Minnesota Water Systems Attacks: Internet-Exposed PLCs Under Attack
| August 03, 2026
Key Takeaways
- A coordinated cyberattack in late July 2026 disrupted water and wastewater operations across more than 30 Minnesota communities.
- The FBI and EPA warned that malicious actors are tampering with internet-exposed PLCs in the water sector.
- The intrusions used no novel exploit or custom malware, only MicroLogix 1100 and 1400 controllers exposed directly online.
- Attackers changed device IP addresses and set passwords, locking operators out and causing loss of view and control.c
- Reported impacts included pressure loss and flooding, with pressure loss risking untreated groundwater seeping into pipes.
In late July 2026, more than 30 Minnesota communities lost operational visibility and control over water and wastewater equipment in a coordinated cyberattack, and the FBI and EPA issued a joint Public Service Announcement (PSA) warning that malicious cyber actors are tampering with internet-exposed Programmable Logic Controllers (PLCs) across the Water and Wastewater Sector (WWS) [1], [2].
The activity did not rely on a novel exploit or custom malware. Attackers reached PLCs that were directly reachable from the internet, changed their IP addresses and passwords, and left operators blind to the equipment those controllers were monitoring or driving. Reported operational effects included loss of pressure and flooding [1].
In this blog, we will explain how the Minnesota water utility attacks unfolded, the PLC tradecraft behind them, and their operational impact.
What Happened in the Minnesota Water Utility Cyberattack?
Water and wastewater utilities in over 30 Minnesota communities were disrupted on Sunday and Monday, July 26 and 27, 2026, in what Minnesota IT Services described as a coordinated cyberattack.
Which Minnesota Communities Were Affected?
The City of Braham, a community of roughly 1,700 residents, posted on Monday morning that its water plant had gone offline for an unknown reason and asked residents to limit water use because the city water tower held only a limited supply.
In Plymouth, a Minneapolis suburb of about 80,000 people, the affected assets were equipment connected over cellular communications at two water towers and multiple lift stations. The city IT division disconnected that equipment from the network to stop the attack and prevent retargeting while it was reconfigured.
Who Is Behind the Attacks on U.S. Water Utilities?
Attribution remains open. Minnesota state and local officials declined to say who was responsible, and TJ Sayers, senior director of threat intelligence at the Center for Internet Security, confirmed the attacks had not been attributed to any party and that it was unclear whether the PLCs CISA warned about were involved [2].
Context still matters for defenders. CISA and partner agencies had recently updated an advisory urgently warning about ongoing attempts by Iranian hacking groups, including CyberAv3ngers, to target internet-connected OT devices such as PLCs.
U.S. strikes near Iran's southern coast earlier in the month destroyed a water facility and cut water access for more than 20,000 people, and the following day the group Hanzala claimed it had breached water utility systems in Bakersfield, Chico, Salinas, and Stockton, California, saying it had held back from disrupting supply as a warning to Washington.
How Did Threat Actors Attack Internet-Facing PLCs in Water Systems?
The tradecraft described in the FBI and EPA PSA is simple, repeatable, and effective against unsegmented OT networks.
Initial Access Through Internet-Exposed PLCs
The actors reached MicroLogix 1100 and 1400 series controllers that were directly exposed to the internet, with no gateway or firewall mediating access [1]. In Plymouth, the affected assets were reachable over cellular links at water towers and lift stations, the same class of remote field connectivity the PSA singles out for hardening.
Configuration Tampering to Cause Loss of View and Loss of Control
After gaining remote access, the actors changed device IP addresses and enabled and set device passwords. Both actions removed legitimate operators from the loop: monitoring and control functionality was lost, producing loss of view and, in some cases, loss of function over connected equipment.
Unauthorized Modification of PLC Project Files and Ladder Logic
At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several of its sites. This is the more serious variant of the same intrusion. Changing logic rather than only configuration means the process itself can be driven into an unsafe state, and it means a restored backup can silently reintroduce attacker logic if it is not validated first.
Repeatable Attack Paths Created by Shared Third-Party Integrator Designs
Across multiple victims, the FBI observed similar network setups delivered by third parties. Where one integrator has deployed the same vulnerable network and hardware pattern across many customers, a single working technique multiplies across the customer base. That shared-design factor helps explain how more than 30 communities were hit inside a single weekend.
What Operational Impact Did the Attacks Have?
Reported effects included loss of pressure and flooding. Pressure loss carries a downstream public health risk because it can allow untreated groundwater to seep into pipes. How badly any single utility was affected depended on whether the PLC was monitoring or controlling equipment, whether it was an 1100 or a 1400, what function it supported, and whether the utility could fall back to manual operation.
References
[1] “[No title].” Accessed: Aug. 02, 2026. [Online]. Available: https://www.ic3.gov/PSA/2026/PSA260730.pdf
[2] C. Wood, “Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities,” StateScoop. Accessed: Aug. 02, 2026. [Online]. Available: http://statescoop.com/coordinated-cyberattack-disrupts-water-utilities-in-30-minnesota-communities/
