Minnesota Water Systems Attacks: Internet-Exposed PLCs Under Attack

Umut Bayram | 4 MIN READ

| August 03, 2026

Key Takeaways

  • A coordinated cyberattack in late July 2026 disrupted water and wastewater operations across more than 30 Minnesota communities.
  • The FBI and EPA warned that malicious actors are tampering with internet-exposed PLCs in the water sector.
  • The intrusions used no novel exploit or custom malware, only MicroLogix 1100 and 1400 controllers exposed directly online.
  • Attackers changed device IP addresses and set passwords, locking operators out and causing loss of view and control.c
  • Reported impacts included pressure loss and flooding, with pressure loss risking untreated groundwater seeping into pipes.

In late July 2026, more than 30 Minnesota communities lost operational visibility and control over water and wastewater equipment in a coordinated cyberattack, and the FBI and EPA issued a joint Public Service Announcement (PSA) warning that malicious cyber actors are tampering with internet-exposed Programmable Logic Controllers (PLCs) across the Water and Wastewater Sector (WWS) [1], [2].

The activity did not rely on a novel exploit or custom malware. Attackers reached PLCs that were directly reachable from the internet, changed their IP addresses and passwords, and left operators blind to the equipment those controllers were monitoring or driving. Reported operational effects included loss of pressure and flooding [1].

In this blog, we will explain how the Minnesota water utility attacks unfolded, the PLC tradecraft behind them, and their operational impact.

What Happened in the Minnesota Water Utility Cyberattack?

Water and wastewater utilities in over 30 Minnesota communities were disrupted on Sunday and Monday, July 26 and 27, 2026, in what Minnesota IT Services described as a coordinated cyberattack.

Which Minnesota Communities Were Affected?

The City of Braham, a community of roughly 1,700 residents, posted on Monday morning that its water plant had gone offline for an unknown reason and asked residents to limit water use because the city water tower held only a limited supply.

In Plymouth, a Minneapolis suburb of about 80,000 people, the affected assets were equipment connected over cellular communications at two water towers and multiple lift stations. The city IT division disconnected that equipment from the network to stop the attack and prevent retargeting while it was reconfigured.

Who Is Behind the Attacks on U.S. Water Utilities?

Attribution remains open. Minnesota state and local officials declined to say who was responsible, and TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed the attacks had not been attributed to any party and that it was unclear whether the PLCs CISA warned about were involved [2].

Context still matters for defenders. CISA and partner agencies had recently updated an advisory urgently warning about ongoing attempts by Iranian hacking groups, including CyberAv3ngers, to target internet-connected OT devices such as PLCs.

U.S. strikes near Iran's southern coast earlier in the month destroyed a water facility and cut water access for more than 20,000 people, and the following day the group Hanzala claimed it had breached water utility systems in Bakersfield, Chico, Salinas, and Stockton, California, saying it had held back from disrupting supply as a warning to Washington.

How Did Threat Actors Attack Internet-Facing PLCs in Water Systems?

The tradecraft described in the FBI and EPA PSA is simple, repeatable, and effective against unsegmented OT networks.

Initial Access Through Internet-Exposed PLCs

The actors reached MicroLogix 1100 and 1400 series controllers that were directly exposed to the internet, with no gateway or firewall mediating access [1]. In Plymouth, the affected assets were reachable over cellular links at water towers and lift stations, the same class of remote field connectivity the PSA singles out for hardening.

Configuration Tampering to Cause Loss of View and Loss of Control

After gaining remote access, the actors changed device IP addresses and enabled and set device passwords. Both actions removed legitimate operators from the loop: monitoring and control functionality was lost, producing loss of view and, in some cases, loss of function over connected equipment.

Unauthorized Modification of PLC Project Files and Ladder Logic

At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several of its sites. This is the more serious variant of the same intrusion. Changing logic rather than only configuration means the process itself can be driven into an unsafe state, and it means a restored backup can silently reintroduce attacker logic if it is not validated first.

Repeatable Attack Paths Created by Shared Third-Party Integrator Designs

Across multiple victims, the FBI observed similar network setups delivered by third parties. Where one integrator has deployed the same vulnerable network and hardware pattern across many customers, a single working technique multiplies across the customer base. That shared-design factor helps explain how more than 30 communities were hit inside a single weekend.

What Operational Impact Did the Attacks Have?

Reported effects included loss of pressure and flooding. Pressure loss carries a downstream public health risk because it can allow untreated groundwater to seep into pipes. How badly any single utility was affected depended on whether the PLC was monitoring or controlling equipment, whether it was an 1100 or a 1400, what function it supported, and whether the utility could fall back to manual operation.

References

[1] “[No title].” Accessed: Aug. 02, 2026. [Online]. Available: https://www.ic3.gov/PSA/2026/PSA260730.pdf

[2] C. Wood, “Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities,” StateScoop. Accessed: Aug. 02, 2026. [Online]. Available: http://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/

 
On July 26 and 27, 2026, water and wastewater utilities in more than 30 Minnesota communities were disrupted in what Minnesota IT Services described as a coordinated cyberattack. Operators lost visibility and control over water and wastewater equipment. Reported operational effects included loss of pressure and flooding.
The City of Braham, home to about 1,700 residents, reported that its water plant went offline for an unknown reason and asked residents to limit water use because the water tower held a limited supply. In Plymouth, a Minneapolis suburb of roughly 80,000 people, equipment at two water towers and multiple lift stations was affected.
Attribution remains open. Minnesota state and local officials declined to name a responsible party, and TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed the attacks had not been attributed to anyone. It is also unclear whether the PLCs CISA warned about were involved.
CISA and partner agencies recently updated an advisory urgently warning about ongoing attempts by Iranian hacking groups, including CyberAv3ngers, to target internet-connected OT devices such as PLCs. Separately, the group Hanzala claimed it had breached water utility systems in Bakersfield, Chico, Salinas, and Stockton, California. The Minnesota attacks themselves remain unattributed.
A programmable logic controller, or PLC, is the device that monitors or drives water and wastewater equipment such as pumps and lift stations. In these attacks, the targeted units were MicroLogix 1100 and 1400 series controllers. Whether a utility suffered loss of monitoring or loss of control depended on the role its PLC played.
The actors reached controllers that were directly exposed to the internet, with no gateway or firewall mediating access, so no novel exploit or custom malware was required. After gaining remote access, they changed device IP addresses and enabled and set device passwords, removing legitimate operators from the loop and causing loss of view and control.
Reported effects in Minnesota included loss of pressure and flooding. Pressure loss carries a downstream public health risk because it can allow untreated groundwater to seep into pipes. Severity varied by utility, depending on the function of the PLC, whether it was an 1100 or 1400 series, and whether manual operation was possible.

Table of Contents

Ready to start? Request a demo