What has been suspected to be a coordinated cyberattack impacted operational technology (OT) systems at dozens of water utilities across Minnesota on July 26 and 27, prompting a joint state and federal response. According to Minnesota IT Services (MNIT), more than 30 community water systems were hit.
Several affected cities including, Maple Plain, Braham, South St. Paul, and Plymouth, disclosed that some automated control functions were disrupted. In most cases, utilities activated contingency procedures and kept water and wastewater operations running. Every city that issued a statement stressed that drinking water remained safe.
The most disruptive case was in Braham, which briefly took its water plant offline and asked residents to limit water use. The city reported that the intruders shut down its operating controls, which in turn took the well and water treatment plant offline until staff could intervene.
Cellular/Wireless Connection?
One detail is drawing particular attention from OT security practitioners: Plymouth stated that the impact was “limited to equipment connected via cellular communications within the system.”
That points to a class of assets many utilities underestimate. Remote sites like water towers, lift stations, and pump stations frequently reach back to the SCADA system over cellular modems, and those secondary or alternative communication links are routinely left out of risk and vulnerability assessments. Denis Calderone, CTO of Suzu Labs, noted that because industrial networks are often built out by integrators, these cellular paths are especially easy to overlook. He pointed out that one affected city has now asked for its vulnerability study to be reevaluated — and suggested that study may never have accounted for those cellular connections in the first place.
The concern extends well beyond Minnesota. Seemant Sehgal, founder and CEO of BreachLock, argued that investigators need to identify the common thread across the incidents, because the same weakness almost certainly exists in water infrastructure elsewhere in the country.
The consequences that matter to operators
Harry Thomas, CTO and co-founder of OT security firm Frenos, framed the incidents less around attribution and more around operational impact. Drawing on the MITRE ATT&CK for ICS framework, he described how attacks like these can produce denial or loss of view, denial or loss of control, and manipulation of view or control — a physical process may keep running even when operators can no longer see it, influence it, or trust what their screens are reporting. From there, he warned, an incident can escalate toward loss of availability, safety, or physical damage. Manipulation is especially dangerous, because the process may be in a very different state than what operators are being shown.
An open question about the timing
Attribution remains unresolved. The incidents landed shortly after the U.S. government warned critical infrastructure operators about Iran-linked activity targeting ICS devices from Siemens, Rockwell Automation, and Schneider Electric. Iranian threat groups such as CyberAv3ngers and Handala would fit the profile, and in the 2020 attacks on Israeli water facilities, Iran-linked actors gained entry through vulnerable cellular routers. Still, investigators have made no formal attribution.
That uncertainty is fueling a pointed question from the OT community. Joe Langill, a veteran industrial control systems security expert, raised the possibility that the attack was deliberately timed to coincide with the same-day T-Mobile outage. He asked whether analysts had considered that the Minnesota attack was “coordinated with the T-Mobile outage for 5G services during the same time frame,” pointing to a structural reason it belongs on their radar: “a LOT of water districts have moved to cellular networks for ICS endpoints across large geo areas,” he wrote, often at “entities with limited budgets for advanced security controls.”
The timing is interesting. On July 27, T-Mobile suffered one of the year’s largest single-carrier disruptions, with peak outage reports topping 140,000 and phones across multiple states (Minnesota among them) dropping into SOS mode before service was restored the following day.
Langill also suggested the damage could have been far greater in more experienced hands and warned how little stands in an attacker’s way once they reach these endpoints: “Get me on the network and I will own just about any system that does not have endpoint security appliances,” he wrote. Langill’s question underscores how tangled timing, connectivity, and intent become when large fleets of lightly secured cellular assets are in play.
Whatever the final attribution, the Minnesota incidents are a reminder that the communication paths into remote OT assets, especially cellular links added by integrators and forgotten by everyone else, deserve the same scrutiny as the control systems themselves.

Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
State and federal agencies are investigating intrusions that disrupted automated controls at municipal water and wastewater systems, and some OT experts are asking whether the attacks were timed to coincide with the same-day T-Mobile 5G outage.
Volt Typhoon Hackers Dwelled in US Electric for 300+ Days: Report
Dragos shared some details describing an intrusion attributed to the notorious Chinese threat actor Volt Typhoon into the US electric grid.
Water Treatment Facility in Arkansas City Switches to Manual Mode After Suspected Cyberattack
Arkansas City said a cybersecurity issue at its Water Treatment Facility on September 22, 2024 forced the facility to switch to manual operations.
Iran-Linked “Cyber Av3ngers” Hackers Compromise Control System at Pennsylvania Water Utility
Iran-Linked "Cyber Av3ngers" hackers compromised an industrial control system at the Municipal Water Authority of Aliquippa (MWAA) in Pennsylvania.
Russian Sandworm Hackers Target Ukraine’s Power Grid in Coordinated Cyber-Physical Attack
Russia’s Sandworm hackers disrupted power in Ukraine using a novel attack against operational technology (OT) coordinated with missile strikes.
Deep Dive: PIPEDREAM/Incontroller ICS Attack Framework
In this session, Mark Plemmons, Sr. Director for Threat Intelligence at Dragos, dives deep into the technical details and real-world impact on the modular ICS attack framework known as PIPEDREAM/Incontroller
Researchers Use IoT and IT to Deliver Ransomware Attack Against OT
Critical industries must prepare themselves for a new wave of ransomware attacks specifically targeting OT
Colonial Pipeline Still Mostly Offline After Ransomware Attack
The Colonial Pipeline is working on a restart plan after a ransomware attack triggered the company to halt all pipeline operations on May 7, 2021.
The Past & Future of Integrity Attacks in ICS Environments (Video)
Integrity-based attacks can produce significant impacts through undermining a physical process and calling into doubt the viability of a specific facility.
The Growing Threat of Drones
Drones are an increasing threat to industrial sites, enabling various attacks (cyber and physical) that historically were only possible in close proximity to a facility or device.
