Back to Blog
Minnesota Water Utilities Ransomware: Coordinated OT Disruption (July 2026)
ransomware

Minnesota Water Utilities Ransomware: Coordinated OT Disruption (July 2026)

breachwire TeamAug 3, 20265 min read

Minnesota Water Utilities: What Happened

Between July 26 and 27, 2026, a coordinated ransomware campaign targeted the operational technology (OT) infrastructure of more than 30 community water utilities across Minnesota. Among the affected organizations were Braham Water Utility, Maple Plain Water Utility, Plymouth Water Utility, and South St. Paul Water Utility. The attackers gained unauthorized access to internet-exposed programmable logic controllers (PLCs), changing passwords and IP addresses to lock out legitimate operators. This resulted in the loss of remote control and monitoring capabilities, forcing several utilities to issue boil water notices and, in at least one case (Braham), to take the entire plant offline.

Attack Vector & Technical Detail

The threat actors exploited PLCs that were directly accessible from the internet, leveraging the vulnerability tracked as CVE-2021-22681. This vulnerability affects certain Schneider Electric PLCs, allowing remote attackers to bypass authentication and gain control over device configuration. The attackers' tactics align with MITRE ATT&CK techniques TA0006 (Credential Access), TA0007 (Discovery), and TA0009 (Collection). By altering device credentials and network parameters, the adversaries effectively denied operators access to critical OT assets, disrupting water treatment and distribution operations. No specific IOCs were disclosed in public reporting, but the attack methodology is consistent with recent ransomware campaigns targeting critical infrastructure.

Confirmed Impact

The attacks had significant operational consequences for the affected Minnesota water utilities. Braham Water Utility was forced offline, while others, including Plymouth and Maple Plain, had to revert to manual operations. The loss of automated monitoring and control led to the issuance of boil water notices across multiple communities, raising public health concerns. The incident underscores the regulatory and safety risks posed by insecure OT environments, particularly in the water sector, where disruption can have immediate consequences for public health and safety. The geographic focus on Minnesota highlights a coordinated, regionally targeted campaign.

What This Means for Your Organization

This incident demonstrates the critical risk posed by internet-exposed OT assets, especially PLCs with known vulnerabilities such as CVE-2021-22681. Organizations operating critical infrastructure must prioritize the removal of direct internet access to OT devices and enforce strict network segmentation. Regular vulnerability assessments and timely patching are essential to mitigate the risk of similar attacks. Security teams should also review remote access policies and implement robust authentication mechanisms to prevent unauthorized access to control systems.

Detection & Response

  • Immediate: Remove all PLCs and OT devices from direct internet exposure and reset credentials on affected devices.
  • Hunt: Search for unauthorized changes to PLC configurations, especially password and IP address modifications, and monitor for MITRE TA0006/TA0007/TA0009 behaviors.
  • Patch: Apply vendor-recommended updates to address CVE-2021-22681 on all susceptible PLCs.

Source: https://securityaffairs.com/196453/ics-scada/cisa-urges-utilities-to-remove-internet-exposed-plcs-after-minnesota-attacks.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: