Coordinated cyberattacks hit OT systems at more than 30 Minnesota water utilities

More than 30 community water systems in Minnesota were targeted in coordinated cyberattacks that disrupted automated controls at some municipal water and wastewater facilities. Minnesota IT Services said the attacks occurred on July 26 and 27; cities including Maple Plain, Braham, South St. Paul, and Plymouth reported impact to operational technology, with Braham briefly taking its water plant offline after attackers shut down operating controls. Plymouth said affected equipment was connected via cellular communications, and officials have not yet attributed the attacks.
Why it matters: This matters because cyberattacks on water-system controls can affect essential public services even when drinking water remains safe. Water utilities and OT defenders should urgently review remote and cellular-connected equipment, verify contingency plans, and look for signs of unauthorized access or loss of control in SCADA and related systems.

Sources

More than 100 water systems were hit in July cyberattacks
2026.08.26 93% relevant
This article appears to update the same July 2026 campaign against internet-exposed water-sector OT, adding CISA's first nationwide count of more than 100 targeted water systems and clarifying that many attacks involved PLCs connected directly to cellular modems across multiple states beyond Minnesota.
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
Eduard Kovacs 2026.08.26 94% relevant
This is a direct update on the same July 2026 wave of attacks against internet-exposed water and wastewater OT systems, expanding the known scope from Minnesota utilities to more than 100 systems nationwide and adding CISA's attribution details about cellular-modem-connected PLCs and mitigation guidance.
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
2026.08.19 89% relevant
This article ties the late-July Minnesota water utility disruptions to a broader federal alert on ongoing attacks against internet-exposed Siemens S7 PLCs, adding that attackers are using AI-generated scripts plus snap7/python-snap7 to read and write PLC memory, configuration, and ladder logic over S7comm.
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
2026.08.14 61% relevant
The article explicitly references the same Minnesota water-utility attacks and adds national-security commentary that private-sector analysts attribute them to Iran, while noting there is no evidence AI was used in those intrusions.
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Eduard Kovacs 2026.08.10 97% relevant
This article is a direct update on the same late-July water-sector campaign, adding newly confirmed targets in New Jersey and Alabama, noting at least 12 affected states, naming Cape May, Woodbine, and Childersburg utilities, and reiterating that Rockwell Automation ICS devices were targeted with limited operational impact so far.
Water utilities group partners with DEF CON offshoot for Water Watch Center
2026.08.07 73% relevant
This article adds follow-on developments tied to the same water-sector attack wave: it says the campaign has affected water systems in at least 12 states, notes new disclosures from two New Jersey towns, and describes the National Rural Water Association's new Water Watch Center to help small utilities defend against similar OT-targeting attacks.
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
info@thehackernews.com (The Hacker News) 2026.08.06 76% relevant
This article adds follow-on exposure data to the Minnesota water-utility attacks by identifying more than 4,400 internet-exposed Rockwell PLCs and noting that 22 of them were in cities affected by the recent water-sector OT incidents, helping scope likely risk and attack surface.
Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
2026.08.05 96% relevant
This updates the same expanding water-utility OT attack campaign first reported in Minnesota, adding that affected states have grown to at least 12 and naming new incidents in Georgia and South Dakota, along with operational impacts such as boil-water advisories, loss of pressure, and flooding.
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Eduard Kovacs 2026.08.05 97% relevant
This is a direct update on the same multistate water-sector campaign first surfaced through the Minnesota incidents, adding that at least 12 states were reportedly affected, naming Georgia as newly confirmed, and providing FBI details that attackers targeted internet-exposed Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs, causing effects including pressure loss and flooding.
Iran Cyberattacks Against Minnesota Water Systems
Bruce Schneier 2026.08.04 91% relevant
This is another report on the same Minnesota water-utility intrusion campaign, adding preliminary attribution to Iran and noting the activity may extend to at least seven U.S. states, while also indicating no major damage is known so far.
New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems
Mike Lennon 2026.08.04 82% relevant
This article does not report a new intrusion in New York; it adds concrete follow-on impact from the same multistate water-sector campaign by showing New York is allocating $9 million to 153 water and wastewater systems after the Minnesota-led attacks spread to at least seven states and prompted CISA guidance.
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
2026.08.03 93% relevant
This is a direct update on the same water-sector intrusion campaign first confirmed in Minnesota, adding that Georgia and Michigan also saw similar activity, that the FBI now says at least seven states are affected, and that Rockwell Automation/Allen-Bradley PLCs remain the primary observed target.
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Eduard Kovacs 2026.08.03 97% relevant
This article clearly updates the same July 26-27 water-sector campaign, adding that the attacks extended beyond Minnesota to at least six other states, including confirmed activity in Michigan and Rapid City, South Dakota, plus reporting that Georgia was among the targeted states. It also adds defensive context that internet-connected OT equipment using cellular communications may have been the intrusion path and ties the campaign to earlier Iran-linked targeting of water-sector OT.
CISA warns of spike in attacks on water systems as Minnesota incidents probed
2026.07.31 95% relevant
This is a direct update on the same Minnesota water-utility incidents, adding CISA’s public alert, details on attacker behavior (changing PLC passwords and IP addresses to lock out operators), the spread to utilities in at least seven states reported to the FBI, and reporting that investigators are probing possible Iran links.
CISA warns of cyberattacks disrupting U.S. water utilities
Bill Toulas 2026.07.31 95% relevant
This article directly updates the same Minnesota water-utility incident by adding CISA's national warning, describing attacker actions against internet-exposed PLCs such as password changes and IP reconfiguration, and naming Rockwell Automation MicroLogix 1400 recovery guidance plus broader exposure context for Rockwell, Siemens, and Schneider Electric devices.
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Associated Press 2026.07.31 96% relevant
This is the same Minnesota water-utility incident and adds reporting that the attacks hit remote monitoring and control technology, briefly disrupted plants in places including Braham and Plymouth, and are being investigated by the FBI amid broader warnings about Iranian targeting of water and wastewater systems.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
Mike Lennon 2026.07.30 93% relevant
This article directly updates the Minnesota water-utility OT attack story with CISA’s July 30 alert, adding that attackers changed PLC passwords and IP addresses, that boil-water notices and sustained manual operations have resulted in some cases, and that undocumented cellular modems may be part of the exposure path.
Hackers target over 30 Minnesota water utilities in coordinated OT attack
Ionut Ilascu 2026.07.29 99% relevant
This article reports the same underlying event and adds details on timing (July 26-27), state response by Minnesota IT Services, confirmed malicious impact at Braham's water plant, and that affected utilities shifted to manual operations or contingency plans.
Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems
2026.07.29 96% relevant
This article is a direct update on the same Minnesota water-utility incident, adding Tenable's suspicion that the Iran-linked CyberAv3ngers group was responsible and linking the timing to CISA's July 22 warning about Iran-linked PLC-targeting activity.
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
info@thehackernews.com (The Hacker News) 2026.07.29 98% relevant
This article appears to cover the same coordinated attack on Minnesota water systems and adds reporting that one treatment plant was taken offline, reinforcing the scope and operational impact of the incident.
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
Eduard Kovacs 2026.07.29 100% relevant
This article appears to be the first tracked report establishing a specific coordinated attack wave against Minnesota municipal water and wastewater OT systems, with named affected cities and operational impact.
← Back to all stories