Public incident case study · Water and wastewater · United States

Minnesota Water Systems PLC/HMI Attacks Case Study

Coordinated OT attacks 26–27 July 2026 · investigation and attribution ongoing

30+Minnesota water systems affectedMinnesota IT Services confirmed a coordinated cyber-attack against operational technology at more than 30 community water systems. Most confirmed cases involved programmable logic controllers or human-machine interfaces used for remote monitoring and control.
100+
internet-exposed U.S. water-sector systems targeted in July
~90 min
to restore Braham’s water plant
US$14,495
proposed replacement of 15 older Alpena cellular modems
0 confirmed
drinking-water quality impacts at publicly identified Minnesota victims
Executive summary

Incident sequence

  1. Coordinated malicious activity reached operational technology

    Minnesota IT Services reported that malicious cyber activity affected technology at more than 30 community water systems on 26 and 27 July. Most confirmed cases involved programmable logic controllers and human-machine interfaces used to remotely monitor and control water-system equipment. Investigators identified similarities in timing and affected technology, while cautioning that they had not established that every incident was performed by the same actor.

  2. Local utilities maintained service despite loss of automated capability

    Publicly identified Minnesota victims experienced different operational effects. Braham lost operating controls for its well and treatment plant, but isolated the system, restored a backup, and restarted it in approximately 90 minutes without residents losing water service. Plymouth lost communications with PLC-connected infrastructure and switched to manual procedures without an impact to water levels or quality. South St. Paul similarly invoked contingency procedures and continued water and wastewater operations manually.

  3. A suspected cyber-related disruption triggered a public-health procedure

    CCWA reported that unauthorised cyber activity may have caused or contributed to an operational disruption that reduced water pressure and triggered a precautionary boil-water advisory. Service returned within hours, and the advisory was lifted after water-quality testing confirmed the water met applicable safety standards. CCWA did not identify the affected controllers, PLC models, initial-access path, or whether logic was altered. Its report therefore cannot confirm that Clayton County was among the MicroLogix compromises described by the FBI.

  4. Federal investigation exposed a wider PLC campaign

    The FBI and EPA subsequently warned that water and wastewater utilities in at least seven states had reported attacks against internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs. CISA later reported malicious activity targeting more than 100 internet-exposed water-sector systems during July. Alpena Township became a named Michigan example after losing UIS/CRUiSE remote monitoring and reprogramming PLCs before reconnection. EGLE reported that nine Michigan municipal water systems experienced activity consistent with the warnings; all continued operating safely and no known public-health impacts occurred. The FBI reported pressure loss and flooding across its victim set, but CCWA's statement does not establish a shared controller type or access path. Attribution remains unresolved.

Full incident chronology

Incident timeline

Incident chronology.

  1. 26–27 Jul 2026

    Coordinated activity

    Malicious access reached more than 30 community water systems

    Minnesota identified a concentrated campaign affecting PLCs and HMIs used for remote monitoring and control, while cautioning that common authorship was not established for every case.

  2. 26–27 Jul 2026

    Operational impact

    Several utilities lost automated visibility or control

    Braham, Plymouth, and South St. Paul reported different losses of control or communications and invoked local contingency procedures.

  3. During the attacks

    Braham recovery

    A backup restored the affected plant in approximately 90 minutes

    Braham isolated the compromised system, restored a backup, and restarted before residents lost water service.

  4. 26–30 Jul 2026

    Manual continuity

    Other utilities operated manually until communications returned

    Plymouth and other affected operators maintained service through manual procedures without a reported water-quality impact.

  5. Named Michigan victim

    Alpena Township lost remote monitoring through UIS SCADA's CRUiSE

    Township and operating-contractor personnel reported loss of remote SCADA visibility. Public reporting does not establish the precise compromise path through UIS, customer PLCs, cellular infrastructure, or a combination.

  6. 27 Jul–5 Aug 2026

    PLC-level recovery

    F&V Operations reprogrammed PLCs at multiple sites before reconnection

    Alpena mainly used SCADA for monitoring, but its operating contractor still had to reprogramme multiple controllers so affected sites could reconnect to the central platform.

  7. Public-health response

    CCWA issued a precautionary boil-water advisory after reduced pressure

    CCWA reported that unauthorised cyber activity may have caused or contributed to a temporary operational-system and water-service disruption in north Clayton County. It restored service within hours and lifted the advisory after required water-quality testing confirmed applicable safety standards.

  8. State update

    Minnesota reported no active public water-use restrictions

    The state’s follow-up distinguished the technology impact from the absence of a confirmed drinking-water safety consequence.

  9. Federal warning

    The FBI and EPA linked the incidents to a wider multi-state PLC campaign

    Federal reporting described password and IP changes, loss of monitoring and control, modified project files, and broader consequences including pressure loss and flooding.

  10. Proposed architecture change

    Alpena received a US$14,495 proposal to replace 15 older cellular modems

    The tabled proposal covers modem replacement, antennas, programming, firewalls, and IP whitelisting because the older hardware cannot support UIS's new security measures.

  11. Aug 2026

    CISA scale disclosure

    CISA reported more than 100 internet-exposed U.S. water-sector systems targeted

    CISA described July activity commonly involving PLCs connected directly to cellular modems. The count covers systems targeted, not utilities confirmed compromised, and the disclosure did not make an incident-specific federal attribution.

Lykos analysis

What organisations should learn.

Why this matters to executives and boards

The Minnesota incidents demonstrate how common OT architecture can turn a weakness at individual small utilities into a coordinated sector-wide event. CCWA adds a named example where a suspected cyber-related operational event crossed into a precautionary public-health response, while rapid restoration and water-quality verification contained the customer consequence. Alpena adds a concrete shared-platform dependency: PLCs at wells, booster stations, and lift stations communicated over cellular modems to UIS SCADA's CRUiSE service, and remote monitoring was lost when that environment was affected. Attackers did not need custom ICS malware to create consequence; loss of trusted monitoring and communications was enough to require controller reprogramming and hardware-replacement planning.

Readiness gaps and lessons visible in the public record

Minnesota and Alpena have not published victim-specific technical retrospectives, so the same initial-access path should not be attributed to every utility or to UIS's platform without further evidence. The public record nevertheless supports identifying internet-exposed ICS and undocumented cellular connections, testing how shared SCADA providers affect multiple customers, removing unnecessary exposure, routing required access through secure gateways, using firewalls and IP allow lists, and maintaining known-good controller configurations. Alpena's proposed replacement also shows why recovery planning must include legacy cellular hardware that cannot support modern security controls. The M-32 booster station could accept pump-setpoint changes through SCADA, but no evidence indicates those setpoints were altered during this incident.

How Lykos helps

Turn the lesson into tested capability.

PLC, HMI and control-system security

Test cyber response where controller access, operational authority, and safety constraints intersect.

Explore Tabletop Exercises

Asset and vulnerability management

Establish whether critical assets, exposures, and remediation priorities are known before response begins.

Explore Capability Validation

Not sure where to begin? Start with Capability Validation.

Public record

Sources

Public record reviewed 29 Aug 2026.

  1. MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructureMinnesota IT Services · 28 Jul 2026 · State government statement
  2. Minnesota continues response to cyber activity affecting community water systemsMinnesota IT Services · 30 Jul 2026 · State government statement
  3. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational DisruptionsFederal Bureau of Investigation and U.S. Environmental Protection Agency · 30 Jul 2026 · Federal cybersecurity advisory
  4. Clayton County Water Authority Security Advisory: Cyber Threat Awareness & ResponseClayton County Water Authority · 3 Aug 2026 · Operator reporting
  5. Communications restored at Plymouth water facilitiesCity of Plymouth, Minnesota · 28 Jul 2026 · Local government statement
  6. Cyber-attacks on Minnesota water systems investigated as officials warn about Iranian hackersAssociated Press · 30 Jul 2026 · News reporting
  7. U.S. investigating if Iran was behind cyber-attack on water systems in 7 states, including Minnesota and MichiganCBS News · 1 Aug 2026 · Investigative reporting with official sources
  8. Assessing Security of Public Water SystemsMinnesota Department of Health · 6 Aug 2026 · State government guidance
  9. Internet Exposure Reduction GuidanceCybersecurity and Infrastructure Security Agency · 4 Jun 2025 · Government guidance
  10. CISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksSecurityWeek · 26 Aug 2026 · Industry reporting
  11. Alpena Township board tables SCADA upgrade after July cyberattackThe Alpena News · 28 Aug 2026 · Local reporting citing operator and city
  12. Cybersecurity for the water sectorMichigan Department of Environment, Great Lakes, and Energy · Undated · State government guidance