More than 30 community water systems across Minnesota were hit by a coordinated cyberattack in late July, disrupting digital controls for pumps, wells, towers and wastewater facilities, according to state officials.[12][7][4] Minnesota IT Services said the incident on July 26–27 targeted technology at community water systems statewide, describing it as a “coordinated cyberattack” on operational technology rather than a traditional IT ransomware event.[12][9][13] The disruptions temporarily affected service in at least several towns, including Braham, Plymouth, South St. Paul and Maple Plain, though water service was restored within hours and there were no immediate reports of compromised water quality.[9][4][8]
Federal and state authorities have not publicly confirmed who carried out the attack, but multiple U.S. officials told reporters they are examining a potential link to Iran or hackers associated with the country.[1][5][11] A report citing unnamed officials described the Minnesota incident as one of the most significant suspected Iranian cyber operations against U.S. water infrastructure to date, while stressing that attribution remains preliminary and subject to further technical analysis.[1][2][6] Officials have also noted that the attack appears focused on disruption rather than financial gain, a pattern consistent with earlier Iran‑linked campaigns against local utilities.[1][12]
Security researchers at Tenable said the tactics used in Minnesota align with previous activity by CyberAv3ngers, a faux hacktivist group formally tied to Iran’s Islamic Revolutionary Guard Corps Cyber‑Electronic Command.[3][9][15] The group has been associated with earlier operations against U.S. water authorities, including attacks that sought to manipulate industrial controllers rather than encrypt or steal data.[9][15] Neither Tenable nor government agencies have attributed the Minnesota attack definitively, but analysts note that the absence of any ransom demand and the focus on operational disruption mirror past Iran‑linked targeting of American water systems.[1][3][12]
The Minnesota attack came just days after the FBI, the Cybersecurity and Infrastructure Security Agency (CISA) and other agencies updated an advisory urgently warning that Iranian hacking groups were targeting internet‑connected operational technology devices, including programmable logic controllers used in the water and wastewater sector.[9][10][13] CISA’s April advisory AA26‑097A detailed how Iranian‑affiliated actors had been exploiting exposed Rockwell Automation and Allen‑Bradley PLCs to disrupt operations in government services, water and wastewater, and energy sectors, underscoring the systemic risk posed by insecure OT assets.[9][13] That guidance urged operators to identify any internet‑accessible control systems and either remove direct exposure or implement strong authentication and monitoring for remote access.[9][13]
Iran‑linked actors have previously gone after U.S. water utilities by abusing hard‑coded credentials and missing authentication on critical functions, weaknesses that remain widespread across industrial control products.[15] In late 2023, CyberAv3ngers exploited CVE‑2023‑6448 in Unitronics Vision PLCs—an issue involving default passwords—to compromise the Aliquippa water authority and other facilities, an episode now seen as a precursor to the current wave of targeting.[15] Investigators have not yet publicly identified any specific vulnerabilities or CVE associated with the Minnesota incident, leaving unanswered whether the attackers abused known flaws or exploited misconfigurations in local utilities’ environments.[9][12]
For defenders, the Minnesota attacks highlight how even small community utilities can be drawn into geopolitical cyber campaigns and suffer real‑world disruption when OT systems are left exposed and poorly secured.[9][12][15] Security agencies and researchers are urging water providers to inventory and segment operational technology networks, remove PLCs and other control devices from direct internet access, change default passwords, and apply vendor patches and firmware updates aligned with recent CISA guidance.[9][13][10] Until attribution is confirmed and technical details emerge, the incident stands as a stark warning that critical infrastructure operators cannot rely on obscurity or size to shield them from nation‑state cyber operations.[12][1][6]
