Public incident case study · Water and wastewater · United States
Minnesota Water Systems PLC/HMI Attacks Case Study
Coordinated OT attacks 26–27 July 2026 · investigation and attribution ongoing
- 100+
- internet-exposed U.S. water-sector systems targeted in July
- ~90 min
- to restore Braham’s water plant
- US$14,495
- proposed replacement of 15 older Alpena cellular modems
- 0 confirmed
- drinking-water quality impacts at publicly identified Minnesota victims
Executive summary
Incident sequence
Coordinated malicious activity reached operational technology
Minnesota IT Services reported that malicious cyber activity affected technology at more than 30 community water systems on 26 and 27 July. Most confirmed cases involved programmable logic controllers and human-machine interfaces used to remotely monitor and control water-system equipment. Investigators identified similarities in timing and affected technology, while cautioning that they had not established that every incident was performed by the same actor.
Local utilities maintained service despite loss of automated capability
Publicly identified Minnesota victims experienced different operational effects. Braham lost operating controls for its well and treatment plant, but isolated the system, restored a backup, and restarted it in approximately 90 minutes without residents losing water service. Plymouth lost communications with PLC-connected infrastructure and switched to manual procedures without an impact to water levels or quality. South St. Paul similarly invoked contingency procedures and continued water and wastewater operations manually.
A suspected cyber-related disruption triggered a public-health procedure
CCWA reported that unauthorised cyber activity may have caused or contributed to an operational disruption that reduced water pressure and triggered a precautionary boil-water advisory. Service returned within hours, and the advisory was lifted after water-quality testing confirmed the water met applicable safety standards. CCWA did not identify the affected controllers, PLC models, initial-access path, or whether logic was altered. Its report therefore cannot confirm that Clayton County was among the MicroLogix compromises described by the FBI.
Federal investigation exposed a wider PLC campaign
The FBI and EPA subsequently warned that water and wastewater utilities in at least seven states had reported attacks against internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs. CISA later reported malicious activity targeting more than 100 internet-exposed water-sector systems during July. Alpena Township became a named Michigan example after losing UIS/CRUiSE remote monitoring and reprogramming PLCs before reconnection. EGLE reported that nine Michigan municipal water systems experienced activity consistent with the warnings; all continued operating safely and no known public-health impacts occurred. The FBI reported pressure loss and flooding across its victim set, but CCWA's statement does not establish a shared controller type or access path. Attribution remains unresolved.
Full incident chronology
Incident timeline
Incident chronology.
- 26–27 Jul 2026
Coordinated activity
Malicious access reached more than 30 community water systems
Minnesota identified a concentrated campaign affecting PLCs and HMIs used for remote monitoring and control, while cautioning that common authorship was not established for every case.
- 26–27 Jul 2026
Operational impact
Several utilities lost automated visibility or control
Braham, Plymouth, and South St. Paul reported different losses of control or communications and invoked local contingency procedures.
- During the attacks
Braham recovery
A backup restored the affected plant in approximately 90 minutes
Braham isolated the compromised system, restored a backup, and restarted before residents lost water service.
- 26–30 Jul 2026
Manual continuity
Other utilities operated manually until communications returned
Plymouth and other affected operators maintained service through manual procedures without a reported water-quality impact.
Named Michigan victim
Alpena Township lost remote monitoring through UIS SCADA's CRUiSE
Township and operating-contractor personnel reported loss of remote SCADA visibility. Public reporting does not establish the precise compromise path through UIS, customer PLCs, cellular infrastructure, or a combination.
- 27 Jul–5 Aug 2026
PLC-level recovery
F&V Operations reprogrammed PLCs at multiple sites before reconnection
Alpena mainly used SCADA for monitoring, but its operating contractor still had to reprogramme multiple controllers so affected sites could reconnect to the central platform.
Public-health response
CCWA issued a precautionary boil-water advisory after reduced pressure
CCWA reported that unauthorised cyber activity may have caused or contributed to a temporary operational-system and water-service disruption in north Clayton County. It restored service within hours and lifted the advisory after required water-quality testing confirmed applicable safety standards.
State update
Minnesota reported no active public water-use restrictions
The state’s follow-up distinguished the technology impact from the absence of a confirmed drinking-water safety consequence.
Federal warning
The FBI and EPA linked the incidents to a wider multi-state PLC campaign
Federal reporting described password and IP changes, loss of monitoring and control, modified project files, and broader consequences including pressure loss and flooding.
Proposed architecture change
Alpena received a US$14,495 proposal to replace 15 older cellular modems
The tabled proposal covers modem replacement, antennas, programming, firewalls, and IP whitelisting because the older hardware cannot support UIS's new security measures.
- Aug 2026
CISA scale disclosure
CISA reported more than 100 internet-exposed U.S. water-sector systems targeted
CISA described July activity commonly involving PLCs connected directly to cellular modems. The count covers systems targeted, not utilities confirmed compromised, and the disclosure did not make an incident-specific federal attribution.
Lykos analysis
What organisations should learn.
Why this matters to executives and boards
The Minnesota incidents demonstrate how common OT architecture can turn a weakness at individual small utilities into a coordinated sector-wide event. CCWA adds a named example where a suspected cyber-related operational event crossed into a precautionary public-health response, while rapid restoration and water-quality verification contained the customer consequence. Alpena adds a concrete shared-platform dependency: PLCs at wells, booster stations, and lift stations communicated over cellular modems to UIS SCADA's CRUiSE service, and remote monitoring was lost when that environment was affected. Attackers did not need custom ICS malware to create consequence; loss of trusted monitoring and communications was enough to require controller reprogramming and hardware-replacement planning.
Readiness gaps and lessons visible in the public record
Minnesota and Alpena have not published victim-specific technical retrospectives, so the same initial-access path should not be attributed to every utility or to UIS's platform without further evidence. The public record nevertheless supports identifying internet-exposed ICS and undocumented cellular connections, testing how shared SCADA providers affect multiple customers, removing unnecessary exposure, routing required access through secure gateways, using firewalls and IP allow lists, and maintaining known-good controller configurations. Alpena's proposed replacement also shows why recovery planning must include legacy cellular hardware that cannot support modern security controls. The M-32 booster station could accept pump-setpoint changes through SCADA, but no evidence indicates those setpoints were altered during this incident.
How Lykos helps
Turn the lesson into tested capability.
PLC, HMI and control-system security
Test cyber response where controller access, operational authority, and safety constraints intersect.
Explore Tabletop ExercisesAsset and vulnerability management
Establish whether critical assets, exposures, and remediation priorities are known before response begins.
Explore Capability ValidationRemote access
Review and exercise the controls and escalation paths surrounding remote administration.
Explore Capability ValidationNot sure where to begin? Start with Capability Validation.
Public record
Sources
Public record reviewed 29 Aug 2026.
- MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructureMinnesota IT Services · 28 Jul 2026 · State government statement
- Minnesota continues response to cyber activity affecting community water systemsMinnesota IT Services · 30 Jul 2026 · State government statement
- Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational DisruptionsFederal Bureau of Investigation and U.S. Environmental Protection Agency · 30 Jul 2026 · Federal cybersecurity advisory
- Clayton County Water Authority Security Advisory: Cyber Threat Awareness & ResponseClayton County Water Authority · 3 Aug 2026 · Operator reporting
- Communications restored at Plymouth water facilitiesCity of Plymouth, Minnesota · 28 Jul 2026 · Local government statement
- Cyber-attacks on Minnesota water systems investigated as officials warn about Iranian hackersAssociated Press · 30 Jul 2026 · News reporting
- U.S. investigating if Iran was behind cyber-attack on water systems in 7 states, including Minnesota and MichiganCBS News · 1 Aug 2026 · Investigative reporting with official sources
- Assessing Security of Public Water SystemsMinnesota Department of Health · 6 Aug 2026 · State government guidance
- Internet Exposure Reduction GuidanceCybersecurity and Infrastructure Security Agency · 4 Jun 2025 · Government guidance
- CISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksSecurityWeek · 26 Aug 2026 · Industry reporting
- Alpena Township board tables SCADA upgrade after July cyberattackThe Alpena News · 28 Aug 2026 · Local reporting citing operator and city
- Cybersecurity for the water sectorMichigan Department of Environment, Great Lakes, and Energy · Undated · State government guidance