The strongest publicly available evidence establishes that a coordinated wave of malicious cyber activity affected technology at more than 30 Minnesota community water systems during July 26–27, 2026, with public confirmation issued by Minnesota IT Services (MNIT) on July 30, 2026. MNIT stated that most confirmed cases involved operational technology used to remotely monitor and control equipment, specifically including programmable logic controllers (PLCs) and human-machine interfaces (HMIs), and that the state had identified methods of access but would not publicly release system-specific forensic details while the investigation remained active. MNIT also stated that Minnesota had not attributed the activity to a specific actor. MNIT, July 30, 2026
Publicly documented local impacts varied. Braham publicly stated on July 27, 2026 that its water plant was offline for an unknown reason and asked residents to minimize water use; later reporting tied that outage to a cyberattack and stated that water quality was not affected. Plymouth stated that communications at water facilities were restored following a cyberattack and that water levels and quality were unaffected. South St. Paul publicly disclosed a cybersecurity incident affecting technology supporting portions of its water utility system. Star Tribune also reported Maple Plain had declared a local state of emergency and implemented contingency procedures to keep water and wastewater operations going. City of Braham notice; City of Plymouth notice; City of South St. Paul notice; Star Tribune, July 28, 2026
Federal warning material released July 30, 2026 by the FBI and EPA broadened the picture beyond Minnesota, warning that since July 27, 2026 utilities in at least seven states had reported incidents targeting internet-facing OT devices, including Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 PLCs, and that some activity degraded water operations. Separately, a Wisconsin Department of Natural Resources bulletin on July 28, 2026 said Minnesota had reported that threat actors gained access to PLCs during July 26–27 and dropped system pressures in several incidents, triggering alarms and law-enforcement response. That Wisconsin bulletin is authoritative for Wisconsin’s advisory but is still secondary with respect to underlying Minnesota incident specifics because it references Minnesota reporting not directly published in the cited bulletin’s attachment. FBI/EPA PSA, July 30, 2026; Wisconsin DNR bulletin, July 28, 2026
Attribution remains unresolved in this assessment. Reputable reporting later described U.S. officials as suspecting Iran or activity aligned with prior Iran-affiliated PLC targeting, and Wired reported on a leaked WaterISAC memo describing alignment with an earlier CISA-described Iran-affiliated campaign. However, MNIT explicitly said attribution was not established, and the leaked memo itself is not a public primary source from the investigating authorities. Accordingly, the report treats Iran-related claims as reported association or investigative lead, not confirmed attribution. MNIT, July 30, 2026; Wired, July 30, 2026; Washington Post, July 30, 2026
MNIT publicly stated on July 30, 2026 that malicious cyber activity targeted technology at more than 30 community water systems across Minnesota.
MNIT specifically identified PLCs and HMIs as technologies involved in most confirmed cases.
Braham reported its plant was offline and asked residents to minimize water use; Plymouth reported communications outages but continued operating; Star Tribune reported Maple Plain implemented contingency procedures.
MNIT recommended removal of unnecessary internet access from PLCs and HMIs and said it had identified methods of access; FBI/EPA and Wisconsin warnings described attacks on internet-facing PLCs using specific ports and affecting multiple states.
MNIT explicitly said similarities existed but investigators had not determined that every incident was carried out by the same actor.
Iran-related claims appear in reputable reporting and leaked-memo reporting, but the investigating Minnesota authority had not publicly attributed the activity as of July 30, 2026.
| Date / Time | Event | Source | Classification | Confidence |
|---|---|---|---|---|
| July 22, 2026 | FBI published alert titled “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.” Publicly available page confirms date and title; detailed overlap with Minnesota incidents is not fully public in the page retrieved. | FBI alert page | CONFIRMED FACT | MODERATE |
| July 26–27, 2026 | MNIT later reported the coordinated cyberattack targeted more than 30 community water systems during these dates. | Reuters syndication quoting MNIT; MNIT | CONFIRMED FACT | HIGH |
| Early morning, July 27, 2026 | South St. Paul identified a cybersecurity incident involving technology used to support portions of the city’s water utility system. | City of South St. Paul | CONFIRMED FACT | MODERATE |
| July 27, 2026 | Braham issued “Water Plant Issue” notice: plant offline for unknown reason; residents asked to minimize water use. | City of Braham | CONFIRMED FACT | HIGH |
| July 27, 2026, 2:05 p.m. | Plymouth stated water-facility communications were restored following a cyberattack; original update said communications outages had not affected water levels or quality. | City of Plymouth | CONFIRMED FACT | MODERATE |
| July 28, 2026 | Star Tribune reported more than 30 utilities were hit; Maple Plain declared a local state of emergency and implemented contingency procedures. | Star Tribune | CONFIRMED FACT / LEAD | MODERATE |
| July 28, 2026, 2:38 p.m. CDT | Wisconsin DNR warned Wisconsin systems of ongoing malicious activity; stated Minnesota reported threat actors accessed PLCs and in several incidents dropped system pressures between July 26–27. | Wisconsin DNR bulletin | ASSESSMENT | MODERATE |
| July 30, 2026, 2:37 p.m. | MNIT public statement: more than 30 community water systems impacted; most confirmed cases involved PLCs and HMIs; no attribution yet; no active requests to modify drinking-water use. | MNIT | CONFIRMED FACT | HIGH |
| July 30, 2026 | FBI/EPA PSA warned that since July 27, 2026 incidents affecting internet-facing PLCs had been reported in at least seven states; some degraded water operations. | FBI/EPA PSA | CONFIRMED FACT | HIGH |
| July 30, 2026 | WaterISAC posted a notice that the leaked memo regarding Minnesota water cyber activity had been shared to members as TLP:AMBER. | WaterISAC notice | CONFIRMED FACT | MODERATE |
| Impact Area | Supported Findings | Status | Sources |
|---|---|---|---|
| Cyber impact | Malicious activity involving water-system OT at 30+ Minnesota community water systems. | CONFIRMED FACT | MNIT |
| Loss of remote monitoring / communications | Plymouth reported communications outage at water facilities, later restored. | CONFIRMED FACT | Plymouth |
| Plant outage / control disruption | Braham plant offline for a period; AP reported attackers shut down operating controls that shut down well and treatment plant. | CONFIRMED FACT / ASSESSMENT | Braham; AP |
| Manual / contingency operations | Maple Plain reportedly implemented contingency procedures; AP/CBS reported transitions to manual operations in affected communities. | ASSESSMENT | Star Tribune; CBS |
| Water service interruption | Not established statewide. Some local disruptions occurred, but MNIT emphasized that “impacted” did not mean every community suffered service disruption. | UNRESOLVED | MNIT |
| Water quality degradation / contamination | No public evidence found confirming contamination or unsafe drinking water. Braham and Plymouth publicly said quality was not affected. MNIT said no active requests to modify drinking-water use statewide as of July 30. | CONFIRMED FACT for “no confirmed public evidence found”; UNRESOLVED for all systems individually | Braham; Plymouth; MNIT |
| Physical equipment damage | MNIT said the state continued to assess whether equipment issues or operational disruptions resulted directly from malicious activity. | UNRESOLVED | MNIT |
| Financial impact | INSUFFICIENT EVIDENCE in public sources reviewed. | INSUFFICIENT EVIDENCE | — |
| Public-safety impact | No confirmed injuries or confirmed contamination found in reviewed sources. Potential public-safety risk was discussed in warnings, not confirmed as realized consequence in Minnesota. | UNRESOLVED | Wisconsin DNR; MNIT |
ASSESSMENT MODERATE CONFIDENCE The Minnesota incidents share enough characteristics to be described as potentially related coordinated activity, especially by timing and OT target type. However, the public record does not support a high-confidence conclusion that all named and unnamed incidents were executed by one actor or through one exact intrusion method.
ATTRIBUTION: UNRESOLVED LOW CONFIDENCE
The public record supports only a reported association between the Minnesota incidents and prior Iran-affiliated PLC activity. It does not support confirmed attribution.
| Claim | Source | Reason Rejected / Not Accepted as Fact | Evidence Required for Validation |
|---|---|---|---|
| Iran definitively conducted the Minnesota attacks. | Wired leaked-memo reporting; Washington Post / NYT-based reports | Minnesota public authority had not attributed the activity; leaked memo is not equivalent to public forensic proof or official final attribution. | Official attribution statement with supporting technical or intelligence basis. |
| All 30+ incidents were conducted by the same actor. | Inferred from statewide timing | MNIT explicitly said investigators had not determined every incident was carried out by the same actor. | Shared forensic artifacts, infrastructure, or law-enforcement findings. |
| Specific Minnesota victims used Rockwell MicroLogix 1100/1400 PLCs. | FBI/EPA PSA | The PSA described broader observed multi-state behavior, not victim-specific identification for named Minnesota utilities. | Victim or investigator confirmation naming models used in the Minnesota incidents. |
| Pressure drops occurred in specific named Minnesota utilities. | Wisconsin DNR bulletin | Authoritative for warning context but secondary to underlying Minnesota source; no named victim-level Minnesota primary confirmation found in reviewed public sources. | Minnesota or victim utility statement documenting pressure impacts. |
| Water contamination occurred. | No validated primary source found | No authoritative public source reviewed confirmed contamination; some named utilities said quality was unaffected. | Water-quality test results, boil-water notices, or utility/public-health confirmation. |
| A specific CVE was exploited. | None validated | No public authoritative source identified a CVE for these Minnesota incidents. | Official forensic report or advisory naming the exploited vulnerability. |
| Claim | Classification | Source | Source Tier | Independent Corroboration | Confidence |
|---|---|---|---|---|---|
| 30+ Minnesota community water systems were targeted. | CONFIRMED FACT | MNIT | Tier 1 | Reuters/AP/Star Tribune repeat MNIT statement | HIGH |
| Most confirmed cases involved PLCs and HMIs used for remote monitoring/control. | CONFIRMED FACT | MNIT | Tier 1 | CBS/AP repeat MNIT | HIGH |
| Braham water plant went offline July 27 and residents were asked to minimize use. | CONFIRMED FACT | Braham | Tier 1 | AP / MPR | HIGH |
| Plymouth experienced water communications outage and restoration following cyberattack. | CONFIRMED FACT | Plymouth | Tier 1 | AP / local reporting | MODERATE |
| South St. Paul identified a cybersecurity incident affecting technology supporting portions of water utility system. | CONFIRMED FACT | South St. Paul | Tier 1 | Search-result snippet; local reporting | MODERATE |
| Maple Plain declared local state of emergency and used contingency procedures. | INVESTIGATIVE LEAD / likely fact | Star Tribune | Tier 3 | No primary city statement validated in this review | MODERATE |
| Some incidents likely involved internet-facing PLC exploitation. | ASSESSMENT | MNIT; FBI/EPA PSA; Wisconsin DNR | Tier 1 / Tier 2 | Multiple independent authorities | MODERATE |
| At least seven states reported similar incidents after July 27. | CONFIRMED FACT | FBI/EPA PSA | Tier 1 | AP/CBS/reuters references | HIGH |
| Pressure drops occurred in several incidents. | ASSESSMENT | Wisconsin DNR bulletin | Tier 1 for Wisconsin advisory / indirect for Minnesota | No Minnesota primary victim confirmation found here | MODERATE |
| Minnesota had not attributed the incidents as of July 30, 2026. | CONFIRMED FACT | MNIT | Tier 1 | AP repeats | HIGH |
| Iran may be linked. | UNRESOLVED / reported association | Wired; Washington Post | Tier 3 | Mutually reinforcing reporting, but not public primary forensic proof | LOW |
OVERALL JUDGMENT MODERATE CONFIDENCE A broad OT-focused cyber campaign affected Minnesota community water systems in late July 2026. ATTRIBUTION: UNRESOLVED