Water utilities in more than 30 Minnesota communities were disrupted by a coordinated cyberattack on Sunday and Monday, the state announced Tuesday. No drinking water was contaminated and no boil-water notices were issued, but the episode is among the broadest attacks on U.S. water infrastructure to become public.
What happened
The attacks hit operational technology, the equipment that runs pumps and valves, rather than office computers. In Braham, a city of about 1,700, the water plant went offline after what the city described as a malicious cyberattack on its computerized operating systems by unknown actors. Crews restored service within roughly two hours by operating manually.
In Plymouth, a Minneapolis suburb of about 80,000, the targets were equipment connected by cellular links at two water towers and several lift stations. The city's IT division disconnected the affected equipment from the network to stop the attack. Officials in both cities said the water remained safe and that residents did not need to change their consumption.
Minnesota IT Services is leading the response, working with the state health and public safety departments, a state fusion center, and federal agencies including the Cybersecurity and Infrastructure Security Agency, the EPA and the FBI. John Israel, the state's chief information security officer, said the whole-of-government response had worked as intended.
How confident is the attribution
Less than the headlines suggest, and officials have been careful about it. State and federal officials have characterized Iranian involvement as likely rather than established, and cautioned that the assessment could change as technical evidence is collected. No formal attribution had been announced as of Thursday.
Outside researchers have pointed in the same direction. Analysts suspect the group known as CyberAv3ngers, which U.S. authorities have tied to the Islamic Revolutionary Guard Corps, based on the pattern of the operation: disruption rather than extortion, aimed at small utilities with exposed industrial controllers. The reasoning is inference from method, not evidence of who typed the commands.
Officials also acknowledged the possibility, which they consider unlikely, that another actor was posing as an Iranian group.
The precedent
CyberAv3ngers is not a new name. In late 2023 the group compromised programmable logic controllers at the Municipal Water Authority of Aliquippa, Pennsylvania, part of a campaign against Unitronics devices that reached utilities in several countries, largely by exploiting default passwords. In February 2024 the Treasury Department sanctioned six IRGC cyber officials over those operations, and the State Department posted a reward for information leading to their arrest.
The vulnerability is structural. Small water systems run industrial equipment that was designed for reliability rather than for exposure to the internet, and they run it with staff counted in single digits and no dedicated security budget. The Aliquippa breach and the Minnesota attacks both hit that same soft layer.
The California question
California's utilities sit in the same position. In June, a separate group claiming Iranian affiliation said it had breached customer billing systems at California Water Service, which serves communities across the state. That claim concerns business IT rather than the systems that treat water, which is a meaningful distinction, but the exposure it points to is the same one Minnesota just demonstrated at scale.



