A coordinated cyberattack targeted more than 30 community water systems across Minnesota over two days in late July, marking what security experts describe as the first distributed campaign against dozens of small utilities potentially linked by a shared vulnerability in widely used industrial controllers, according to a CSO Online report. While drinking water remained safe and disruptions were limited, researchers say the incident represents another escalation in a months-long campaign targeting US water infrastructure amid heightened geopolitical tensions with Iran. The attacks alarmed industrial cybersecurity experts not because of widespread damage, but because they appear to demonstrate a new tactic of simultaneously exploiting a common operational technology weakness across multiple small facilities.
Minnesota IT Services disclosed that the water systems experienced coordinated cyber activity from July 26 to July 27. The city of Braham, with roughly 1,700 residents in Isanti County, suffered the most visible operational impact after shutting down portions of its water system for approximately two hours while operators regained control. Plymouth disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to halt the intrusion and prevent attackers from regaining access during reconfiguration. South St. Paul reported that some automated controls were affected, and Maple Plain declared a local state of emergency to expand its response. Federal authorities are examining whether vulnerable Rockwell Automation MicroLogix 1400 programmable logic controllers served as a common enabling factor in the campaign, with a targeted search revealing Plymouth using at least two of these controllers.
The report finds that "this is a first-of-its-kind distributed attack on water utilities," according to Markus Mueller, field CISO at Nozomi Networks, who says it was "clearly aimed at disruption rather than financial gain." The incident came just days after CISA, the FBI, NSA and EPA expanded an advisory warning that Iranian-affiliated cyber actors continue targeting programmable logic controllers used throughout US critical infrastructure, including water systems. CISA Acting Director Nick Andersen stated the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities." Unlike previous campaigns by Iranian-aligned hacktivist groups, no convincing public victory videos or detailed posts immediately appeared following the Minnesota attacks, with an Iranian state publication attributing the attack to threat group Handala only on July 29, days after the incident.
Experts believe the coordination strongly suggests investigators will eventually identify some technical thread connecting the affected communities. Security researchers searched Minnesota's public IP space and didn't find obvious exposed water infrastructure, noting that many of these utilities use cellular communications, which makes them much harder to identify than internet-facing industrial systems. That distinction could explain why dozens of geographically clustered utilities were affected while neighboring infrastructure apparently was not. The possibility that exposed controllers provided access aligns with both recent federal warnings and a July 30 Rockwell Automation security advisory addressing the MicroLogix 1400 family of controllers. Depending on configuration, an attacker could gain monitoring capability, manipulate what operators see, or in some circumstances modify operational settings, though manual safety controls built into most water facilities make catastrophic consequences considerably more difficult.
Federal agencies have stopped short of publicly identifying those responsible, although most experts believe Iranian-affiliated actors remain the leading suspects based on the timing and motivation. Former FBI cyber deputy director Cynthia Kaiser argues Iran increasingly benefits from "strategic ambiguity," thriving when people suspect their involvement but can't confirm it. The report concludes the attacks reinforce an uncomfortable reality: attackers often don't need sophisticated zero-day exploits to disrupt operational technology, but instead succeed because industrial control devices remain directly reachable from the internet, protected by weak credentials, or deployed without the network segmentation long recommended by federal agencies. As one researcher noted, it seems threat actors are implementing CISA's recommended actions for controllers without operator permission: set a password, remove them from the internet.

