Minnesota Water Cyberattack: FBI and EPA Warn of PLC Attacks Across Seven States
Key Takeaways
- A coordinated cyberattack hit operational technology at more than 30 Minnesota community water systems on July 26 and 27, 2026.
- On July 30, the FBI and EPA issued PSA I-073026-PSA, reporting incidents at water and wastewater utilities in at least seven states since July 27, some of which degraded water operations.
- The devices involved are Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs exposed directly to the internet.
- Attackers changed device IP addresses and set passwords, locking operators out of monitoring and, in some cases, control.
- Every utility that recovered cleanly did so by falling back to manual operation.
- Separately, Infrastructure Destruction Squad, the group behind the BLACKNET-00 ransomware builder, spent July selling OT attack tooling that names the same controller vendors.
Between Sunday, July 26 and Monday, July 27, water utility staff across Minnesota began finding that their equipment had stopped answering. In Braham, a city of 1,700 north of Minneapolis, crews found the well feeding the water tower malfunctioning and the treatment plant offline. In Plymouth, cellular communications failed at two water towers and several wastewater lift stations. By Tuesday, Minnesota IT Services (MNIT) had confirmed a coordinated cyberattack against operational technology at more than 30 community water systems.
Four days later, the picture widened. On July 30, the FBI and the Environmental Protection Agency issued Public Service Announcement I-073026-PSA, reporting that utilities in at least seven states had reported similar incidents since July 27, some of which degraded water operations. CISA published a companion alert the same day, telling operators to pull exposed controllers off the internet immediately. The activity follows the updated joint advisory we covered here, and no agency has attributed it to anyone.
What the FBI and EPA Advisory Says
| Advisory | FBI/EPA PSA I-073026-PSA, July 30, 2026 |
| Sector | Water and Wastewater Systems |
| Affected devices | Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs |
| Reporting window | Incidents reported to the FBI since July 27, 2026 |
| Scope | Utilities in at least seven states |
| Attribution | None published |
| Reported effects | Loss of monitoring and control, loss of pressure, flooding |
The tradecraft differs from the earlier advisory, which centered on rewriting controller logic. Here the actors changed device IP addresses and set passwords, leaving the controllers running while operators lost sight of them, and lost control where a device was actuating equipment.
Reported effects included loss of pressure and flooding. Two findings generalize: several victims shared network builds from the same third parties, letting one success repeat across an integrator’s customers, and CISA warns the targeting includes vendor-installed cellular modems that are undocumented and missing from attack surface scans.
Inside the Minnesota Water Cyberattack
Braham’s crews isolated the affected system, restored a backup, and had the plant treating water again in roughly 90 minutes. The city asked residents to minimize use while the tower carried the load, then lifted the request. Plymouth operated manually through its communications failures. South St. Paul moved public works staff to manual control and reported no impact to treatment, quality, pressure, or delivery, and no sign that customer data was touched. Maple Plain declared a local state of emergency to support its response. MNIT said on July 28 that no Minnesota city had an active request out for residents to change their water use.
Two patterns run through all of it. Recovery depended on human operability, which is exactly the capability the federal guidance asks operators to rehearse. And the incidents were linked by timing and technique before they were linked by evidence: MNIT has said the timing, access methods, and targeted infrastructure share characteristics with other coordinated incidents federal partners have observed, while stating it cannot discuss formal attribution or confirm that every incident involved the same actor.
Is Iran Behind the Attacks?
Investigators are examining whether Iranian hackers are responsible, and separately whether the activity was staged to appear Iran-based during an active conflict. Assessments could change as technical evidence accumulates.
In March 2026, the Justice Department seized four domains and stated that Iran’s Ministry of Intelligence and Security operates Handala as a fictitious persona, with an FBI affidavit asserting that Handala, Justice Homeland, and Karma Below are run by the same individuals. Handala is tracked elsewhere as Void Manticore, Banished Kitten, and Storm-0842. Personas that can be issued and retired at will are hard to reason about as distinct adversaries.
Handala’s messaging has tracked the advisories closely. On July 23, the same day our earlier post was published, the group claimed a cyber operation against operational technology infrastructure in the state of Maryland and said that manipulating PLCs and SCADA systems was only part of its capabilities, naming water, electricity, and fuel networks as future targets. An IRGC-branded Telegram channel, @SEPAHCYBERY, amplified the claim the same day and tied it explicitly to the FBI advisory covering Rockwell Automation, Schneider Electric, and Siemens equipment, framing US critical infrastructure as the front line of coming attacks.

IRGC-branded Telegram channel @SEPAHCYBERY amplifying Handala’s Maryland claim and warning that water, electricity, and fuel networks would follow (Source: Telegram, July 23, 2026)
Channels of this kind function as propaganda amplifiers rather than official IRGC outlets, and Handala’s own record is mixed: it claimed a breach at a California water provider in June and said it could have disrupted the water supply, while the utility reported no unauthorized access to the networks that control supply. On July 25, it claimed an attack on a Wisconsin internet service provider.
None of this is new ground for the water sector. Iranian-affiliated actors ran a comparable playbook in late 2023, when CyberAv3ngers logged into internet-exposed Unitronics controllers at US water systems using default credentials, and the tempo has climbed through 2026 alongside the broader Iran-Israel-US cyber conflict. For an operator, the attribution question changes little. An exposed controller with a weak password is reachable by whoever claims credit that week.
Infrastructure Destruction Squad: SCADA Attack ToolKit
Infrastructure Destruction Squad, the Telegram-based group behind the BLACKNET-00 ransomware builder SOCRadar analyzed in April, spent July monetizing the same exposed-OT approach, and escalated across three posts in twelve days.
July 8, selling the scanner: The group advertised a toolkit called TRK25 ADVANCED SCADA for $1,000, described as an internet-wide scanner for exposed industrial devices. The vendor list in the advertisement is worth reading against the federal advisories: Rockwell Automation, Allen-Bradley, Schneider, Modicon, and Siemens all appear, alongside GE, ABB, Honeywell, Emerson, Mitsubishi, Omron, WAGO, Beckhoff, and Phoenix Contact. Advertised protocol coverage overlaps the OT ports named in AA26-097A, including 502, 44818, 102, and 22, and extends to DNP3, OPC, BACnet, VNC, and RDP. The listed modules run from HMI screenshot capture and interface defacement to Modbus register writes, Siemens S7 stop and start commands, backdoor persistence, and denial of service.
The evidence posted alongside it is thinner than the pitch. One screenshot shows the login panel of a SenNet OWA31 datalogger, an IEC 870-5-102 energy metering device from a Spanish vendor, sitting on the open internet with an incorrect-password message on screen. The second shows a municipal street lighting control page for a project in Catalonia. Both demonstrate exposure rather than control.
July 15, selling the access: The operator claimed full compromise of a power plant in Daudkandi, Bangladesh, offering the access for $200 and asserting the ability to disable the plant’s SCADA system, cooling, internal communications, surveillance recording, and core switch, with regional blackouts as the consequence. The supporting screenshots are an unauthenticated SNMP walk of a MikroTik hEX lite router running RouterOS 6.49.6, with a configuration date of April 2022. The walk exposes the plant name, the operator’s support contact domain, interface counters, a VLAN, a GRE tunnel, and a Cisco SG300 switch. It is read-only reconnaissance of undocumented edge networking gear, which is precisely the exposure CISA flagged, and it is a long way from control of generators.

Unauthenticated SNMP walk posted as proof of access, exposing device inventory on a MikroTik router at the targeted power plant, including interface counters, a GRE tunnel, and a downstream Cisco switch (Source: Telegram, July 15, 2026)
July 20, extortion: The channel posted a threat against a city gas distributor in India, naming nine metering and distribution stations across greater Mumbai and giving the company 75 hours to pay. It described a claimed tool for issuing commands to PLCs that would raise temperature readings gradually to stay under early warning thresholds, then spike them to force pressure buildup, valve failure, and pipeline rupture into residential areas. The basis offered for all of it was data exfiltrated from the company’s IT systems, which is a station list rather than an OT foothold.
None of these claims has been independently verified, neither claimed victim has disclosed an incident, and the described consequences run far ahead of the posted evidence.
What Operators Should Do Now
- Take PLCs off the public internet: Broker remote access through a secure gateway or jump host so no OT system is directly reachable.
- Audit cellular modems: Secure them with strong authentication and current firmware, enable and review logs, and move toward isolated architectures such as a private APN, 5G PNI-NPN, cellular SD-WAN, ZTNA, or a site-to-site VPN. These devices are frequently vendor-installed and missing from inventories.
- Replace default and weak device passwords, and restrict which hosts can reach controllers using firewall rules or ACLs, including blocks on hosting-provider ranges.
- Put key switches in the run position, and validate project files before changing modes, since the switch locks in whatever logic is loaded.
- Rehearse manual operation: Test failover, islanding, backups, and standby systems on a schedule. This is the control that determined outcomes in Minnesota.
- Compare running logic against known-good baselines, including reusable code modules and I/O configuration, and verify backups are clean before restoring.
- Review logs on every connected device, including modems, HMIs, and engineering workstations, and reimage anything the actors appear to have reached.
- Plan end-of-life replacements on a rolling 12-month forecast reviewed quarterly with asset owners and procurement.
Utilities that find affected devices should engage their incident response plan and contact their local FBI field office, IC3, CISA’s 24/7 Operations Center, and Rockwell’s PSIRT.
Frequently Asked Questions
Which PLCs are affected?
The FBI has observed this activity against internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers, and advises operators of other brands to make similar considerations. The July update to AA26-097A separately reported targeting of Schneider Electric and Siemens devices.
How many utilities were affected?
Minnesota reported more than 30 community water systems targeted on July 26 and 27. The FBI and EPA report incidents in at least seven states since July 27. The states beyond Minnesota have not been named.
Was drinking water contaminated?
The utilities that disclosed publicly reported no impact to water quality, and no Minnesota city has an active advisory out. The FBI notes that pressure loss can allow untreated groundwater into pipes, which is why pressure events are treated as safety incidents.
Who is responsible?
No actor has been publicly named. Investigators are examining a possible Iranian link and, separately, whether the activity was made to look Iranian.
Is this the same campaign as the earlier advisory?
The entry point is the same, and the method differs. The earlier campaign centered on exfiltrating and rewriting PLC project files. This wave centers on changing device IP addresses and setting passwords to lock operators out, with one victim also reporting modified project files.
What should a small utility do first?
Determine whether any controller, HMI, or cellular modem is reachable from the internet and remove that exposure before anything else. Then confirm the plant can be run manually.

