A major cyberattack has struck over 30 community water systems in Minnesota, affecting operations on July 26 and 27, 2026. The event prompted a comprehensive cybersecurity response to safeguard essential services across the state.
Impact on Local Water Systems
Communities such as Braham, Plymouth, South St. Paul, and Maple Plain reported disruptions, including communication failures and affected automated controls. Braham experienced a complete shutdown of its water plant, leading to a public request for reduced water usage. Despite cellular issues at water towers and wastewater stations, Plymouth continued manual operations. Meanwhile, South St. Paul and Maple Plain maintained service, with Maple Plain declaring a local emergency to manage the situation.
Statewide Cybersecurity Measures
Minnesota IT Services (MNIT) announced on July 28 that there were no current advisories for residents to alter their water consumption. Although the attack’s perpetrator remains unidentified, MNIT is collaborating with various agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, to contain and investigate the breach. Officials have yet to determine the exact method of access or the extent of compromised systems.
John Israel, MNIT’s assistant commissioner, emphasized the need for a unified government approach to combat cyber threats against critical infrastructure, underscoring the importance of such collaboration in mitigating potential damages.
Connection to Broader Cyber Threats
Coinciding with this incident, U.S. agencies had recently warned of threats from Iranian-linked actors targeting programmable logic controllers from manufacturers like Rockwell Automation, Schneider Electric, and Siemens. Although no direct link between these broader threats and the Minnesota attack has been publicly confirmed, the operational similarities have raised concerns within the cybersecurity community.
While the investigation continues, CISA has issued guidelines to bolster defenses, including the monitoring of cellular modem connections, restricting access to authorized systems, and ensuring the integrity of project files. Operators are advised to verify backups and use physical mode switches only after confirming system integrity.
As of July 29, MNIT’s investigation remains active, with efforts focused on assessing and restoring affected systems. The Hacker News is seeking further clarification from MNIT regarding the scope of the disruptions and the evidence supporting the coordinated nature of the attack.
