ctipilot.ch

Minnesota coordinated water-utility OT cyberattack (July 2026)

incident · incident:minnesota-water-utilities-coordinated-cyberattack-2026-07

Coordinated cyberattack over 26-27 July 2026 that Minnesota IT Services announced had disrupted water and wastewater utilities in more than 30 communities, affecting programmable logic controllers and cellular-connected equipment at water towers and lift stations. Plymouth disconnected affected cellular equipment from its network; Braham's water plant went offline and the city briefly asked residents to minimise use on tank level; South St. Paul reported impact to certain automated controls. No source reports impact to drinking-water safety or treatment quality. No named authority has attributed the attack to any actor — the affected city says unknown actors, and the Center for Internet Security states it has not been attributed and that it is unclear whether the internet-exposed PLC vector of joint advisory AA26-097A was involved (StateScoop, Cybersecurity Dive, 2026-07-28).

Coverage timeline
1
first 2026-07-29 → last 2026-07-29
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Tags

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Persistence TA0003

T1133External Remote Services×1

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Impact TA0040

T1565Data Manipulation×1

Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.

Evidence: 2026-07-29/minnesota-30-water-utilities-coordinated-ot-attack · ATT&CK page ↗

Story timeline

  1. 2026-07-29Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities — no authority has attributed it
    active-threatsMinnesota confirms a coordinated attack on field OT at more than 30 community water systems, days after a US advisory update on internet-exposed PLCs

Where this entity is cited

  • active-threats1

Source distribution

  • cisa.gov1 (33%)
  • cybersecuritydive.com1 (33%)
  • statescoop.com1 (33%)

explore in graph

Entries about Minnesota coordinated water-utility OT cyberattack (July 2026) (1)

2026-07-29 · view entry permalink →

HIGHNATOB1

Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities — no authority has attributed it

The confirmed facts are narrow and worth stating precisely. Minnesota's technology bureau announced on 2026-07-28 that more than 30 communities had their water and wastewater utilities disrupted by a coordinated cyberattack on 26 and 27 July (StateScoop, 2026-07-28), a two-day event rather than a single-utility incident (Cybersecurity Dive, 2026-07-28). Where individual utilities described impact, it fell on field equipment rather than treatment processes: Plymouth stated the attack was limited to equipment connected via cellular communications at two water towers and multiple lift stations, and disconnected that equipment from the network to stop the attack and avoid retargeting during reconfiguration; Braham's water plant went offline, and the city later stated the outage was the result of a malicious cyberattack of computerised operating systems by unknown actors (StateScoop, 2026-07-28). Braham did ask residents to minimise water use while its tower held a limited quantity, and a later notice reported the plant back online (StateScoop, 2026-07-28) — a real if temporary consumption instruction. Separately, authorities in South St. Paul said they identified a cyberattack on Monday that impacted certain automated controls, and after implementing contingency procedures confirmed no major impact to drinking and wastewater treatment operations (Cybersecurity Dive, 2026-07-28). Multiple utilities stated water remained safe and no treatment-quality impact has been reported. Minnesota IT Services coordinated a response alongside the FBI, CISA and the EPA, with its chief information security officer describing a whole-of-government response that helped prevent more serious impacts (StateScoop, 2026-07-28).

What is not established matters as much. No authority has named an actor. The Center for Internet Security's senior director of threat intelligence stated the Minnesota attacks have not yet been attributed to any particular party and that it is unclear whether the programmable logic controllers CISA had warned about were involved, and separately noted that of the nation-state attacks on US water facilities in recent years, none has documented major downstream health impacts (StateScoop, 2026-07-28). The FBI confirmed only that it is aware and in contact with victims (Cybersecurity Dive, 2026-07-28). The reason Iran appears in coverage of this event is timing: the attack landed days after federal officials warned of state-linked groups targeting a wider set of industrial devices (Cybersecurity Dive, 2026-07-28) — a juxtaposition, not a finding. Treating it as attribution would be reading the calendar as evidence.

The transferable content sits in that separate advisory, and it is why this belongs in front of European water and energy operators despite the victims being American. AA26-097A documents actors using leased third-party infrastructure and the vendors' own engineering software — Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, Siemens TIA Portal — to reach misconfigured, internet-facing controllers and pull down device project files, then re-upload files with modified or deleted logic (CISA and partners, 2026-07-22). At one victim the FBI observed a malicious project file downloaded to a PLC that retained ladder logic for downstream function but added logic overriding the instruction sets responsible for maintaining safe operating parameters, and the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators (CISA and partners, 2026-07-22). CISA is explicit that this represents no new vulnerability in the named products — it is opportunistic targeting of misconfiguration. The affected controller families are the same Rockwell, Schneider and Siemens lines that run European water, wastewater and district-energy plants, and in one instance access came through Dropbear SSH on a victim's modem, which is precisely the class of device Plymouth found affected.

Triage: engineering software connecting to a PLC and writing a project file is exactly what commissioning and maintenance look like, so the activity class is not the signal. The discriminators the advisory's own mechanics supply are provenance and timing: a project-file write originating from outside the engineering network or from leased hosting rather than an engineering workstation; a controller left in program or remote mode outside a change window rather than in RUN; and a logic change with no corresponding maintenance record. On the network side, protocol functions that modify programs or change controller mode are the ones to surface — connection attempts to controller-associated ports are ubiquitous background noise, whereas a mode change or program write is a discrete, auditable act.

Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim's environment.

the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.

CISA, FBI, NSA, EPA, DOE, CNMF and Treasury (joint advisory AA26-097A) 2026-07-22

The two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices.

Cybersecurity Dive 2026-07-28

Builds on: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion

incident29 Jul 05:45Zmulti-sourceOpen finding ↗