A coordinated cyberattack targeting operational technology (OT) at over 30 community water systems in Minnesota occurred on July 26-27, 2026, prompting a statewide cybersecurity response. The affected systems include those in Braham, Plymouth, South St. Paul, and Maple Plain. Braham’s water plant went offline, leading to a request for residents to minimize water use until treatment resumed. Plymouth reported cellular communication failures at two water towers and multiple wastewater lift stations but continued manual operations. South St. Paul and Maple Plain maintained services after automated utility controls were affected, with Maple Plain declaring a local state of emergency.
Minnesota IT Services (MNIT) stated on July 28 that there were no active requests for residents to change their drinking-water use. Officials have not publicly identified the attacker, initial access method, affected products, exploited vulnerabilities, or whether data was stolen. The statewide figure of 30+ systems refers to those targeted, not necessarily compromised. MNIT is coordinating containment, investigation, recovery, and threat-intelligence sharing with state agencies, CISA, the EPA, the FBI, and affected utilities.
In a separate development, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers (PLCs) from Rockwell Automation, Schneider Electric, Siemens, and others. Tenable noted that the timing and operational pattern of the Minnesota attacks are consistent with the CyberAv3ngers threat ecosystem, though no official attribution has been made. CISA has provided defensive guidance, including logging cellular modem connections, restricting controller access, and validating backups before restoration.
CVEs: CVE-2026-50522
Attack groups: CyberAv3ngers
Companies: Tenable, Rockwell Automation, Schneider Electric, Siemens
Service providers: MNIT
Original source: thehackernews.com