Cyberattacks on Minnesota water systems have officials warning about a broader hacker threat

A coordinated cyberattack striking more than 30 municipal water systems across Minnesota has prompted federal authorities to investigate whether Iranian hackers were responsible, as officials warn of an expanding threat to water infrastructure nationwide.

The attack unfolded over two days, beginning on July 26 and continuing through July 27, disrupting operational technology at water and wastewater utilities across the state. Four communities publicly disclosed they were affected: Braham, Plymouth, South St. Paul, and Maple Plain. State officials described it as one of the largest attacks on local water infrastructure in Minnesota’s history.

Minnesota IT Services confirmed the intrusion in a statement Tuesday and immediately activated the state’s cybersecurity incident response capabilities. The affected systems targeted programmable logic controllers, or PLCs, which are devices used to remotely monitor and control water system equipment. Hackers modified passwords to lock out operators and disrupted communications between water towers, treatment plants, and lift stations.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

In Braham, a community of roughly 1,700 people, the attack disabled computerized operating controls and temporarily shut down the city’s well and water treatment plant. Public works crews restored operations within approximately two hours. Plymouth experienced cellular communications failures at two water towers and multiple lift stations but continued operating manually. South St. Paul and Maple Plain also saw automated controls affected but implemented contingency procedures that allowed public works employees to maintain normal water and wastewater services.

Despite the disruptions, no community experienced compromised water quality or safety. The Minnesota Department of Health reported that no municipality asked residents to alter their drinking water use. Officials also found no indication that customer or resident data were accessed.

Intelligence agencies have assessed that Iran was likely responsible for the attack, according to U.S. officials familiar with the investigation. However, state and federal authorities have not made a formal public attribution. Sources cautioned that their assessment remains preliminary and could change as additional technical evidence is collected. Investigators are also considering whether the attackers attempted to appear Iran-based as a way of escalating tensions during the ongoing conflict between the United States and Iran.

The timing of the Minnesota attack proved significant. Four days before the state systems were compromised, the Cybersecurity and Infrastructure Security Agency updated an advisory warning that Iranian-linked attackers were targeting internet-exposed programmable logic controllers across critical infrastructure. Security researchers at Tenable noted the operational pattern is consistent with CyberAv3ngers, a hacker group that the U.S. government has formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

CyberAv3ngers has previously targeted water utilities and other critical infrastructure. The group emerged in late 2023 and initially posed as a hacktivist collective, but subsequent investigation revealed it operates as a state-sponsored actor. The U.S. Treasury Department sanctioned six officials from the Islamic Revolutionary Guard Corps Cyber-Electronic Command in February 2024 for directing the group’s operations. The State Department has offered a $10 million bounty for information on the group’s activities.

On Thursday, July 30, federal agencies issued an urgent warning to water systems nationwide. The FBI, Environmental Protection Agency, and CISA all warned that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities of all sizes. In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding.

CISA urged critical infrastructure owners and operators to remove publicly exposed programmable logic controllers and other operational technology from the internet as soon as possible. The agency noted that hackers have changed passwords to lock out operators and disconnected systems by changing their IP addresses. CISA also recommended that water organizations validate external connections, including cellular modems that may have been installed by operators or vendors but not documented in routine security scans.

The FBI noted in a statement that water and wastewater utility companies in at least seven states have reported incidents to the bureau, with some activity degrading water operations. The wider pattern suggests the Minnesota attack may be part of a broader campaign targeting critical infrastructure across the country.

State and federal authorities activated a coordinated, whole-of-government response. Minnesota IT Services worked alongside CISA, the Environmental Protection Agency, the FBI, and affected utilities to contain the intrusions, share threat intelligence, and remediate damages. Officials emphasized that the rapid, coordinated response enabled agencies to prevent more serious impacts to critical services.

The investigation remained active as of late July, with responders continuing to assess affected systems and collect forensic evidence. Authorities stressed that water operators should implement additional security measures, including restricting controller access to authorized systems, logging cellular modem connections, and inspecting running project files for unauthorized changes. The incident underscores growing vulnerabilities in how small municipal water utilities protect their industrial control systems against state-sponsored cyber threats.

Share this story