MINNESOTA WATER SYSTEM CYBERATTACK
Agentic AI Investigative Assessment
July 2026

Standalone evidence-driven report based on publicly available information collected from primary government sources, official utility statements, and reputable reporting.
Confirmed scale
30+
community water systems in Minnesota reported as targeted by July 30, 2026.
Primary affected technology
OT / PLC / HMI
Most confirmed cases involved remote monitoring and control technology.
Public attribution status
UNRESOLVED
Minnesota had not attributed the activity to a specific actor as of July 30, 2026.
Confirmed public water-use restriction statewide
None
No active statewide requests to modify drinking-water use as of July 30, 2026.

1. EXECUTIVE ASSESSMENT

The strongest publicly available evidence establishes that a coordinated wave of malicious cyber activity affected technology at more than 30 Minnesota community water systems during July 26–27, 2026, with public confirmation issued by Minnesota IT Services (MNIT) on July 30, 2026. MNIT stated that most confirmed cases involved operational technology used to remotely monitor and control equipment, specifically including programmable logic controllers (PLCs) and human-machine interfaces (HMIs), and that the state had identified methods of access but would not publicly release system-specific forensic details while the investigation remained active. MNIT also stated that Minnesota had not attributed the activity to a specific actor. MNIT, July 30, 2026

Publicly documented local impacts varied. Braham publicly stated on July 27, 2026 that its water plant was offline for an unknown reason and asked residents to minimize water use; later reporting tied that outage to a cyberattack and stated that water quality was not affected. Plymouth stated that communications at water facilities were restored following a cyberattack and that water levels and quality were unaffected. South St. Paul publicly disclosed a cybersecurity incident affecting technology supporting portions of its water utility system. Star Tribune also reported Maple Plain had declared a local state of emergency and implemented contingency procedures to keep water and wastewater operations going. City of Braham notice; City of Plymouth notice; City of South St. Paul notice; Star Tribune, July 28, 2026

Federal warning material released July 30, 2026 by the FBI and EPA broadened the picture beyond Minnesota, warning that since July 27, 2026 utilities in at least seven states had reported incidents targeting internet-facing OT devices, including Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 PLCs, and that some activity degraded water operations. Separately, a Wisconsin Department of Natural Resources bulletin on July 28, 2026 said Minnesota had reported that threat actors gained access to PLCs during July 26–27 and dropped system pressures in several incidents, triggering alarms and law-enforcement response. That Wisconsin bulletin is authoritative for Wisconsin’s advisory but is still secondary with respect to underlying Minnesota incident specifics because it references Minnesota reporting not directly published in the cited bulletin’s attachment. FBI/EPA PSA, July 30, 2026; Wisconsin DNR bulletin, July 28, 2026

Attribution remains unresolved in this assessment. Reputable reporting later described U.S. officials as suspecting Iran or activity aligned with prior Iran-affiliated PLC targeting, and Wired reported on a leaked WaterISAC memo describing alignment with an earlier CISA-described Iran-affiliated campaign. However, MNIT explicitly said attribution was not established, and the leaked memo itself is not a public primary source from the investigating authorities. Accordingly, the report treats Iran-related claims as reported association or investigative lead, not confirmed attribution. MNIT, July 30, 2026; Wired, July 30, 2026; Washington Post, July 30, 2026

Bottom line: The public record supports a confirmed fact that Minnesota experienced a multi-system cyber campaign affecting water-sector OT during July 26–27, 2026. The public record supports only a moderate-confidence assessment that some incidents likely involved direct interaction with internet-accessible PLCs. Attribution is unresolved.

2. KEY FINDINGS

CONFIRMED FACT
HIGH CONFIDENCE

More than 30 Minnesota community water systems were targeted.

MNIT publicly stated on July 30, 2026 that malicious cyber activity targeted technology at more than 30 community water systems across Minnesota.

Supporting evidence: MNIT, July 30, 2026
CONFIRMED FACT
HIGH CONFIDENCE

Most confirmed cases involved OT used to remotely monitor and control equipment.

MNIT specifically identified PLCs and HMIs as technologies involved in most confirmed cases.

Supporting evidence: MNIT, July 30, 2026
CONFIRMED FACT
MODERATE CONFIDENCE

At least some local utilities experienced operational disruption or manual contingency operations.

Braham reported its plant was offline and asked residents to minimize water use; Plymouth reported communications outages but continued operating; Star Tribune reported Maple Plain implemented contingency procedures.

Supporting evidence: Braham; Plymouth; Star Tribune
ASSESSMENT
MODERATE CONFIDENCE

The activity is consistent with targeting of internet-accessible PLCs and related OT.

MNIT recommended removal of unnecessary internet access from PLCs and HMIs and said it had identified methods of access; FBI/EPA and Wisconsin warnings described attacks on internet-facing PLCs using specific ports and affecting multiple states.

Supporting evidence: MNIT; FBI/EPA PSA; Wisconsin DNR
UNRESOLVED
LOW CONFIDENCE

No public evidence was found establishing a single common actor for every Minnesota incident.

MNIT explicitly said similarities existed but investigators had not determined that every incident was carried out by the same actor.

Supporting evidence: MNIT
UNRESOLVED
LOW CONFIDENCE

Attribution to Iran is not established by publicly released primary evidence.

Iran-related claims appear in reputable reporting and leaked-memo reporting, but the investigating Minnesota authority had not publicly attributed the activity as of July 30, 2026.

Supporting evidence: MNIT; Wired

3. INCIDENT TIMELINE

Date / Time Event Source Classification Confidence
July 22, 2026 FBI published alert titled “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.” Publicly available page confirms date and title; detailed overlap with Minnesota incidents is not fully public in the page retrieved. FBI alert page CONFIRMED FACT MODERATE
July 26–27, 2026 MNIT later reported the coordinated cyberattack targeted more than 30 community water systems during these dates. Reuters syndication quoting MNIT; MNIT CONFIRMED FACT HIGH
Early morning, July 27, 2026 South St. Paul identified a cybersecurity incident involving technology used to support portions of the city’s water utility system. City of South St. Paul CONFIRMED FACT MODERATE
July 27, 2026 Braham issued “Water Plant Issue” notice: plant offline for unknown reason; residents asked to minimize water use. City of Braham CONFIRMED FACT HIGH
July 27, 2026, 2:05 p.m. Plymouth stated water-facility communications were restored following a cyberattack; original update said communications outages had not affected water levels or quality. City of Plymouth CONFIRMED FACT MODERATE
July 28, 2026 Star Tribune reported more than 30 utilities were hit; Maple Plain declared a local state of emergency and implemented contingency procedures. Star Tribune CONFIRMED FACT / LEAD MODERATE
July 28, 2026, 2:38 p.m. CDT Wisconsin DNR warned Wisconsin systems of ongoing malicious activity; stated Minnesota reported threat actors accessed PLCs and in several incidents dropped system pressures between July 26–27. Wisconsin DNR bulletin ASSESSMENT MODERATE
July 30, 2026, 2:37 p.m. MNIT public statement: more than 30 community water systems impacted; most confirmed cases involved PLCs and HMIs; no attribution yet; no active requests to modify drinking-water use. MNIT CONFIRMED FACT HIGH
July 30, 2026 FBI/EPA PSA warned that since July 27, 2026 incidents affecting internet-facing PLCs had been reported in at least seven states; some degraded water operations. FBI/EPA PSA CONFIRMED FACT HIGH
July 30, 2026 WaterISAC posted a notice that the leaked memo regarding Minnesota water cyber activity had been shared to members as TLP:AMBER. WaterISAC notice CONFIRMED FACT MODERATE

4. AFFECTED SYSTEMS

Confirmed or publicly disclosed organizations / locations

  • Minnesota community water systems: more than 30 affected statewide. MNIT
  • Braham, Minnesota: water plant offline July 27; later publicly described as cyberattack-related. Braham notice; AP
  • Plymouth, Minnesota: water infrastructure communications outage/restoration after cyberattack. Plymouth
  • South St. Paul, Minnesota: cybersecurity incident involving technology supporting portions of water utility system. South St. Paul
  • Maple Plain, Minnesota: reported local state of emergency and contingency operations. Publicly reported by Star Tribune; not independently validated here from city primary record. Star Tribune

Confirmed / reported technologies

  • Operational Technology (OT) used for remote monitoring and control. MNIT
  • Programmable Logic Controllers (PLCs). MNIT
  • Human-Machine Interfaces (HMIs). MNIT
  • Internet-facing PLCs in broader multi-state federal warning. FBI/EPA PSA
  • Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 PLCs in the federal multi-state PSA. Public evidence does not verify that these exact models were used in any specific named Minnesota utility. FBI/EPA PSA
NOT PUBLICLY VERIFIED: exact PLC vendors, firmware versions, remote-access products, VPN products, engineering workstations, supervisory software, or network diagrams for the named Minnesota victims.

5. ATTACK METHODOLOGY

Confirmed activity

  • Malicious activity involved technology used to remotely monitor and control water-system equipment, including PLCs and HMIs. MNIT
  • MNIT stated investigators had identified methods of access but withheld system-specific details. MNIT
  • Federal PSA warned of attacks against internet-facing OT devices, specifically certain Rockwell MicroLogix PLCs, with some incidents degrading operations in at least seven states. FBI/EPA PSA

Supported assessment

  • ASSESSMENT MODERATE CONFIDENCE Initial access in at least some incidents likely involved directly internet-accessible OT or remotely accessible PLC/HMI infrastructure rather than only conventional IT compromise. Basis: MNIT remediation guidance focused on removing internet access from PLCs/HMIs, replacing default credentials, reviewing remote-access logs, and separating OT from business networks; FBI/EPA and Wisconsin bulletins described internet-facing PLC exploitation patterns. MNIT; FBI/EPA PSA; Wisconsin DNR
  • ASSESSMENT MODERATE CONFIDENCE Weak or default credentials may have been relevant in the broader campaign model, but this is not publicly verified for the Minnesota incidents. The evidence is indirect: MNIT advised replacing default credentials; CISA/FBI had recently warned of Iranian-affiliated exploitation of exposed PLCs; historical PLC campaigns often used default or absent passwords. MNIT; FBI, July 22 alert page; CISA AA23-335A context
  • ASSESSMENT LOW CONFIDENCE Some incidents may have involved process manipulation affecting pressure or operational control. This is based on the Wisconsin DNR bulletin’s reference to Minnesota reporting of pressure drops and on AP reporting that attackers shut down controls in Braham. Public forensic evidence has not been released. Wisconsin DNR; AP

Not publicly verified

  • Specific CVE exploitation.
  • Specific malware families or custom tools.
  • Confirmed VPN compromise or credential-phishing path.
  • Lateral movement between IT and OT.
  • Persistence mechanisms.
  • Command-and-control infrastructure.
  • Evidence deletion or log tampering.
  • Specific PLC logic modification in Minnesota victims.

6. OPERATIONAL IMPACT

Impact Area Supported Findings Status Sources
Cyber impact Malicious activity involving water-system OT at 30+ Minnesota community water systems. CONFIRMED FACT MNIT
Loss of remote monitoring / communications Plymouth reported communications outage at water facilities, later restored. CONFIRMED FACT Plymouth
Plant outage / control disruption Braham plant offline for a period; AP reported attackers shut down operating controls that shut down well and treatment plant. CONFIRMED FACT / ASSESSMENT Braham; AP
Manual / contingency operations Maple Plain reportedly implemented contingency procedures; AP/CBS reported transitions to manual operations in affected communities. ASSESSMENT Star Tribune; CBS
Water service interruption Not established statewide. Some local disruptions occurred, but MNIT emphasized that “impacted” did not mean every community suffered service disruption. UNRESOLVED MNIT
Water quality degradation / contamination No public evidence found confirming contamination or unsafe drinking water. Braham and Plymouth publicly said quality was not affected. MNIT said no active requests to modify drinking-water use statewide as of July 30. CONFIRMED FACT for “no confirmed public evidence found”; UNRESOLVED for all systems individually Braham; Plymouth; MNIT
Physical equipment damage MNIT said the state continued to assess whether equipment issues or operational disruptions resulted directly from malicious activity. UNRESOLVED MNIT
Financial impact INSUFFICIENT EVIDENCE in public sources reviewed. INSUFFICIENT EVIDENCE —
Public-safety impact No confirmed injuries or confirmed contamination found in reviewed sources. Potential public-safety risk was discussed in warnings, not confirmed as realized consequence in Minnesota. UNRESOLVED Wisconsin DNR; MNIT

7. INCIDENT CORRELATION

Similarities

  • Temporal clustering around July 26–27, 2026. MNIT
  • Target class: community water systems / water utility technology. MNIT
  • Technology class: remote monitoring/control OT, especially PLCs and HMIs. MNIT
  • Operational symptom pattern in public reporting: communications loss, plant offline status, control disruption, shift toward manual or contingency operations. AP; Star Tribune

Differences / limitations

  • Public evidence does not show identical victim technology, network architecture, or access paths across all affected systems.
  • Impacts differed substantially by locality, from communications issues to temporary outage conditions.
  • MNIT explicitly cautioned that investigators had not determined that every incident was carried out by the same actor. MNIT

ASSESSMENT MODERATE CONFIDENCE The Minnesota incidents share enough characteristics to be described as potentially related coordinated activity, especially by timing and OT target type. However, the public record does not support a high-confidence conclusion that all named and unnamed incidents were executed by one actor or through one exact intrusion method.

8. EXTERNAL CAMPAIGN CORRELATION

Similar activity elsewhere

  • At least seven states: FBI/EPA PSA said that since July 27, 2026 utility companies in at least seven states had reported incidents involving internet-facing PLCs, and some activity degraded operations. FBI/EPA PSA
  • Wisconsin defensive warning: Wisconsin DNR issued urgent guidance referencing Minnesota incidents and open PLC ports 44818, 2222, 102, and 502. Wisconsin DNR
  • Historical comparator: prior U.S. and allied advisories described Iran-affiliated targeting of internet-connected PLCs and HMIs in multiple sectors, including water and wastewater, especially where devices used default or weak passwords. CISA AA23-335A; Joint fact sheet

Relationship assessment

  • CONFIRMED RELATIONSHIP between the Minnesota incidents and a broader July 2026 national pattern of water-sector PLC targeting: supported by FBI/EPA PSA.
  • POSSIBLE RELATIONSHIP between the Minnesota incidents and earlier Iran-affiliated PLC campaigns against critical infrastructure: similarities exist in target type, internet-exposed PLC theme, and timing relative to federal warnings, but public primary attribution evidence is incomplete.
  • NOT ESTABLISHED that the Minnesota activity and all other state incidents were one single campaign by one actor.

9. ATTRIBUTION ASSESSMENT

Known Facts

  • Minnesota had not attributed the activity to a specific actor as of July 30, 2026. MNIT
  • MNIT said federal government was evaluating the activity in a broader national context and leading efforts to determine attribution. MNIT
  • Federal and reputable-media reporting described suspicion of Iran or similarity to Iran-affiliated PLC targeting, but those reports were not equivalent to public official confirmation by Minnesota. Washington Post; Wired

Supporting Evidence for Iran-related suspicion

  • Wired reported a leaked WaterISAC memo said the Minnesota Fusion Center found the attacks “aligned” with a CISA-described Iran-affiliated campaign. Wired
  • Reuters-syndicated reporting quoted MNIT spokesperson language that timing, access methods, and targeted infrastructure shared characteristics with coordinated incidents observed by federal partners. Reuters syndication
  • Federal warnings days earlier focused on Iranian-affiliated PLC exploitation. FBI July 22 alert page

Contradictory / Limiting Evidence

  • MNIT expressly withheld attribution. MNIT
  • Public forensic evidence, IOCs, malware, victim-side artifacts, and infrastructure details have not been released.
  • Leaked-memo reporting is not the same as a public attribution statement by investigating authorities.
  • Similarity in target type and TTPs does not alone establish authorship.

Alternative Explanations

  • Copycat or opportunistic actors emulating recently publicized PLC-targeting TTPs.
  • Multiple actors exploiting a broadly insecure attack surface during the same period.
  • One actor with mixed access methods across different utilities.

Assessment

ATTRIBUTION: UNRESOLVED LOW CONFIDENCE

The public record supports only a reported association between the Minnesota incidents and prior Iran-affiliated PLC activity. It does not support confirmed attribution.

Evidence Gaps

  • Public IOCs or victim telemetry.
  • Publicly released forensics linking victims to shared infrastructure.
  • Official public attribution statement from FBI/CISA/MNIT/DOJ.
  • Evidence excluding other actor hypotheses.

10. INTELLIGENCE GAPS

  • Exact list of all affected Minnesota community water systems.
  • Exact event times for each incident.
  • Precise initial-access mechanism(s) per victim.
  • Which PLC/HMI vendors and models were deployed in each affected system.
  • Whether default credentials, no passwords, exposed ports, or remote-access products were actually used in Minnesota cases.
  • Whether any PLC logic, setpoints, port settings, or communication parameters were modified.
  • Whether any pressure drops, pump stoppages, or shutdown conditions were directly caused by malicious commands in Minnesota.
  • Whether equipment damage occurred.
  • Recovery cost and duration per utility.
  • Any released IOCs, malicious IPs, domains, hashes, or command artifacts.
  • Official attribution determination, if any, after July 30, 2026.

11. INVESTIGATIVE LEADS

  1. Obtain primary local statements from Maple Plain and any additional named Minnesota utilities.
  2. Review Minnesota Fusion Center, MDH, MPCA, or county emergency-management releases for technical updates after July 30, 2026.
  3. Search for subsequent FBI, CISA, EPA, or DOJ releases that may have provided attribution, IOCs, or case outcomes.
  4. Identify whether Minnesota public records, city council packets, or emergency declarations preserve incident specifics such as affected equipment, overtime, contractor costs, or manual operations.
  5. Determine whether any EPA-sanitary-survey or MDH compliance correspondence references post-incident remediation.
  6. Look for vendor advisories or litigation/insurance filings naming affected PLCs, HMIs, or remote-access platforms.
  7. Seek any public court filings if criminal charges are later brought.

12. REJECTED / UNVERIFIED FINDINGS

Claim Source Reason Rejected / Not Accepted as Fact Evidence Required for Validation
Iran definitively conducted the Minnesota attacks. Wired leaked-memo reporting; Washington Post / NYT-based reports Minnesota public authority had not attributed the activity; leaked memo is not equivalent to public forensic proof or official final attribution. Official attribution statement with supporting technical or intelligence basis.
All 30+ incidents were conducted by the same actor. Inferred from statewide timing MNIT explicitly said investigators had not determined every incident was carried out by the same actor. Shared forensic artifacts, infrastructure, or law-enforcement findings.
Specific Minnesota victims used Rockwell MicroLogix 1100/1400 PLCs. FBI/EPA PSA The PSA described broader observed multi-state behavior, not victim-specific identification for named Minnesota utilities. Victim or investigator confirmation naming models used in the Minnesota incidents.
Pressure drops occurred in specific named Minnesota utilities. Wisconsin DNR bulletin Authoritative for warning context but secondary to underlying Minnesota source; no named victim-level Minnesota primary confirmation found in reviewed public sources. Minnesota or victim utility statement documenting pressure impacts.
Water contamination occurred. No validated primary source found No authoritative public source reviewed confirmed contamination; some named utilities said quality was unaffected. Water-quality test results, boil-water notices, or utility/public-health confirmation.
A specific CVE was exploited. None validated No public authoritative source identified a CVE for these Minnesota incidents. Official forensic report or advisory naming the exploited vulnerability.

13. SOURCE / EVIDENCE MATRIX

Claim Classification Source Source Tier Independent Corroboration Confidence
30+ Minnesota community water systems were targeted. CONFIRMED FACT MNIT Tier 1 Reuters/AP/Star Tribune repeat MNIT statement HIGH
Most confirmed cases involved PLCs and HMIs used for remote monitoring/control. CONFIRMED FACT MNIT Tier 1 CBS/AP repeat MNIT HIGH
Braham water plant went offline July 27 and residents were asked to minimize use. CONFIRMED FACT Braham Tier 1 AP / MPR HIGH
Plymouth experienced water communications outage and restoration following cyberattack. CONFIRMED FACT Plymouth Tier 1 AP / local reporting MODERATE
South St. Paul identified a cybersecurity incident affecting technology supporting portions of water utility system. CONFIRMED FACT South St. Paul Tier 1 Search-result snippet; local reporting MODERATE
Maple Plain declared local state of emergency and used contingency procedures. INVESTIGATIVE LEAD / likely fact Star Tribune Tier 3 No primary city statement validated in this review MODERATE
Some incidents likely involved internet-facing PLC exploitation. ASSESSMENT MNIT; FBI/EPA PSA; Wisconsin DNR Tier 1 / Tier 2 Multiple independent authorities MODERATE
At least seven states reported similar incidents after July 27. CONFIRMED FACT FBI/EPA PSA Tier 1 AP/CBS/reuters references HIGH
Pressure drops occurred in several incidents. ASSESSMENT Wisconsin DNR bulletin Tier 1 for Wisconsin advisory / indirect for Minnesota No Minnesota primary victim confirmation found here MODERATE
Minnesota had not attributed the incidents as of July 30, 2026. CONFIRMED FACT MNIT Tier 1 AP repeats HIGH
Iran may be linked. UNRESOLVED / reported association Wired; Washington Post Tier 3 Mutually reinforcing reporting, but not public primary forensic proof LOW

14. FINAL ASSESSMENT

WHAT DO WE KNOW?

  • During July 26–27, 2026, malicious cyber activity targeted technology at more than 30 Minnesota community water systems.
  • Most confirmed Minnesota cases involved OT used to remotely monitor and control equipment, including PLCs and HMIs.
  • Named local examples include Braham, Plymouth, and South St. Paul; Maple Plain is credibly reported but not fully primary-validated here.
  • At least some utilities experienced communications loss, plant outage conditions, or contingency/manual operations.
  • No public evidence reviewed confirmed contamination, and MNIT reported no active statewide requests to alter drinking-water use as of July 30, 2026.

WHAT DO WE ASSESS?

  • The incidents were likely coordinated in timing and target class, but not yet proven to be the work of one actor.
  • At least some incidents likely involved direct access to exposed or remotely reachable OT/PLC infrastructure.
  • The Minnesota activity is consistent with a broader July 2026 water-sector pattern affecting multiple U.S. states.

WHAT DO WE SUSPECT?

  • Publicly available evidence suggests possible alignment with previously described Iran-affiliated PLC targeting patterns, but this remains a suspicion / reported association rather than established fact.
  • Weak configuration, internet exposure, and possibly credential weaknesses may have enabled some compromises.

WHAT DON’T WE KNOW?

  • The complete victim list.
  • The exact access mechanism for each victim.
  • Whether PLC logic or setpoints were changed in Minnesota.
  • Whether pressure drops and other process effects were confirmed in named victims.
  • Whether any equipment damage occurred.
  • Whether a single actor or multiple actors were responsible.
  • Whether Iran or any other actor can be conclusively attributed.

WHAT EVIDENCE WOULD CHANGE THE ASSESSMENT?

  • Release of official forensic findings, IOCs, or victim-specific technical reports.
  • Public statements by FBI/CISA/MNIT/DOJ naming an actor and evidentiary basis.
  • Victim utility disclosures identifying PLC/HMI vendors, remote-access paths, and exact operational effects.
  • Court filings, indictments, or seizures linking infrastructure to the attacks.
  • Water-quality or engineering reports documenting cyber-caused physical consequences.

OVERALL JUDGMENT MODERATE CONFIDENCE A broad OT-focused cyber campaign affected Minnesota community water systems in late July 2026. ATTRIBUTION: UNRESOLVED