In a significant cybersecurity incident, over 30 water and wastewater utilities in Minnesota were targeted by a coordinated cyberattack between July 26 and July 27, 2026. This attack disrupted operational technology (OT) systems, specifically affecting computerized operating systems and equipment connected via cellular communications. Fortunately, rapid manual intervention by local officials prevented any impact on water quality or public health, and no service outages were reported. The incident highlights the vulnerabilities faced by small and rural water utilities and underscores the urgent need for enhanced compliance with federal risk assessment and emergency response protocols. The response involved collaboration among state and federal agencies, including the Minnesota Information Technology Services (MNIT), the FBI, CISA, and the EPA. While the attribution of the attack remains unconfirmed, the tactics employed are consistent with those used by Iranian-linked groups such as CyberAv3ngers, as noted in recent advisories.
Technical Overview of the Attack
The cyberattack specifically targeted OT environments, exploiting internet-accessible devices at water towers and lift stations. The initial access vector aligns with the MITRE ATT&CK technique T0883: Internet Accessible Device. Unlike many cyber incidents, there was no evidence of phishing, ransomware, or data theft; the primary goal appeared to be the disruption of OT operations.
Temporary equipment malfunctions were reported, necessitating affected utilities to disconnect compromised systems and revert to manual operations. For instance, in Braham, the water plant was offline for less than two hours, while in Plymouth, manual intervention ensured that water service remained uninterrupted. Similar disruptions were noted in other communities, including Maple Plain and South St. Paul.
Despite the severity of the attack, no specific malware or tools have been publicly identified. There were no ransom demands or indications of data exfiltration. Although CISA advisories have raised concerns about the risks to programmable logic controllers (PLCs), there is no confirmation that PLCs were compromised during this incident.
Vulnerabilities and Compliance Issues
This incident underscores the vulnerabilities inherent in small and rural water utilities, which often lack the resources necessary for robust cybersecurity measures. The EPA has previously indicated that over 70% of water systems fail to meet federal requirements for risk assessments and emergency response plans. Fortunately, the rapid manual intervention and backup procedures in place prevented any service outages or water quality issues.
While the attribution of the attack remains uncertain, the observed tactics and techniques are consistent with those employed by Iranian-linked groups like CyberAv3ngers, which have a history of targeting critical infrastructure sectors, including water and energy. Recent advisories from CISA and the FBI have specifically warned about the targeting of internet-connected OT devices in U.S. water utilities.
Recommendations for Mitigation
In light of this incident, several critical recommendations have emerged for water utilities:
- Immediately disconnect internet-exposed OT devices, particularly those connected via cellular communications, from public networks.
- Implement network segmentation to isolate OT systems from IT networks and the internet.
- Regularly update and patch OT systems and equipment to address known vulnerabilities.
- Conduct comprehensive risk assessments and update emergency response plans in compliance with federal requirements.
- Ensure manual operation capabilities and conduct regular cyber drills to test response procedures.
- Share threat intelligence with state and federal agencies and participate in sector-specific information sharing and analysis centers (ISACs).
- Review and implement guidance from CISA, EPA, and other relevant agencies to strengthen defenses against future attacks.
Conclusion
The coordinated cyberattack on Minnesota’s water utilities serves as a stark reminder of the vulnerabilities faced by critical infrastructure sectors. While no major health impacts were documented, the potential for disruption to public health systems remains significant. The incident emphasizes the urgent need for improved compliance with federal risk assessment and emergency response requirements, as well as the importance of regular cyber drills and manual operation capabilities.
For further details, refer to the comprehensive analysis by Rescana.


