Active Incident: Minnesota Water Systems, July 26-27, 2026

ICS Threat Intelligence for Critical Infrastructure

Analysis of active threats to water, energy, and industrial operators. Nation-state actors are targeting U.S. critical infrastructure. Exposure is higher than most operators know.

Phases, timeline, deliverables, pricing, and what to expect after the report. Or read the threat intelligence blog.

New

More Than 30 Minnesota Water Systems Hit at Once

A coordinated attack on operational technology across July 26 and 27, 2026. Braham's treatment plant went offline. Plymouth lost telemetry to two water towers and multiple sewer lift stations. Operators kept the water safe by running plants manually. State officials say the goal was disruption, not money.

Matt Lucas  |  July 30, 2026  |  5 min

July 26-27: More Than 30 Minnesota Water Systems Targeted in a Coordinated OT Attack

Minnesota IT Services says 30-plus community water systems were hit inside 48 hours, at the control layer rather than the business network. Braham's well and treatment-plant controls were disabled and the plant went offline; Plymouth, South St. Paul, and Maple Plain lost automated control functions and ran manually. Drinking water stayed safe and no boil advisories were issued. The state CISO says the signs point to disruption, not financial gain. No actor has been named. Separately, federal advisory AA26-097A was reissued July 22 covering Iranian-affiliated actors exploiting internet-exposed PLCs across Rockwell, Schneider Electric, and Siemens: read that advisory. The two are separate events. No one has attributed the Minnesota attack.

Read the Incident Brief

Who Is At Risk

If you operate industrial control systems, you are a target. Exposure is far greater than most operators realize.

Water Treatment

Municipal water systems, wastewater facilities, and treatment plants are primary targets. In July 2026 more than 30 Minnesota community water systems were hit in a single coordinated attack on operational technology. Aliquippa, PA (2023) and Muleshoe, TX (2024) are earlier documented examples.

Energy and Utilities

Electric utilities, natural gas pipelines, and power generation facilities face constant probing. Flat OT networks mean a single entry point reaches everything.

Manufacturing

Industrial facilities running PLCs and SCADA systems. Legacy equipment with unpatched firmware and default credentials is the norm, not the exception.

Building Automation

HVAC, access control, and BMS systems in critical facilities. Tridium Niagara and BACnet devices expose building systems to the same threat actors targeting ICS.

Assessment Process

A comprehensive 2-week threat hunt. Zero operational impact. AWIA 2018-aligned.

1

Discovery

Full inventory of PLCs, RTUs, HMIs, SCADA. Network mapping and internet exposure check.

2

Monitoring

Passive network capture of ICS protocols. Baseline normal behavior. No operational impact.

3

Threat Hunt

Search for active IOCs, unauthorized access, anomalous commands, after-hours activity.

4

Report

Executive summary, technical findings, prioritized remediation roadmap, grant documentation.

Federal Funding Covers Your Assessment

Your utility may qualify for grants that fully cover cybersecurity assessments. No operating budget required.

CWSRF / DWSRF Grants

Clean Water and Drinking Water State Revolving Funds include cybersecurity as an eligible expense. Typical awards: $500K to $2M per system.

FEMA HSGP

Homeland Security Grant Program funds cybersecurity for critical infrastructure. Awards range from $100K to $500K. Apply through your state emergency management agency.

SLCGP

State and Local Cybersecurity Grant Program. 80% of funds flow to local governments. Designed for entities like municipal water systems.

IIJA Bonus Funding Expires 2026

Bipartisan Infrastructure Law bonus funding rates expire end of 2026. After that, standard rates apply at significantly lower levels. Act now.

AWWA Cybersecurity Guidance and AWIA Compliance

The American Water Works Association's cybersecurity framework is the industry standard for the water sector. Federal law requires water systems serving 3,300 or more people to address cybersecurity in their risk and resilience assessments.

AWIA 2018 Requirement

America's Water Infrastructure Act §2013 requires systems serving 3,300 or more people to include cybersecurity in their risk and resilience assessment and emergency response plan. Certifications are required every 5 years.

AWWA Risk Management Guidance (V4.0)

AWWA's Water Sector Cybersecurity Risk Management Guidance provides step-by-step guidance for process control vulnerabilities, incident response templates, and a prioritized controls list mapped to EPA requirements.

NIST Cybersecurity Framework Alignment

AWWA guidance maps to the NIST CSF, Identify, Protect, Detect, Respond, Recover. Our assessments produce documentation your system can use to satisfy both AWWA and NIST requirements.

EPA Priority Controls

EPA's cybersecurity guidance for drinking water systems identifies priority controls all utilities should implement. Our assessment delivers a prioritized roadmap aligned to EPA's list and your specific risk profile.

Key regulatory resources

AWWA Assessment Tool → AWWA Risk Management Guidance → EPA Cybersecurity Guidance (PDF) →

Free Tool

How does your utility score?

30-question AWWA-aligned self-assessment. Know your gaps in 10 minutes.

Take the Assessment →

Know Your Exposure Before Someone Else Does

Free scoping call. We assess your exposure, identify applicable grants, and show you exactly what an assessment covers.

Schedule Free Scoping Call

Already evaluating? See how an engagement runs: phases, timeline, deliverables, pricing, and what to expect after the report.

7115 Southpoint Pkwy Ste 5, Brentwood TN 37024