Skip to content

Plymouth water communications cyberattack

Summary

City of Plymouth logo

A cyberattack disrupted cellular communications at two Plymouth water towers and several wastewater lift stations overnight July 26–27, 2026, but crews maintained operations manually without affecting water levels, quality, or public services. Plymouth restored all impacted communications connections July 28 and returned the system to normal operations; attribution remained unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Utility operations disrupted

    Electric, water, wastewater, gas, telecommunications, or other utility operations were materially affected.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that malicious cyber activity disrupted communications equipment supporting Plymouth, Minnesota, water and wastewater infrastructure. Plymouth’s official incident page says an overnight July 26 communications outage affected two water towers and multiple wastewater lift stations and was caused by a cyber attack. The issue was limited to equipment using cellular communications.

The incident was part of a broader cluster. FOX 9 reported that Minnesota IT Services characterized activity against technology at more than 30 community water systems during July 26–27 as a coordinated cyberattack. Plymouth was among the initially disclosed municipalities.

Operational significance

The outage removed normal remote communications at distributed water and wastewater facilities, forcing Public Works crews to operate manually. Plymouth said the affected infrastructure did not shut down and that water levels, water quality, and public services were unaffected. The evidence supports a communications and workflow disruption, not manipulation of physical operating controls or interruption of water or wastewater service.

The public record does not establish that pumps, valves, tank levels, wastewater flows, or treatment processes were altered. No conservation order, boil-water advisory, wastewater-service warning, or public-health restriction was issued for this incident.

Disclosure posture

Plymouth initially described the cause as a suspected cyber attack while emphasizing safe water and continued service. Its later official update states that communications were restored following a cyber attack and says Public Safety continued working with law-enforcement and investigative organizations. That later wording provides direct municipal confirmation of cyber activity but does not identify the technical basis, equipment, access method, or responsible actor.

Current status

Plymouth reported that crews reestablished communications to all impacted infrastructure Tuesday afternoon, July 28, monitored the system overnight, and returned it to normal operations. Associated Press reporting independently relayed the city’s restoration update. This positive official restoration statement supports resolved status and a July 28 operational end.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused the communications outage because Plymouth now directly describes the event as a cyber attack and Minnesota officials confirmed malicious activity involving water-system remote monitoring and control technology across the wider cluster. Confidence is also high that operations were restored because the city reported every impacted communications connection reestablished and the system operating normally.

Attribution remains unresolved. Axios reported that anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. The same report said Minnesota IT Services had not attributed the activity to a specific actor, and AP reported that neither state officials nor the FBI had publicly identified a culprit. DysruptionHub treats the Iran link as an unconfirmed investigative hypothesis, not attribution of Plymouth’s incident.

The public record does not support ransomware or extortion. No ransom demand, threat-actor listing, payment request, encryption claim, or data-theft allegation was found. Data impact remains unresolved because sources do not establish whether operational telemetry, administrative information, credentials, or customer data were accessed, copied, altered, or removed.

Analytic gaps

The reviewed public sources do not establish the initial access vector, compromised account or device, vulnerability, affected communications hardware or software, cellular carrier, third-party vendor, configuration change, malware, persistence, dwell time, or restoration method. They also do not establish whether Plymouth’s incident shared infrastructure, tooling, or command-and-control with the other Minnesota water-system incidents or which actor was responsible.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: High

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

Minnesota IT Services characterized the July 26-27 activity against more than 30 community water systems as coordinated, and Plymouth was among the publicly identified municipalities. The city independently documented a cyberattack disrupting cellular communications at water towers and wastewater lift stations and requiring manual procedures; the membership does not establish common infrastructure or actor attribution.

Organizations involved

Impacted location

Sources

Suspected cyberattack disrupts Plymouth water-system communications

A suspected cyberattack disrupted communications at two Plymouth water towers and multiple wastewater lift stations overnight Sunday. The affected equipment used cellular connections, crews continued through manual procedures, and the city said water levels, quality and services were unaffected.

Suspected cyberattack affects utility communications

The City of Plymouth said a suspected cyberattack disrupted cellular communications at two water towers and multiple wastewater lift stations. Crews continued operations through manual procedures, while water levels and water quality were unaffected and residents did not need to conserve water.

Communications restored at Plymouth water facilities

Plymouth said crews reestablished communications connections to all impacted water and wastewater infrastructure Tuesday afternoon, monitored overnight, and returned the system to normal operations. The city described the event as a cyber attack and said water levels and quality were unaffected throughout.

More than 30 Minnesota water systems targeted in cyberattack

Minnesota IT Services said a coordinated cyberattack targeted technology at more than 30 community water systems between July 26 and July 27. Plymouth was among four cities that disclosed incidents, and officials said impacts were limited or mitigated and normal water use could continue.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

AP reported that Plymouth officials said water-infrastructure communications were restored Tuesday afternoon following a cyberattack and that water levels and quality were unaffected. Minnesota IT Services and the FBI had not publicly identified a culprit, and investigators had not determined whether one actor caused every incident.

Report: Iranian hackers likely behind Minnesota municipal water cyberattack

Axios relayed New York Times reporting that three anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. Axios also reported Minnesota IT Services’ public statement that the active investigation had not attributed the activity to a specific actor.

See something that needs correction?

Signed-in members can report an error, update, or missing source.