urldefense.com Coordinated Cyberattack Disrupts Water Utilities in Minnesota
Article Content
- •Over 30 Minnesota communities experienced disruptions to water utilities due to a cyberattack.
- •The attack targeted computerized operating systems, causing temporary outages but no water quality issues.
- •State and federal agencies are investigating the incident, with indications of potential Iranian involvement.
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted computerized operating systems, causing temporary outages but no compromise to water quality. Officials reported that the attacks were executed by unknown actors, with speculation pointing towards Iranian hacking groups. Minnesota's IT Services activated its cybersecurity response capabilities, collaborating with federal agencies like CISA and the FBI. While the immediate threat was contained, investigations into the attack's origin are ongoing. Residents were assured that drinking water remained safe throughout the incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (325)
Following this threat?
Track INC, Apt28 and Braham in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SonicWall SMA1000 Faces Critical Zero-Day Exploitation SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access…
Critical RCE Vulnerability in Zimbra Exploited by Attackers A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers to execute arbitrary commands as the Zimbra user through improper input sanitization in SNMP…