable, told The Hacker News that while MNIT did not provide attribution, these tactics remain consistent with the tradecraft attributed to CyberAv3ngers and other IRGC-CEC affiliated groups, who have been known to target critical infrastructure since at least 2023.
A Call to Action
The cyberattack on Minnesota's community water systems highlights the vulnerability of critical infrastructure to cyber threats. It also underscores the need for a coordinated response to such incidents. As officials continue to investigate and respond to the attack, it is essential to remember the importance of cybersecurity in protecting our critical infrastructure.
Key points
- A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27.
- The attack caused a plant outage, communications failures, or affected automated controls in several cities.
- The investigation is still ongoing, but officials have confirmed that the incidents shared common characteristics.
- The agency said the similarities were consistent with activity observed by federal partners in other states and industries.
- U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens, and potentially other manufacturers.
The investigation into the cyberattack on Minnesota's community water systems is ongoing, and officials are working to contain the incident and prevent further impacts. If the investigation is successful in identifying the attacker and their methods, it could lead to improved cybersecurity measures for critical infrastructure and a safer water supply for the state's residents.
The cyberattack on Minnesota's community water systems highlights the vulnerability of critical infrastructure to cyber threats. If the attackers are not caught and brought to justice, it could lead to further attacks on other critical infrastructure, putting the state's residents at risk of a compromised water supply.



