City of Plymouth and City of Maple Plain: Coordinated cyberattack hits more than 30 Minnesota water utilities

City of Plymouth and City of Maple Plain: Coordinated cyberattack hits more than 30 Minnesota water utilities

Cyberattack Targets Over 30 Minnesota Water Utilities in Coordinated OT Breach

On July 26 and 27, a coordinated cyberattack struck operational technology (OT) systems at more than 30 community water utilities across Minnesota, triggering an immediate response from Minnesota IT Services (MNIT). The agency confirmed the intrusion on July 28, activating its cybersecurity incident response protocols and collaborating with state and federal partners to contain the threat, investigate the breach, and bolster infrastructure defenses.

John Israel, MNIT Assistant Commissioner and Minnesota’s Chief Information Security Officer (CISO), emphasized the need for a "whole-of-government response," noting that the agency is working with affected communities to restore operations securely while mitigating future risks. The Minnesota Department of Health is also engaged, ensuring public health protections remain in place. To date, no impacted city has issued advisories altering drinking water usage.

Four municipalities Braham, Plymouth, South St. Paul, and Maple Plain have publicly acknowledged the attack. Maple Plain officials stated that while water and wastewater services remain uninterrupted and water quality is unaffected, certain details are being withheld to avoid compromising ongoing cybersecurity efforts.

Federal Guidance and Suspected Iranian Involvement
On July 28, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside cybersecurity agencies from Australia, the UK, and Canada, released CI Fortify guidance urging critical infrastructure operators to isolate OT systems from broader networks to maintain service continuity during breaches. CISA’s Chris Butera stressed the importance of proactive isolation and recovery planning to counter state-sponsored threats.

Though officials have not formally attributed the attack, security researchers at Tenable suspect the Iran-linked group CyberAv3ngers, citing patterns consistent with its history of targeting small water utilities. The timing aligns with a July 22 CISA advisory warning of Iranian-affiliated actors compromising internet-exposed programmable logic controllers (PLCs) in U.S. water, energy, and government sectors.

Tenable’s analysis highlights a recurring vulnerability: small utilities often rely on consumer-grade remote-access tools like TeamViewer and AnyDesk or expose PLC interfaces directly to the internet, lacking dedicated OT security staff and sufficient budgets for robust defenses. The broader OT sector also faces a critical shortage of engineers with dual expertise in control systems and cybersecurity, further exacerbating risks.

Source: https://www.helpnetsecurity.com/2026/07/30/minnesota-water-utilities-coordinated-cyberattack/

Plymouth Utilities - City of Plymouth Wisconsin cybersecurity rating report: https://www.rankiteo.com/company/plymouth-utilities

City of Maple Grove, Minnesota cybersecurity rating report: https://www.rankiteo.com/company/city-of-maple-grove-minnesota

"id": "PLYCIT1785407517",
"linkid": "plymouth-utilities, city-of-maple-grove-minnesota",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Braham',
                        'type': 'Municipal water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Plymouth',
                        'type': 'Municipal water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'South St. Paul',
                        'type': 'Municipal water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Maple Plain',
                        'type': 'Municipal water utility'}],
 'attack_vector': 'Internet-exposed programmable logic controllers (PLCs), '
                  'consumer-grade remote-access tools (e.g., TeamViewer, '
                  'AnyDesk)',
 'customer_advisories': 'No advisories altering drinking water usage issued; '
                        'water quality unaffected.',
 'date_detected': '2024-07-26',
 'date_publicly_disclosed': '2024-07-28',
 'description': 'A coordinated cyberattack struck operational technology (OT) '
                'systems at more than 30 community water utilities across '
                'Minnesota on July 26 and 27. The intrusion triggered an '
                'immediate response from Minnesota IT Services (MNIT), which '
                'activated cybersecurity incident response protocols and '
                'collaborated with state and federal partners to contain the '
                'threat, investigate the breach, and bolster infrastructure '
                'defenses.',
 'impact': {'operational_impact': 'No immediate disruption to water and '
                                  'wastewater services; ongoing cybersecurity '
                                  'efforts may impact transparency',
            'systems_affected': 'Operational technology (OT) systems at water '
                                'utilities'},
 'initial_access_broker': {'entry_point': 'Internet-exposed PLCs, '
                                          'consumer-grade remote-access tools'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Small utilities often lack dedicated OT security staff '
                    'and sufficient budgets for robust defenses. The OT sector '
                    'faces a critical shortage of engineers with dual '
                    'expertise in control systems and cybersecurity.',
 'motivation': 'State-sponsored targeting of critical infrastructure',
 'post_incident_analysis': {'corrective_actions': 'Isolation of OT systems, '
                                                  'enhanced monitoring, '
                                                  'addressing OT cybersecurity '
                                                  'expertise shortage',
                            'root_causes': 'Exposed PLC interfaces, lack of OT '
                                           'security staff, insufficient '
                                           'budgets for robust defenses, '
                                           'reliance on consumer-grade '
                                           'remote-access tools'},
 'recommendations': 'Isolate OT systems from broader networks, avoid reliance '
                    'on consumer-grade remote-access tools, implement '
                    'proactive isolation and recovery planning, and address '
                    'the shortage of OT cybersecurity expertise.',
 'references': [{'source': 'Minnesota IT Services (MNIT)'},
                {'source': 'U.S. Cybersecurity and Infrastructure Security '
                           'Agency (CISA)'},
                {'source': 'Tenable'},
                {'source': 'CI Fortify Guidance (CISA, Australia, UK, '
                           'Canada)'}],
 'response': {'communication_strategy': 'Limited details disclosed to avoid '
                                        'compromising cybersecurity efforts; '
                                        'no advisories altering drinking water '
                                        'usage issued',
              'containment_measures': 'Isolation of OT systems from broader '
                                      'networks, collaboration with affected '
                                      'communities to restore operations '
                                      'securely',
              'incident_response_plan_activated': 'Yes',
              'network_segmentation': 'Isolation of OT systems from broader '
                                      'networks',
              'remediation_measures': 'Bolstering infrastructure defenses, '
                                      'ongoing cybersecurity efforts',
              'third_party_assistance': 'State and federal partners (e.g., '
                                        'CISA, Minnesota Department of '
                                        'Health)'},
 'stakeholder_advisories': 'Whole-of-government response; collaboration with '
                           'affected communities to restore operations '
                           'securely and mitigate future risks.',
 'threat_actor': 'Suspected Iran-linked group CyberAv3ngers',
 'title': 'Coordinated Cyberattack on Over 30 Minnesota Water Utilities',
 'type': 'Cyberattack on OT Systems',
 'vulnerability_exploited': 'Exposed PLC interfaces, lack of OT security '
                            'staff, insufficient budgets for robust defenses'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.