davidkoran.com
Contact

Daily Cybersecurity Brief

More Than 30 Minnesota Water Systems Targeted in Coordinated OT Cyberattack

Published July 29, 2026
Category Critical Infrastructure
Sector Water and Utility Infrastructure
Immediate Action
Reading Time About 5 Minutes
Author David Koran

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, 2026, prompting a statewide response involving federal, state, local, Tribal, and private-sector partners. Public water service continued, drinking water remained safe, and no community has asked residents to change their water use. The incident is directly relevant to any organization operating control systems, because its outcome turned on two capabilities: knowing every pathway into the operational environment, and being able to close those pathways without losing control of the physical process. This brief covers what is documented, the federal isolation guidance published the same day the attack was disclosed, and the actions operators should take.

What Happened

Minnesota IT Services, the state agency responsible for information technology, disclosed on July 28 that the attack targeted operational technology, the systems that monitor and control physical processes, at more than 30 community water systems across the state over the two-day period. MNIT activated the state's cybersecurity incident response immediately and is coordinating with the Minnesota Bureau of Criminal Apprehension's Fusion Center, the Department of Health, the Pollution Control Agency, CISA, the EPA, the FBI, and local water utilities. The state's Chief Information Security Officer, John Israel, described the response as working as intended, with agencies at every level coordinating to contain the incident and prevent more serious impacts to critical services.

Four communities disclosed publicly on July 27: Plymouth, South St. Paul, Maple Plain, and Braham. Braham's water plant was briefly taken offline on the morning of July 27 before being restored, and the three other named communities reported attempted attacks. MNIT has declined to name the remaining affected communities, citing state law that classifies cyberattack reports as nonpublic information. The agency's ongoing response includes coordinating technical response activities across government partners, sharing threat intelligence and indicators of compromise with affected organizations, supporting investigation, containment, recovery, and remediation, and monitoring for related malicious cyber activity. The investigation remains active.

What Is Documented and What Is Not

The attack has not been publicly attributed to any threat actor, and this brief makes no attribution. State officials have said only that the timeline, access methods, and targeted infrastructure share characteristics with other coordinated critical-infrastructure incidents federal partners have observed. Readers will note the proximity to Joint Advisory AA26-097A, updated July 22, four days before this attack began, which documented Iranian-affiliated actors exploiting internet-facing PLCs at U.S. water and energy organizations. That advisory is context for why water system OT is under pressure. It is not evidence of who attacked Minnesota, and the two matters should be kept separate until investigators say otherwise.

Why This Matters Beyond Minnesota

The architecture that made 30 systems attackable in one coordinated campaign is not a Minnesota architecture. It is the standard architecture of small utility and municipal operations everywhere: small operational teams, older control equipment, remote facilities connected by cellular modems, vendor-installed remote access, limited logging, and responsibility divided unevenly among public works, IT, integrators, and equipment vendors. Ports, terminals, and shipyards running pumps, fuel systems, shore power, and remote telemetry share the same pattern, as do smaller manufacturers.

Minnesota also extends the lesson of the internet-exposed PLC problem covered in this publication's July 28 brief. Removing direct internet exposure is the first control, not the last one. A coordinated multi-site campaign is a reminder that the meaningful question is the full inventory of pathways into the operational environment: cellular, vendor, cloud, wireless, corporate-network, and remote-maintenance connections, every one of them. Management must know that inventory, and must be able to shut those pathways down without losing the ability to run the physical process. Braham's outcome, a plant briefly offline and restored the same morning while water stayed safe, is what that capability looks like when it exists.

New Federal Guidance: CI Fortify Isolation Advice

On July 28, the day the Minnesota attack was disclosed, CISA, the FBI, the Australian Signals Directorate's Australian Cyber Security Centre, the United Kingdom's NCSC, the Canadian Centre for Cyber Security, and other international partners published CI Fortify: Advice for Isolating Vital Systems. The joint guidance addresses the capability the Minnesota utilities needed: preparing critical infrastructure to disconnect vital operational technology from all other networks during a crisis and continue delivering essential services in isolation.

The guidance asks operators to do, in advance, what Minnesota's utilities had to do under fire: identify the minimum OT and supporting systems required to maintain essential service; map every connection to corporate networks, vendors, managed service providers, cloud platforms, internet services, mobile and satellite networks, Wi-Fi, and peer utilities; establish predetermined isolation points with graduated procedures; test complete isolation rather than individual devices; keep offline copies of the isolation plan; and confirm that vital services can continue while external systems are unavailable, through manual operation or alternative control paths where needed. The guidance treats isolation as a designed and tested capability rather than an emergency measure improvised during an incident. The Australian guidance that opened the CI Fortify initiative in October 2025 sets the planning expectation concretely: operators should be prepared to isolate vital OT and enabling systems for an extended period, up to three months, while maintaining critical services, and then rebuild compromised systems.

What Utilities and OT Operators Should Do Now

  1. Build the pathway inventory. List every connection into the operational environment: cellular modems, vendor and integrator access, remote-maintenance platforms, cloud dashboards, corporate-network links, wireless, and anything installed by an equipment supplier. If the inventory cannot be produced, that is the first finding.
  2. Verify the inventory onsite against the actual equipment, not against the network diagram. In small-utility environments, the two routinely differ.
  3. Identify the minimum systems required to keep the essential service running, per the CI Fortify guidance, and document which connections those systems genuinely need.
  4. Establish predetermined isolation points and written, graduated isolation procedures, including who holds standing authority to order isolation immediately, at any hour, without further approval.
  5. Confirm operators can run the process manually, and for how long. Braham's brief outage was absorbed because the plant could be restored quickly; every operator should know its own answer.
  6. Test isolation as a whole, not device by device, and keep an offline copy of the plan so it remains available if the network that stores it is compromised.
  7. Verify PLC and HMI backups exist, are stored off the production environment, and have been restored successfully in a test.
  8. Review the incident-response plan against this scenario specifically: a coordinated attack on OT with state and federal responders involved, nonpublic reporting obligations, and media inquiries.

Questions Management Should Ask Today

  1. Can we produce a complete list of every pathway into our operational environment, and when was it last verified against the actual equipment?
  2. Which systems are the minimum required to keep our essential service running?
  3. Do we have predetermined isolation points and a written procedure, and who is authorized to execute it immediately?
  4. Can our operators run the process manually, and when did we last prove it?
  5. Have we ever tested complete isolation rather than disconnecting a single device?
  6. Do our PLC and HMI backups exist off the network, and have they been test-restored?
  7. Who would we contact first during a coordinated incident, and are those relationships and notification procedures established in advance?

The Bottom Line

More than 30 community water systems were targeted in a coordinated two-day campaign, and the documented record shows that the systems handling it well were those able to isolate affected functions and continue operating. The question the incident puts to every utility and critical-infrastructure operator, and to the ports, terminals, and manufacturers running the same architecture, is whether the organization knows every pathway into its operational environment and whether it can close those pathways while continuing to deliver its essential service. A firewall diagram or a written policy does not establish that capability. The capability is established onsite, coordinated with the personnel who operate the process, and tested before an incident requires it.

Sources

CISA, FBI, ASD's ACSC, NCSC-UK, CCCS, and international partners. July 28, 2026.
FBI, CISA, NSA, EPA, DOE, U.S. Cyber Command CNMF, and Department of the Treasury. Originally published April 7, 2026. Updated July 22, 2026. Context only; the Minnesota attack is unattributed.

About This Brief

The Daily Cybersecurity Brief is written by David Koran and published by David Koran & Associates Inc. Each brief translates current cybersecurity threats, government advisories, vulnerabilities, and regulatory developments into practical action for ports, shipping and vessel operators, aerospace manufacturers, GSA and other federal contractors, and utility infrastructure operators, and for the executives, IT and OT personnel, and governance professionals inside them.

View All Briefs

Do You Know Every Pathway Into Your Operational Environment?

Assistance is available to utilities, municipalities, maritime operators, and manufacturers with onsite OT exposure review, isolation readiness, IT/OT segmentation assessment, backup verification, and remediation planning.

Contact David Koran