Edit

Minnesota Water Cyberattack Disrupts Local Utility Systems

Minnesota Water Cyberattack Disrupts Local Utility Systems

A Minnesota water cyberattack targeting systems in more than 30 communities has renewed concern about the security of essential US utilities. Investigators are examining possible links to Iran-affiliated hackers, while officials have stopped short of formally attributing the operation.

Minnesota Water Cyberattack Disrupts Local Services

The coordinated attacks reportedly affected water and wastewater technology across Minnesota on Sunday, July 26, and Monday, July 27, 2026. Braham, Plymouth, South St. Paul and Maple Plain were among the communities that publicly disclosed incidents.

The most visible disruption occurred in Braham, a small city north of Minneapolis. The attack temporarily interfered with water operations, but local officials restored services in less than two hours. Available information did not indicate that drinking water had become unsafe.

Cybersecurity company Tenable said more than 30 Minnesota communities were affected and described the activity as a coordinated campaign against water and wastewater utilities. However, the precise number of successfully compromised systems and the full operational impact remain under investigation.

CyberAv3ngers Link Remains Under Investigation

Investigators are examining whether CyberAv3ngers, also known as the Shahid Kaveh Group, played a role in the attacks. The FBI has identified the group as an Iranian-affiliated threat actor connected to the Islamic Revolutionary Guard Corps’ cyber operations.

CyberAv3ngers has previously targeted programmable logic controllers, commonly called PLCs. These devices manage physical processes such as pumps, pressure controls, valves and water levels. An attacker who gains access to an exposed controller may alter settings or interrupt normal operations without entering a utility building.

Tenable found similarities between the Minnesota incidents and techniques associated with earlier attacks on internet-connected industrial equipment. That connection does not establish responsibility. Federal investigators had not publicly confirmed that CyberAv3ngers or the Iranian government directed the Minnesota operation when the incident was reported.

This distinction matters. Similar tools, targets or methods can support an investigation, but they are not conclusive proof of who ordered an attack.

CISA Warning Highlights Exposed Control Systems

The attacks followed federal warnings about Iranian-affiliated actors exploiting programmable logic controllers used across US critical infrastructure. The FBI said CyberAv3ngers had targeted internet-facing industrial devices, including equipment used by water and wastewater operators.

Many smaller utilities depend on remote-access software and older operational technology because they have limited staff and cybersecurity budgets. Systems connected directly to the public internet can become easy targets when operators retain default passwords, delay security updates or fail to separate business networks from industrial controls.

Tenable advised utilities to remove unnecessary internet exposure, strengthen authentication, review remote-access accounts and separate information technology networks from operational systems. These measures cannot prevent every intrusion, but they can reduce the ability of attackers to reach equipment that controls physical services.

US Water Utilities Face Growing Cyber Risk

The Minnesota water cyberattack shows how politically motivated hackers can create disruption without targeting a major city or national provider. Smaller public utilities may offer fewer protections while still controlling services that communities depend on every day.

The incident also demonstrates why authorities should avoid premature attribution. Investigators must examine access records, malware, compromised accounts and infrastructure used by the attackers before assigning responsibility.

Minnesota officials and federal agencies are continuing their investigation. Until they release confirmed findings, the most accurate conclusion is that the attacks resemble previously documented Iran-affiliated activity, but direct responsibility has not been officially established.

What is your response?

joyful Joyful 0%
cool Cool 0%
thrilled Thrilled 0%
upset Upset 0%
unhappy Unhappy 0%
AD
AD
AD
AD
AD
AD
AD
AD
AD