Overview
- Minnesota IT Services says the intrusion targeted operational-technology systems that run pumps, wells and treatment controls at more than 30 community water utilities on July 26 and 27.
- State and federal teams including MNIT, the FBI and the Minnesota Bureau of Criminal Apprehension have opened an active investigation to contain the incident and assess affected systems.
- Officials and security firms report patterns consistent with Iran-linked activity, notably tactics linked to the group called CyberAv3ngers, but formal attribution remains provisional and under review.
- No confirmed impacts to water quality or public boil orders have been reported and many utilities kept service by switching to manual controls or disconnecting exposed devices, though Braham’s automated controls were disabled for about two hours and Maple Plain briefly declared an emergency.
- The attacks expose common weaknesses at small utilities—internet-exposed PLCs, cellular-connected controllers and use of consumer remote-access tools—and have prompted CISA guidance urging operators to isolate OT systems and shore up recovery planning as states weigh funding and staffing needs.