Skip to content
OtherContained

Coordinated cyberattack disrupts more than 30 Minnesota water systems (2026)

A coordinated intrusion into the operational technology of more than 30 Minnesota municipal water and wastewater utilities forced several communities onto manual controls in late July 2026.

Victim
Minnesota municipal water utilities

Over the weekend of 26–27 July 2026, a coordinated cyberattack struck the operational-technology (OT) systems of more than 30 Minnesota municipal water and wastewater utilities at roughly the same time. By Monday morning, 27 July, city officials across the state began discovering outages and disruptions to the automated controls that run treatment and distribution, and Minnesota IT Services (MNIT) activated a statewide cybersecurity response to support the affected communities.

What happened

The cities of Plymouth, South St. Paul, Maple Plain, and Braham publicly confirmed that they were among the targets; MNIT classified the remaining systems as non-public while the investigation continued. Braham's water plant went offline, prompting the city to ask residents to minimise water use until treatment resumed. Plymouth reported communications problems at two water towers and multiple wastewater lift stations but continued operating manually, while South St. Paul and Maple Plain maintained service after their automated utility controls were affected β€” Maple Plain declaring a local state of emergency to support its response.

Crucially, the utilities reported no confirmed contamination of drinking water: operators fell back to manual control of pumps and treatment while they isolated and assessed the compromised systems. The attack targeted the computerised controls rather than the physical treatment process itself.

Attribution and wider campaign

A preliminary assessment by U.S. investigators suggested that an Iran-nexus actor was probably responsible, while stressing that the judgement was tentative and could change. The Minnesota incident was subsequently linked to a broader campaign affecting utilities across several U.S. states, and the FBI and Environmental Protection Agency issued warnings urging water and wastewater operators nationwide to review the exposure of their OT and remote-access systems.

Why it matters

The Minnesota case is a stark reminder that small municipal utilities β€” often running lean IT teams and internet-exposed industrial controls β€” sit on the front line of critical-infrastructure security. A single coordinated campaign was able to disrupt automated operations across dozens of communities at once, and only manual fallback procedures and rapid state coordination prevented the disruption from reaching customers' taps.

Timeline

  1. A coordinated intrusion begins striking the operational-technology environments of dozens of Minnesota water and wastewater utilities over the weekend.

  2. City officials discover outages and disruptions to automated operating controls; Minnesota IT Services (MNIT) activates a statewide cybersecurity response.

  3. The scale of the campaign β€” more than 30 affected systems β€” becomes public, with several cities confirming they had switched to manual operations.

  4. Federal investigators probe the attack and warn utilities nationwide; preliminary assessments point to a possible Iran-nexus actor while cautioning the attribution could change.

Sources

  1. aljazeera.comhttps://www.aljazeera.com/news/2026/7/30/us-authorities-probe-cyberattack-on-water-systems-in-minnesota
  2. mn.govhttps://mn.gov/mnit/media/blog/?id=38-761869
  3. fox9.comhttps://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack
  4. secureworld.iohttps://www.secureworld.io/industry-news/cyberattack-taps-minnesota-water
  5. tenable.comhttps://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know

Related incidents