Skip to content

Suspected cyberattack disrupts Plymouth, Minnesota, water-system communications

The city said water remained safe as crews used manual procedures after communications failed at two water towers and multiple wastewater lift stations.

Close-up of a white Plymouth, Minnesota, water tower with the city name and logo painted near the top and cellular antennas mounted on the roof.
A water tower bearing the city of Plymouth logo in Plymouth, Minnesota. (Minnesota Water Towers)

A suspected cyberattack disrupted communications at two Plymouth water towers and multiple wastewater lift stations overnight Sunday, but the Minnesota city said water remained safe and services continued.

The city described the problem as limited to communications equipment and did not say the facilities had shut down. Plymouth, a Minneapolis suburb in Hennepin County, has nearly 79,000 residents.

The affected equipment used cellular connections, the city said. Crews continued operations through manual procedures, and residents were told they did not need to conserve water or change their consumption.

No boil-water advisory or wastewater-service warning was issued. Plymouth said water levels and water quality were unaffected.

The activity began overnight Sunday and continued into Monday, July 27. Plymouth said it suspected a cyberattack but had not disclosed how the systems were accessed.

Screenshot of a City of Plymouth, Minnesota, Facebook post stating that a suspected cyberattack disrupted communications at two water towers and multiple lift stations, while water quality and service remained unaffected.
The city of Plymouth, Minnesota, said a suspected cyberattack affected cellular communications at two water towers and multiple wastewater lift stations. The city said water remained safe and crews continued operations using manual procedures. (Screenshot via City of Plymouth)

The incident was among several reported Monday involving municipal water technology in Minnesota.

Braham said unknown actors carried out a malicious cyberattack against computerized operating systems at its water plant. The incident disabled operating controls, causing a well and the plant to go offline for less than two hours.

Water stored in the city’s tower continued supplying residents, and officials said water quality and safety were not affected.

South St. Paul said a cybersecurity incident affected technology supporting parts of its water utility system. Some automated controls were affected, but the city said drinking water remained safe and water and wastewater operations continued normally.

Braham officials said they had been told that at least four other communities were attacked “with the same result.” Plymouth and South St. Paul have publicly identified incidents, while at least two other affected communities have not been named.

Minnesota IT Services said it was providing cybersecurity and technical support to state and local partners. The agency said its work included assessing potential effects, sharing threat information and supporting response and recovery efforts as the investigation continued.

The Minnesota incidents followed a March ransomware attack on the Minot Water Treatment Plant in North Dakota. Minot said ransomware was detected on a server supporting its supervisory control and data acquisition system, prompting workers to conduct more frequent manual gauge checks for about 16 hours.

Minot said its water remained safe, pressure was maintained and no ransom was paid. Officials have not connected that attack to the Minnesota incidents.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The Cybersecurity and Infrastructure Security Agency, the FBI, the Environmental Protection Agency and other federal partners updated an advisory July 22 warning that Iranian-affiliated actors were targeting internet-connected programmable logic controllers across U.S. critical infrastructure.

The advisory said the activity had disrupted operational technology. It urged operators to remove control devices from direct internet access, change default passwords, use multifactor authentication where available and restrict remote access.

Federal officials have not attributed the Minnesota incidents to Iranian-affiliated actors or said programmable logic controllers were involved.

Plymouth had not said whether automated communications were fully restored. Officials also had not identified the affected hardware, software, cellular provider or vendor; explained whether communications were lost, degraded or manipulated; or said whether pumps, valves, tank levels or wastewater flows were altered.

Authorities had not disclosed an initial access method, malware, data theft, a ransom demand or a threat actor. It also remained unclear whether the named Minnesota communities and the unnamed municipalities shared technology, a vendor or a common vulnerability.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all