Coordinated Cyberattack Disrupts 30+ Minnesota Water Utilities, CISA Warns of Wider Threat

A coordinated cyberattack disrupted operational technology at more than 30 community water systems across Minnesota over the weekend of July 26–27, prompting the state’s IT services agency to activate its cybersecurity incident response plan. Municipalities including Braham, Plymouth, South St. Paul, and Maple Plain reported equipment malfunctions, communications failures, and disrupted automated controls; Braham’s water plant was forced offline entirely, and the city asked residents to conserve water while staff switched to manual operations.

The U.S. Cybersecurity and Infrastructure Security Agency responded with an urgent bulletin warning of a broader, sustained increase in attacks against internet-exposed programmable logic controllers (PLCs) in the water and wastewater sector. According to the agency, attackers have been changing device passwords to lock out legitimate operators, altering IP configurations to sever devices from remote management, and taking other actions capable of causing operational disruption or physical damage. CISA noted that even utilities with relatively mature cybersecurity programs have been affected, and it specifically flagged Rockwell Automation MicroLogix 1400 controllers as a target of recent activity.

Independent research from cybersecurity firm Censys found more than 4,100 internet-exposed Rockwell/Allen-Bradley devices, over 4,100 Siemens devices, and more than 2,000 Schneider Electric devices reachable from the public internet, though it cautioned that exposure alone does not mean a device has been compromised. The firm also highlighted a common blind spot: nearly half of the exposed Rockwell devices are reachable through undocumented cellular modems connected via commercial carriers, bypassing traditional network perimeter defenses entirely.

CISA is urging critical infrastructure operators to remove PLCs and other operational technology from direct internet exposure immediately, or, where that isn’t feasible, to restrict access through a VPN or gateway device, change default passwords, and limit connections to an allow-list of approved IP addresses. The episode adds to a growing pattern of attacks against small and mid-sized water utilities, which often operate with limited cybersecurity staffing and budgets despite controlling infrastructure critical to public health.

Read the original report →