Coordinated Cyberattack Hits 30+ Minnesota Water Systems as Officials Suggest Iran-Linked Pattern

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Attack scope: A coordinated cyberattack hit more than 30 community water systems across Minnesota on July 26 and July 27.
  • Agency response: Minnesota IT Services confirmed unauthorized access with malicious intent and found no active requests for residents to modify water usage.
  • Federal involvement: The FBI is in contact with victims, while similarities point to prior Iranian-affiliated targeting of U.S. water infrastructure.

Over 30 community water systems across Minnesota were targeted by a coordinated cyberattack on July 26 and July 27, according to a statement from Minnesota IT Services. The disclosure followed local media reports that four Minnesota cities had issued notices about cyberattacks on their networks – Plymouth, South St. Paul, Maple Plain, and Braham.

Minnesota IT Services said it wasn't aware of any active requests from Minnesota cities asking residents to modify their drinking water usage. 

State Agency Confirms Malicious Access

The Minnesota cyberattack announcement came just five days after federal agencies had updated a joint advisory warning that similar infrastructure was already in the crosshairs. 

Emily Zimmer, a spokesperson for the agency, told Reuters that while the investigation remains ongoing, "the timing, methods of access, and targeted infrastructure share characteristics with other coordinated cyber incidents our federal partners have observed involving critical infrastructure." 

She said the agency used the term "attack" because "investigators identified unauthorized access with malicious intent directed at these systems," though it couldn't yet discuss formal attribution. 

Minnesota's chief information security officer, John Israel, said the response “worked as intended.” The FBI confirmed it was aware of the incident and in contact with victims "to resolve the matter," Reuters said. 

Pattern Mirrors Iranian-Linked Intrusions

The attacks resemble a wave of intrusions against U.S. water infrastructure previously attributed to Iran-linked attackers. An April 7 CISA advisory warned that Iranian-affiliated hackers were targeting internet-facing programmable logic controllers manufactured by Rockwell Automation – industrial computers used to automate pumps, valves, and treatment operations. A July 22 update expanded the scope to include devices from Schneider Electric, Siemens, and potentially other manufacturers. 

The advisory notes similarities with a previous campaign orchestrated by CyberAv3ngers (also tracked as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul, Soldiers of Solomon, UNC5691, and the Shahid Kaveh Group). 

The group is believed to be affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC) and tied to 2023 intrusions into U.S., Israeli, U.K., and Irish water and energy infrastructure. The APT then compromised at least 75 U.S.-based Unitronics PLC devices, the advisory says.

Experts Warn of Physical Impact Scenarios

Joe Slowik, director of threat research and cyber engineering at Dataminr, said CISA's updated reporting "shows a worrying expansion in Iran-linked critical infrastructure targeting." He warned that extending activity to additional equipment lines, paired with process manipulation and safety degradation, "enables various physical impact scenarios."

Braham saw its water plant briefly forced offline entirely – operating controls for the well and treatment plant went down before the system was restored by 11:25 a.m. Monday. Maple Plain’s automated utility controls were affected, but the city said drinking water and wastewater services stayed fully operational.

Recently, Microsoft analyzed the GigaWiper backdoor, which has wiper and spying capabilities, and linked it to the Crucio malware family, previously connected to CyberAv3ngers.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: