Coordinated Attack on OT Water Infrastructure in Minnesota: When Cellular Modems Become the Weak Point
Minnesota water systems faced an OT cyberattack exploiting cellular modems. The incident disrupted SCADA controls, forcing manual plant operations.
Illustrative image generated with AI
Introduction
Between July 26 and 27, 2026, over thirty municipal water systems in Minnesota (USA) were targeted by a cyberattack aimed at industrial automation and control systems (OT/SCADA). The cities of Maple Plain, Braham, South St. Paul, and Plymouth confirmed malfunction of automatic control functions, forcing operators to activate emergency procedures and switch to manual operation of the plants. Drinking water remained safe in all cases, but the incident reignited attention on the vulnerability of critical infrastructure to remote access, particularly those carried over often-neglected cellular networks.
Technical Analysis
The attack leveraged remote telemetry devices – such as piezometric towers and pumping stations – connected via cellular modems, a channel that often represents a secondary path not adequately protected by standard cybersecurity measures. The attackers managed to disrupt automatic control functions, causing a temporary denial of view/control over the plants. In Braham, the shutdown of operational controls forced the temporary turning off of the well and treatment plant, resulting in a call to residents to reduce consumption.
Investigations, coordinated by Minnesota IT Services (MNIT) and federal agencies, have not yet formalized attribution. However, the modus operandi resembles recent campaigns targeting devices from Siemens, Rockwell Automation, and Schneider Electric, often associated with Iranian groups such as CyberAv3ngers or Handala. It is unclear whether a specific vulnerability was exploited or simply insecure modem configurations; the context suggests targeted preparation to hit ICS systems exposed over mobile networks.
An illuminating precedent dates back to 2020 in Israel, when cellular routers were used as an entry point to water facilities. The attack in Minnesota demonstrates that the same vectors remain current and that attack surface mapping must include every communication channel, not just traditional corporate networks.
Impact
The overall impact was contained thanks to the immediate activation of contingency procedures. No physical damage or water contamination was reported: the production of drinking water was maintained, albeit under manual operation. However, localized operational disruptions occurred:
- In Braham, the interruption of automatic controls required a temporary shutdown and an appeal to residents to limit water usage.
- In Plymouth, effects were concentrated on equipment connected via cellular, confirming that the most significant damage was on secondary communication channels. The episode highlighted how compromising these links can rapidly degrade supervision and control capabilities, even without direct access to PLCs or central SCADA servers.
Mitigation
In the immediate aftermath, the affected utilities applied emergency response plans: switching to manual control, isolating compromised systems, and verifying the safety of physical processes. To prevent future attacks, experts from companies like Frenos, Suzu Labs, and BreachLock have issued specific recommendations:
- Include cellular connections and secondary paths in risk assessments, updating threat models that often overlook these interfaces.
- Strengthen network segmentation, using encrypted VPNs, dedicated firewalls, and multi-factor authentication for every remote access to OT devices.
- Adopt continuous monitoring of ICS traffic, including flows on cellular networks, to promptly detect anomalies or unauthorized commands.
- Secure secondary communications: disable non-essential services on modems, apply regular patches, replace clear-text protocols with authenticated and encrypted versions.
- Learn from the past: the 2020 attack in Israel showed that protecting cellular routers (updated firmware, strong passwords, closing unused ports) serves as an effective first line of defense.
FAQ
1. Did the attack make the water unsafe to drink?
No, in none of the affected systems did drinking water suffer contamination or alterations. Local authorities confirmed that water quality remained compliant with safety standards. The attack only interfered with automatic control systems, leaving treatment processes unaffected, which continued in manual mode.
2. How was it possible to attack dozens of facilities simultaneously?
The most widely accepted hypothesis is that the attackers exploited a homogeneous attack surface: many water facilities use telemetry devices with cellular modems, often configured with default credentials or outdated firmware. Pre-scanning IP blocks assigned to mobile operators makes it easy to locate these exposed devices, enabling a large-scale attack without the need for zero-day vulnerabilities.
3. What should operators do to protect plants from similar threats?
In addition to technical measures (segmentation, VPN, monitoring, updates), it is essential to perform a complete inventory of all remote access points, including cellular ones, and subject them to the same rigorous controls as corporate networks. It is advisable to schedule regular drills to test the switch to manual control and the response capability to denial-of-control scenarios. Finally, collaboration with agencies like CISA can provide timely intelligence on ongoing campaigns.
Sources
This article is an original reworking based on the sources below.
- The Hacker News
- BleepingComputer
- SecurityWeek
- Security Affairs




