Threat Intelligence

Coordinated OT Attacks Strike Over 30 Minnesota Water Utilities 

Coordinated OT Attacks Strike Over 30 Minnesota Water Utilities 

On July 26 and 27, 2026, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water and wastewater utilities across Minnesota. Attackers disrupted automated control functions, forcing some plants to switch to manual operations and briefly shutting down at least one water treatment facility. The attack comes just days after the U.S. and Australian governments released new CI Fortify guidance urging critical infrastructure operators to prepare isolation plans for vital OT systems. No group has formally claimed responsibility, but state and federal investigators are assessing potential links to Iran-aligned threat actors previously observed targeting industrial control systems. 

The Attack: What Happened 

According to Minnesota IT Services (MNIT), the coordinated intrusions targeted over 30 community water systems across the state over the weekend of July 26 and 27. Statements from affected cities including Maple Plain, Braham, South St. Paul, and Plymouth confirm that “automated control functions” at water and wastewater facilities were disrupted. 

The City of Braham briefly took its water plant offline after detecting the intrusion, urging residents to minimize water use. Officials there reported that “attackers shut down the operating controls, which shut down the well and water treatment plant.” In Plymouth, the impact was described as “limited to equipment connected via cellular communications within the system.” 

In many cases, contingency procedures kept water and wastewater operations running, and all affected cities stressed that drinking water remains safe. However, the coordinated nature of the attack and its focus on OT control systems marks an escalation in targeting of U.S. critical infrastructure. 

The Attack Vector: Cellular-Backhauled SCADA 

Industry experts immediately noted the significance of Plymouth’s disclosure that the incident was limited to equipment connected via cellular communications. Denis Calderone, CTO of Suzu Labs, commented, “Water towers, lift stations, pump stations  these remote assets often connect back to the SCADA system over cellular modems. Secondary and alternative comm links are often overlooked when doing risk and vulnerability analysis.”

Calderone noted that SCADA and industrial control networks are frequently built out by integrators, increasing the chance that cellular communication paths are overlooked during vulnerability assessments. The Braham city administrator is now requesting a re-evaluation of their system vulnerability study, a study Calderone suspects never included those cellular paths in the first place. 

This exploitation pattern has historical precedent. In the 2020 attacks targeting Israeli water facilities, threat actors linked to the Iranian government exploited vulnerable cellular routers as a point of entry into SCADA networks. 

The Attribution Question 

No group has formally claimed responsibility, and officials have stated that formal attribution has not been made. However, the attack comes shortly after the U.S. government warned critical infrastructure organizations about Iran-linked attacks targeting industrial control systems from Siemens, Rockwell Automation, and Schneider Electric. 

Iranian threat groups such as CyberAv3ngers and Handala would fit the profile. CyberAv3ngers has previously targeted Israeli water infrastructure and U.S. OT systems, while Handala (also known as Imperial Kitten or TA456) has conducted disruptive operations against transportation and manufacturing sectors. 

Attribution in OT attacks is inherently difficult. The operational constraints of critical infrastructure — limited logging, segmented networks, reliance on proprietary protocols — make forensic tracing challenging. The absence of a claim does not rule out state-sponsored actors who often prefer deniability. 

CI Fortify: Guidance That Arrived Days After the Attack 

On July 28, mere days after the Minnesota attacks began, the CISA, the FBI, the Australian Signals Directorate’s ACSC, and international partners released new guidance titled “CI Fortify: Advice for isolating vital systems.” The guidance urges critical infrastructure operators to prepare plans for disconnecting critical OT systems from corporate and internet-facing networks during cyberattacks. 

Key recommendations include:

  • Identify minimum systems and networks required to deliver critical services 
  • Document every connection between OT and corporate networks, remote access services, cloud environments, vendors 
  • Determine predetermined isolation points where connectivity can be physically disconnected 
  • Test complete isolation of vital systems regularly, not just individual systems 
  • Maintain secure offline copies of isolation plans 
  • Plan for post-isolation operations: manual processes, reduced monitoring, delayed security updates 

The key insight from CI Fortify is that physical isolation of vital OT systems provides the most effective protection. However, isolation introduces risks: systems fall behind on patches, monitoring degrades, and removable media usage increases. Organizations must prepare not only to disconnect, but to operate and monitor manually until safe reconnection. 

Broader Context: OT Under Siege 

The Minnesota attacks did not occur in isolation. Water infrastructure has been a persistent target: 

  • October 2024: American Water (serving 14M+ people) deactivated systems following a cyberattack 
  • 2024: Kansas water treatment facility switched to manual operations after compromise 
  • 2020: Iranian-linked group exploited cellular routers to attack Israeli water facilities 
  • Pro-Russian hacktivists have actively scanned for unsecured OT systems at water facilities 
  • Chinese state-sponsored Volt Typhoon remained undetected in a critical infrastructure network for five years  positioning for disruptive attacks 

The convergence is unmistakable: state-sponsored actors are building access, hacktivists are scanning for weaknesses, and the attack surface expands as OT systems adopt IP-based and cellular connectivity. 

Analysis: What Defenders Should Do 

  1. Audit secondary communication paths immediately. Cellular modems, radio links, and backup WAN connections to SCADA equipment are often unaccounted for in risk assessments. Inventory every communication path to remote assets. 
  2. Build and test isolation plans now. CI Fortify provides a framework. Implement it before an incident. Test complete isolation, not just individual systems, to uncover hidden dependencies.
  3. Assume cellular-connected OT is compromised. Cellular modems on lift stations, pump houses, and water towers are soft targets. Treat them as untrusted. Segment, monitor, and apply least-privilege access controls. 
  4. Maintain manual operational capability. If automated controls fail, can your team operate the plant manually? Train for it. Document procedures. Keep schematics and runbooks offline.
  5. Collaborate across the sector. As Seemant Sehgal (founder and CEO of BreachLock) noted, investigators must find the common thread because the same vulnerability “almost certainly exists in water infrastructure well beyond Minnesota.” Share indicators! 

AOG ANALYST COMMENT 

The Minnesota water utility attacks are the kind of incident the OT security community has been warning about for a decade: coordinated, multi-target, and exploiting secondary communication paths that fall outside traditional perimeter defense. The fact that the CI Fortify guidance was released after the attacks began, not before, is telling. Policy is reactive. Threat actors are proactive. The cellular-backhauled SCADA design pattern that enabled these intrusions is widespread  across water, energy, and transportation. The question is not whether a similar attack will succeed elsewhere, but how many other OT networks share the same architectural blind spot. 

Sources: 

  • SecurityWeek  Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks](https://www.securityweek.com/dozens-of-minnesota-water-utilities-targeted-in-coordinated-ot-attacks/ 
  • BleepingComputer  CISA shares advice on isolating vital systems during cyberattacks](https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/ 
  • CISA/FBI/ACSC  CI Fortify: Advice for isolating vital systems](https://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systems 
  • City of Braham  Incident statement (27 Jul 2026) 
  • City of Plymouth  Incident statement (27 Jul 2026) 
  • MNIT  Minnesota IT Services coordination notice (28 Jul 2026)