A coordinated cyberattack disrupted water and wastewater utilities in more than 30 Minnesota communities, prompting a multiagency response from Minnesota Information Technology Services and federal partners including CISA, the EPA, and the FBI. A restricted WaterISAC TLP:AMBER notification said the Minnesota Fusion Center reported ongoing malicious cyber activity affecting Minnesota water utilities, indicating the incident was active enough to warrant limited-sector sharing.
Local impacts included Braham’s water plant going offline and Plymouth isolating affected equipment connected to two water towers and several lift stations as responders worked on containment, investigation, remediation, and threat-intelligence sharing. Officials said water quality remained safe, and no public attribution has been announced, though the incident comes amid broader federal concern over attacks on internet-connected operational technology in under-resourced U.S. water systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
An operational technology industry coalition called for a stronger U.S. federal response after suspected Iran-linked intrusions affected more than 30 Minnesota water utilities. The group urged CISA to issue a Binding Operational Directive for federal civilian OT systems and asked Congress to renew cybersecurity grant and information-sharing programs.
On 2026-07-30, the FBI and EPA issued Alert I-073026-PSA warning that malicious actors were targeting internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in the water and wastewater sector. The agencies said utilities in at least seven U.S. states had reported incidents to the FBI since 2026-07-27, with some attacks degrading operations through password and IP changes, modified project files, pressure loss, and flooding.
On 2026-07-30, CISA urged water and wastewater operators to secure internet-exposed PLCs and other OT assets after coordinated attacks disrupted automated controls at more than 30 Minnesota community water systems. The agency said it is seeing increased PLC targeting in the water sector, including password changes and IP address alterations that can lock out operators or disconnect controllers, and recommended measures such as removing public exposure and maintaining clean backups.
By 2026-07-30 reporting, four cities had publicly acknowledged impact from the coordinated Minnesota water utility cyberattack: Braham, Plymouth, South St. Paul, and Maple Plain. South St. Paul and Maple Plain were newly identified affected communities beyond those previously named publicly.
On 2026-07-29, Tenable said the coordinated cyberattacks that disrupted more than 30 Minnesota community water systems appeared consistent with activity by the Iran-linked group CyberAv3ngers. Minnesota and federal officials had not formally attributed the incident at that time.
The Minnesota Fusion Center reported ongoing malicious cyber activity impacting Minnesota water utilities in a WaterISAC notification marked TLP:AMBER. The available reference metadata does not disclose technical details, attribution, or specific affected utilities.
Reporting published on 2026-07-31 said the coordinated cyberattacks against more than 30 Minnesota community water systems on July 26 and July 27 locked out operators, disrupted plants, and prompted boil-water notices, while water delivery continued normally. This adds a new publicly reported impact detail beyond earlier accounts that said water quality remained safe.
A coordinated cyberattack disrupted water and wastewater utilities in more than 30 Minnesota communities on Sunday and Monday. Reported impacts included Braham’s water plant going offline and Plymouth isolating affected equipment tied to two water towers and multiple lift stations, while officials said water quality remained safe.
On 2026-07-22, CISA updated Advisory AA26-097A to expand observed targeting beyond Rockwell Automation to Schneider Electric and Siemens PLCs. The update also added evidence of PLC project file exfiltration and manipulation of Add-On Instructions that could disable safety and alarm functions.
Minnesota Information Technology Services said it is assisting affected utilities with containment, investigation, remediation, and threat intelligence sharing. Federal partners including CISA, the EPA, and the FBI are also involved in the response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
39 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcenextgov.com
Open sourcecyberscoop.com
Open sourcewaterisac.org
Open sourcecisa.gov
Open sourceplymouthmn.gov
Open sourceic3.gov
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.