More than 30 municipal water and wastewater systems across Minnesota lost automated control of their treatment processes on July 26 and 27, forcing staff onto manual operation, in what state officials have described as a coordinated cyberattack on the sector’s operational technology.
Minnesota’s state IT agency confirmed the number of affected communities surpassed 30 after the first public reports, from Plymouth, South St. Paul, Braham, and Maple Plain, widened through the week. No utility reported a change to drinking water safety or quality, and officials said the switch to manual control kept systems running. Formal attribution has not been announced, but the timing lines up closely with a federal advisory that has been tracking exactly this kind of intrusion for months.
CISA’s Advisory AA26-097A, first issued in April and updated again on July 22, warns that Iranian-affiliated actors have been exploiting internet-connected programmable logic controllers across US water, energy, and government-services facilities. The July update widened the advisory’s scope beyond Rockwell Automation devices to include Schneider Electric and Siemens PLCs, and for the first time documented attackers exfiltrating PLC project files rather than only tampering with HMI and SCADA displays, a shift toward reconnaissance ahead of future disruption, not just vandalism.
The original insight for defenders is in that scope expansion: an advisory written around one vendor’s hardware widened to cover three within a single update cycle, which means any inventory of “exposed PLCs” built against last quarter’s guidance is already stale. Water utilities are named repeatedly in AA26-097A as targets specifically because their PLCs are small, unmonitored, and often left reachable from the public internet. The response pattern also mirrors what CyberTech has tracked elsewhere in nation-state cyber policy, including the coordinated US, UK, and EU action against FSB-linked cyber units: agencies are now updating guidance in near-real time as campaigns evolve, rather than waiting for an annual revision.
CISA’s recommended fix has not changed: remove PLCs from direct internet exposure behind a secure gateway and firewall, and review project files for unauthorized changes regardless of manufacturer.
Source: CISA