Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities – Incident Analysis and Response Recommendations

Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities – Incident Analysis and Response Recommendations

Executive Summary

Between July 26 and July 27, 2026, more than 30 water and wastewater utilities across Minnesota experienced a coordinated cyberattack targeting their operational technology (OT) systems. The attacks caused temporary disruptions to computerized operating systems and equipment connected via cellular communications at water towers and lift stations. Rapid manual intervention and backup procedures by local officials ensured that water quality and public health were not impacted, and no service outages occurred. No evidence of data theft, ransom demands, or compromise of programmable logic controllers (PLCs) has been reported. The incident underscores the vulnerability of small and rural water utilities to cyber threats and highlights the need for improved compliance with federal risk assessment and emergency response requirements. State and federal agencies, including Minnesota Information Technology Services (MNIT), the FBI, CISA, and the EPA, coordinated a whole-of-government response. While attribution remains unconfirmed, the tactics, techniques, and procedures (TTPs) are consistent with those used by Iranian-linked groups such as CyberAv3ngers, as noted in recent federal advisories.

Technical Information

The coordinated cyberattack on Minnesota’s water utilities targeted OT environments, specifically computerized operating systems and equipment connected via cellular communications at water towers and lift stations. The initial access vector is consistent with exploitation of internet-accessible OT devices, a technique documented as MITRE ATT&CK for ICS T0883: Internet Accessible Device (https://attack.mitre.org/techniques/T0883/). There is no evidence of phishing, ransomware, or data theft; the focus was on disruption of OT operations.

The attacks caused temporary equipment malfunctions, requiring affected utilities to disconnect compromised equipment from networks and switch to manual operations. In the City of Braham, the water plant was offline for under two hours before being restored. In Plymouth, the attack was limited to equipment connected via cellular communications, and manual intervention ensured uninterrupted water service. Similar issues were reported in other communities, including Maple Plain and South St. Paul.

No specific malware or tool has been publicly identified in this incident. There were no ransom demands or indications of data exfiltration. While CISA advisories have warned of the risk to programmable logic controllers (PLCs), there is no confirmation that PLCs were compromised in this event (https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a).

The attack methods align with several MITRE ATT&CK for ICS techniques: - T0883: Internet Accessible Device – Adversaries gain access to industrial environments through systems exposed directly to the internet. - T0813: Impair Process Control – Disruption of water plant operations, causing systems to go offline. - T0809: Inhibit System Recovery – Temporary equipment malfunctions and manual intervention required to restore operations.

The incident highlights the vulnerability of small and rural water utilities, which often lack resources for robust cybersecurity. The EPA has previously warned that over 70% of water systems were failing to comply with federal requirements for risk assessments and emergency response plans. The attacks did not result in service outages or water quality issues due to rapid manual intervention and backup procedures.

Attribution remains unconfirmed. However, the TTPs observed are consistent with those used by Iranian-linked groups such as CyberAv3ngers (MITRE Group G1027: https://attack.mitre.org/groups/G1027/), which have a documented history of targeting water and energy sectors. Recent CISA and FBI advisories specifically warned of Iranian-linked groups targeting internet-connected OT devices in U.S. water utilities.

No major downstream health impacts have been documented in this or previous attacks, but the potential for disruption to hospitals and public health is significant. The event underscores the need for improved compliance with federal risk assessment and emergency response requirements, as well as the importance of regular cyber drills and manual operation capabilities.

Affected Versions & Timeline

The attacks occurred on Sunday and Monday, July 26-27, 2026. State and local officials began reporting and responding to incidents on Monday, July 27, 2026, with a statewide response and public disclosure on Tuesday, July 28, 2026. The attacks targeted OT systems, specifically computerized operating systems and equipment connected via cellular communications at water towers and lift stations. No specific software versions or vendors have been publicly identified as affected. The focus was on disruption of OT operations, with no evidence of data theft, ransom demands, or compromise of PLCs.

Threat Activity

The threat activity involved coordinated attacks on more than 30 water and wastewater utilities across Minnesota, targeting OT systems and equipment connected via cellular communications. The attacks caused temporary equipment malfunctions, requiring manual intervention and backup procedures to restore operations. No evidence of data theft, ransom demands, or compromise of PLCs has been reported. The TTPs observed are consistent with those used by Iranian-linked groups such as CyberAv3ngers, which have a documented history of targeting water and energy sectors. Recent CISA and FBI advisories specifically warned of Iranian-linked groups targeting internet-connected OT devices in U.S. water utilities. Attribution remains unconfirmed, but the pattern of activity aligns with known operations of these groups.

Mitigation & Workarounds

Critical recommendations include immediately disconnecting internet-exposed OT devices, especially those connected via cellular communications, from public networks. Utilities should implement network segmentation to isolate OT systems from IT networks and the internet. Regularly update and patch OT systems and equipment to address known vulnerabilities. Conduct comprehensive risk assessments and update emergency response plans in compliance with federal requirements. Ensure manual operation capabilities and conduct regular cyber drills to test response procedures. Share threat intelligence with state and federal agencies and participate in sector-specific information sharing and analysis centers (ISACs). Review and implement guidance from CISA, EPA, and other relevant agencies to strengthen defenses against future attacks.

Indicators of Compromise

No public indicators of compromise were available at the time of writing.

References

StateScoop: https://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

ABC News: https://abcnews.com/US/minnesota-water-systems-hit-cyberattack-state-officials/story?id=135166078

KSTP: https://kstp.com/kstp-news/top-news/state-more-than-30-water-systems-targeted-in-cyberattack/

MITRE ATT&CK Group G1027 (CyberAv3ngers): https://attack.mitre.org/groups/G1027/

MITRE ATT&CK Technique T0883 (Internet Accessible Device): https://attack.mitre.org/techniques/T0883/

MITRE ATT&CK Technique T0813 (Impair Process Control): https://attack.mitre.org/techniques/T0813/

MITRE ATT&CK Technique T0809 (Inhibit System Recovery): https://attack.mitre.org/techniques/T0809/

CISA Advisory AA26-097A: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

IC3 Advisory: https://www.ic3.gov/CSA/2026/260407.pdf

Tenable FAQ on CyberAv3ngers: https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure

LinkedIn Analysis: https://www.linkedin.com/pulse/iran-backed-cyberav3ngers-sets-sights-water-industrial-vlfyc

OWASP Frankfurt: https://owasp.org/www-chapter-frankfurt/assets/slides/72_OWASP_Frankfurt_Chapter_Meeting_1.pdf

About Rescana

Rescana’s Third-Party Risk Management (TPRM) platform enables organizations to continuously monitor and assess the cyber risk posture of their critical suppliers and partners. Our platform provides actionable insights into supply chain vulnerabilities, supports compliance with regulatory requirements, and facilitates rapid response to emerging threats in operational technology environments. For questions or further information, contact us at info@rescana.com.