Skip to content

South St. Paul water utility cyber incident

Summary

City of South St. Paul logo

South St. Paul identified malicious activity affecting automated water-utility controls on July 27, 2026, but contingency procedures kept drinking water safe and water and wastewater services operating normally. The incident was among more than 30 Minnesota water-system attacks; public attribution remained open despite reports that anonymously briefed officials suspected Iranian hackers.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that South St. Paul experienced malicious cyber activity affecting technology used to support portions of its municipal water utility. The city’s official notice said certain automated controls were affected and that Public Works staff immediately implemented established contingency procedures. The notice’s reference to “June 27th” conflicts with contemporaneous reporting and Minnesota’s July 26–27 incident chronology; July 27 remains the best-supported South St. Paul detection date.

The incident was part of a broader cluster. FOX 9 reported that Minnesota IT Services characterized activity against technology at more than 30 community water systems during July 26–27 as a coordinated cyberattack. The state activated incident-response capabilities and said the initially identified communities, including South St. Paul, had limited or mitigated effects.

Operational significance

Automated controls support reliable water and wastewater operations, so their loss required operators to use contingency procedures while normal automation was restored. South St. Paul said drinking water remained safe, both utility services stayed fully operational, and residents did not need to act. The evidence therefore supports disruption to operational technology and normal automated workflows, but not unsafe water, lost water service, a wastewater outage or a public-use restriction.

Later Associated Press reporting said most confirmed Minnesota incidents involved technology used to remotely monitor and control water equipment. Minnesota IT Services described the attacks as taking place July 26–27 and said July 30 that there were no active community requests for residents to modify drinking-water use.

Disclosure posture

South St. Paul’s notice gave clear public-safety and continuity information but did not identify the affected equipment, access method, system changes, actor or precise restoration time. The state’s later statements added campaign scale, technology context and an end to the observed attack window while preserving uncertainty about whether one culprit caused every incident.

Current status

The incident is assessed as resolved. South St. Paul reported immediately mitigated effects and fully operational services on July 27, Minnesota IT Services later confined the coordinated attack activity to July 26–27, and no evidence of continuing South St. Paul operational impact was found. The absence of a city-specific automation-restoration timestamp remains a technical documentation gap, but it does not justify treating the attack as operationally active.

Confidence and uncertainty

Confidence is high that malicious activity affected South St. Paul’s water-utility control technology because the city confirmed the incident and Minnesota officials later confirmed malicious activity involving remote monitoring and control systems across the wider cluster. Confidence is also high that contingency procedures maintained safe water and normal service because the city directly addressed those outcomes.

Attribution remains unresolved. Axios reported that anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. The same report said Minnesota IT Services had not attributed the activity to a specific actor, and AP reported that neither state officials nor the FBI had publicly identified a culprit. DysruptionHub treats the Iran link as an unconfirmed investigative hypothesis, not attribution of South St. Paul’s incident.

The public record does not support ransomware or extortion. No ransom demand, threat-actor listing, payment request, encryption claim or data-theft allegation was found. Data impact also remains unresolved because sources do not establish whether operational, administrative or customer information was accessed, copied, altered or removed.

Analytic gaps

The reviewed public sources do not establish the initial access vector, compromised account or device, internet exposure, vulnerability, affected control product, configuration change, malware, persistence, dwell time, data-access scope, restoration method or exact automation-restoration time. They also do not establish whether South St. Paul’s incident shared infrastructure, tooling or command-and-control with the other Minnesota water-system incidents or which actor was responsible.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: High

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

Minnesota IT Services characterized the July 26-27 activity against more than 30 community water systems as coordinated, and South St. Paul was among the publicly identified municipalities. The city independently documented malicious activity affecting automated controls and requiring contingency procedures; the membership does not establish common infrastructure or actor attribution.

Organizations involved

Impacted location

Sources

South St. Paul, Minnesota, keeps water flowing after cyber incident

South St. Paul officials said a cybersecurity incident affected automated controls supporting parts of the city’s water utility, but drinking water remained safe and water and wastewater services continued normally. Staff used contingency procedures and continued work to restore normal automated operations.

Water Utility Cybersecurity Incident Update

The City identified a cybersecurity incident involving technology used to support portions of the water utility system. Certain automated controls were affected, contingency procedures were implemented, drinking water remained safe, and water and wastewater services remained fully operational.

More than 30 Minnesota water systems targeted in cyberattack

Minnesota IT Services reported that a coordinated cyberattack targeted technology at more than 30 community water systems between July 26 and July 27. South St. Paul was among cities that disclosed limited or mitigated impacts, and officials said residents could continue normal water use.

Report: Iranian hackers likely behind Minnesota municipal water cyberattack

Axios relayed New York Times reporting that three anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. Axios also reported Minnesota IT Services’ public statement that the active investigation had not attributed the activity to a specific actor.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

AP reported that Minnesota IT Services described the coordinated attacks as taking place July 26–27 and said no active community drinking-water-use modification requests remained July 30. Most confirmed incidents involved technology used to remotely monitor and control water equipment; investigators had not determined whether one actor caused every incident.

See something that needs correction?

Signed-in members can report an error, update, or missing source.