Overview
- State officials and the FBI say malicious activity hit operational technology at over 30 community water systems on Sunday and Monday, forcing some plants to switch to backups and manual controls.
- Most intrusions targeted programmable logic controllers and other remote monitoring devices that manage wells and treatment equipment, and some sites lost automated control for short periods.
- Federal and private investigators have provisionally linked the pattern to Iran‑affiliated actors and to tradecraft tied to the group CyberAv3ngers, but officials emphasize attribution is not final and the probe is ongoing.
- There are no confirmed impacts to drinking water quality, and affected cities such as Braham, Plymouth, Maple Plain and South St. Paul restored service using backups and contingency procedures.
- CISA, the FBI and Minnesota IT Services are urging operators to remove internet‑exposed PLCs, check cellular modems and use VPN or gateway access; experts warn small, legacy systems remain highly vulnerable and more incidents could follow.