Domain Systems
Back to Insights
Article
August 2, 2026

Minnesota Water Systems Hack: Why Every Local Utility Needs Air-Gapped OT and Data Diodes

S
By Sudon't • 18 min read
Critical Infrastructure
Water & Wastewater
SCADA
Security
Product

A detailed explainer on the July 2026 Minnesota water systems cyberattack that hit more than 30 community utilities, the Iran-linked PLC campaign warning from CISA, President Trump's blame of Minnesota leadership, and why air-gapped operational technology with hardware data diodes is the practical defense before these attacks reach your town.

Minnesota Water Systems Hack: Why Every Local Utility Needs Air-Gapped OT and Data Diodes

In late July 2026, more than thirty community water systems across Minnesota lost reliable automated control of the equipment that moves, treats, and monitors drinking water. Some towns switched to manual operations. One small city briefly shut down its well and treatment plant. Another disconnected cellular links at water towers and sewer lift stations to stop the intrusion from continuing. Drinking water quality was preserved, boil-water notices were largely avoided, and crews restored service. That outcome depended on luck and competent emergency response. Communities still need a durable security architecture underneath those recoveries.

If you live in a mid-sized suburb, a rural township, or a city that still runs pumps and PLCs the way it did a decade ago, treat this as a preview of what happens when operational technology (OT), the industrial computers that control physical processes, remains reachable from the public internet. The Minnesota incident is one of the clearest recent demonstrations that cyber effects on critical infrastructure are no longer rare, exotic, or limited to Fortune 500 operators. They are arriving in ordinary American communities.

This article explains what happened, how the political argument around blame misses the engineering problem, why Iranian-affiliated and copycat actors are escalating against U.S. water and energy systems, and why the durable answer for OT is true air-gapping. Data diodes provide the one-way paths operators still need for monitoring, logging, and situational awareness.


What Happened in Minnesota

According to Minnesota IT Services (MNIT), a coordinated cyberattack targeted operational technology at more than thirty Minnesota community water systems on Sunday, July 26, and Monday, July 27, 2026.1 Confirmed public disclosures came from communities including Braham, Plymouth, South St. Paul, and Maple Plain.

The technical picture, pieced together from state statements and industry reporting, looks like this:

  • Attackers focused on systems used to remotely monitor and control water and wastewater equipment, especially programmable logic controllers (PLCs): industrial computers that open valves, run pumps, manage lift stations, and drive treatment processes.
  • In Braham (about 1,700 residents), computerized operating controls were disabled and the city's well and water treatment plant were temporarily shut down. Public works restored the plant in roughly two hours.
  • In Plymouth (about 80,000 residents), IT staff disconnected cellular-connected equipment at two water towers and fourteen sewer lift stations after detecting compromised PLCs, then continued operations with manual procedures while equipment was reconfigured.
  • South St. Paul reported effects on some automated water utility controls.
  • Maple Plain declared a local state of emergency to expand response capacity.

Minnesota officials stated that drinking water quality was not known to be compromised and that there were no widespread active requests for residents to change water use. Investigators and reporting around the incident described a more serious likely intent: loss of system pressure and the subsequent risk of contamination if control systems remain under adversary influence.2

In short, attackers went after the machines that keep municipal water safe and pressurized. Sustained or repeated at scale, that kind of effect turns a cyber incident into a public-health and public-confidence crisis.

Beyond Minnesota

The FBI later indicated malicious cyber activity affecting water systems in at least seven states, with Michigan among those publicly acknowledging related incidents.3 CISA followed with urgent guidance for the water and wastewater sector: remove publicly exposed PLCs and other OT from the internet as soon as possible, including cellular modems that operators, vendors, or integrators may have installed without documenting them in normal attack-surface scans.4

Minnesota was the loudest public case. Similar activity appeared elsewhere.


Politics, Blame, and the Wrong Lesson

Within days, the Minnesota events entered national politics. At a Cabinet meeting at Camp David, President Donald Trump rejected the suggestion that Iran was responsible and blamed Minnesota and its Democratic governor, Tim Walz:

"We heard in Minnesota there was a cyberattack and they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent... There was a cyberattack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, oh, is Iran? Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."5

Governor Walz pushed back, arguing that other states were hit as well, that this is what modern warfare looks like, and that federal cybersecurity capacity had been weakened.6

For operators, boards, and city councils, the political argument distracts from an engineering truth both sides should be able to agree on:

If a PLC that runs a pump station is reachable from the internet (through a cellular modem, a poorly segmented VPN, a vendor remote-access tool, or a forgotten engineering port), then someone, somewhere, will eventually find it. Attribution matters for diplomacy and deterrence. Architecture matters for whether your town still has water pressure on Monday morning.

Even if investigators ultimately conclude the Minnesota events were the work of a foreign APT, a proxy hacktivist collective, or an actor trying to look like Iran, the vulnerability class stays the same. Internet-exposed OT is the enabling condition. Competence without isolation fails as a strategy. Isolation without a way to still operate the plant fails as an operating model. Data diodes are designed to resolve that bind.

The local takeaway: Whether you accept the President's framing that Minnesota failed operationally, or the view that state-linked foreign actors are probing U.S. water systems, the practical result is the same. Communities that leave industrial control on the open internet are volunteering to be next.


Iran's Campaign Against U.S. Industrial Controls Is Escalating

Formal public attribution of the Minnesota incidents remains incomplete as of early August 2026. MNIT has said it has not determined a specific actor. Federal investigators have examined possible Iranian links; some reporting has described Iranian hackers as the likely explanation, while also noting the possibility of false-flag activity amid broader U.S.–Iran tensions.3 7

The broader Iranian-affiliated campaign against U.S. PLCs that federal agencies documented earlier in 2026 is well established.

CISA Advisory AA26-097A

On April 7, 2026, CISA, the FBI, NSA, EPA, DOE, and U.S. Cyber Command published joint advisory AA26-097A, warning that Iranian-affiliated APT actors were exploiting internet-exposed programmable logic controllers across U.S. critical infrastructure, including government facilities, water and wastewater systems, and energy.8

The advisory ties this activity to the same threat ecosystem previously associated with CyberAv3ngers (also tracked as Shahid Kaveh Group, Hydro Kitten, Storm-0784, Bauxite, UNC5691, and related names), a group the U.S. government has linked to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). In earlier campaigns beginning around November 2023, those actors compromised dozens of Unitronics PLCs used in water systems and other sectors, often by exploiting default passwords on internet-facing devices. The Municipal Water Authority of Aliquippa, Pennsylvania, was among the best-known victims.

On July 22, 2026, four days before the Minnesota disruptions began, CISA and partner agencies updated AA26-097A. The update expanded observed targeting beyond Rockwell Automation / Allen-Bradley devices to include Schneider Electric and Siemens PLCs, documented exfiltration of PLC project files using legitimate vendor engineering software, and described manipulation of reusable code modules (Add-On Instructions) that can disable safety shutdown and alarm logic while leaving operator displays looking normal.9

That last point deserves emphasis for non-specialists:

In documented cases, attackers have altered the logic inside industrial controllers and falsified what operators see on screens. Equipment can then run in unsafe conditions without the alarms that staff are trained to trust.

Why Water Utilities Keep Getting Hit

Small and mid-sized water systems are attractive targets for structural reasons:

  1. Massive internet exposure. Industry scans in 2026 identified thousands of Rockwell/Allen-Bradley devices responding to industrial protocols on the public internet, with the United States accounting for a large majority of that exposure. Much of it rides cellular carrier networks feeding remote towers, lift stations, and pump sites.10
  2. Thin security staffing. Many community utilities have excellent plant operators and almost no dedicated OT cybersecurity personnel.
  3. Convenience over isolation. Cellular modems, TeamViewer-style remote tools, and direct PLC management ports make overnight troubleshooting easy. The same paths make adversary access easy.
  4. Hard-to-patch controllers. Some critical Rockwell authentication weaknesses associated with this campaign cannot be fully fixed with a simple software patch; vendors point operators to network segmentation and defense-in-depth instead.11
  5. Proxy proliferation. Iranian-linked PLC techniques have reportedly spread across dozens of affiliated hacktivist groups, raising the chance of disruptive effects even when the core APT is not personally at the keyboard.10

CISA's assessment of the Iranian-affiliated activity is blunt: the intent is to cause disruptive effects inside the United States. Minnesota showed what that looks like when it reaches municipal OT.


The Tip of the Iceberg: Cyber Effects Are Becoming Normal

For years, critical-infrastructure cyber risk was discussed mainly through a handful of famous cases: Stuxnet, the Ukraine power grid attacks, Colonial Pipeline, Oldsmar water, Aliquippa. Those case studies mattered, but they also created a false sense that catastrophic OT events were rare black swans.

That framing no longer fits 2026.

What we are seeing now is a campaign environment:

  • Repeated exploitation of the same exposed PLC classes across many victims
  • Expansion from one manufacturer ecosystem to several
  • Mixing of state-directed APT tradecraft with loosely affiliated hacktivist proxies
  • Parallel pressure on water, energy, and local government systems
  • Geopolitical conflict that raises the political value of visible disruption on U.S. soil

Expect more of this over the coming years. The attack economics favor the adversary. Finding an exposed controller is cheap. Changing a password on a forgotten modem is cheap. The defensive retrofit across roughly 150,000 to 170,000 U.S. water systems is expensive, slow, and uneven.

Colonial Pipeline taught the country that an IT ransomware event could force a precautionary OT shutdown and empty gas stations along the East Coast. Minnesota teaches a sharper lesson: adversaries are increasingly going straight at OT, including through paths that never touch email servers or VPN accounts. When the first foothold is the controller itself, restoring from backup is only part of recovery. You need an architecture where remote attackers never have a path to that controller in the first place.

Coming to your community: The next incident may stay off national cable news. It may be a single lift station in your county, a booster pump that fails closed, or a night shift that discovers SCADA screens no longer match reality. The Minnesota pattern scales down easily. That is why every local government and utility board should treat air-gapped OT as a civic responsibility.


A Plain-Language Technical Explainer: What Was Actually Exposed?

IT versus OT

Most organizations run two different kinds of computing environments:

  • IT (information technology): email, websites, billing, office laptops, cloud apps. These systems must talk to the internet to do their jobs.
  • OT (operational technology): PLCs, SCADA servers, human-machine interfaces (HMIs), historians, and sensors that control physical processes like water pressure, chlorine dosing, or pump sequencing.

When IT and OT share networks, or when OT devices are given their own direct internet links "just for remote support," malware and adversaries can move from the open world into the plant. Firewalls and VPNs help, but they are software policies. Software can be misconfigured, credentials can be stolen, and zero-days happen. Minnesota-style incidents exploit that reality.

What a PLC Is

A PLC is a rugged industrial computer. It runs ladder logic or similar control programs that say, in effect: if tank level is low, start pump A; if pressure exceeds X, open relief valve; if chlorine residual drops, increase dose. Compromise a PLC and you gain the ability to change how the physical world behaves.

How Attackers Reach Them

In the Iranian-affiliated campaign documented by CISA, and in the Minnesota pattern described by responders, common themes include:

  • Controllers reachable over the public internet or cellular links
  • Use of legitimate vendor engineering software (the same tools plant engineers use) from attacker-controlled infrastructure
  • Theft or modification of PLC project files
  • Manipulation of HMI/SCADA displays and safety-related logic
  • Persistence mechanisms such as SSH on compromised modems

CISA has urged operators to watch industrial and remote-access ports commonly associated with these protocols and access paths, and to treat unexpected overseas connections to engineering interfaces as urgent.

None of this requires science fiction. It requires an exposed device and patience.


Why "Air-Gapped" Is the Right Goal for OT

An air gap means there is no bidirectional network path between a trusted OT environment and untrusted networks (including the corporate IT LAN and the internet). Remote attackers cannot open a session to your PLC because there is no route that can carry that session.

For water, energy, manufacturing, and other critical processes, air-gapping should be the default design goal:

  • Controllers should not have public IP addresses.
  • Cellular modems should not present raw PLC management interfaces to the carrier network.
  • Engineering workstations should not sit on the same flat network as email and browsers.
  • Vendor remote access should be exceptional, time-bounded, and architecturally constrained.

CISA's post-Minnesota guidance essentially restates this in operational language: disconnect publicly exposed PLCs; do not leave OT on the open internet.

The objection every plant manager raises is fair: If we fully disconnect, how do we still get telemetry to the control center, send historian data to corporate systems, share alarms with the IT security team, or meet reporting requirements?

That is where unidirectional hardware enters.


Data Diodes: Air-Gap Security Without Freezing Operations

A data diode is a hardware device that allows data to flow in only one direction. The constraint is physical. It is enforced in hardware rather than by a firewall rule someone can reverse or a VPN policy that drifts.

Think of it like a check valve in a water system: flow is permitted downstream; reverse flow is mechanically impossible. In networking terms, OT can send monitoring data, logs, alarm feeds, and historian updates out to IT or a SOC, while nothing from the internet or corporate LAN can send commands, packets, or malware back in.

That is the architectural answer to Minnesota:

NeedWithout isolationWith firewalls / VPNs onlyWith data diode air-gapRemote PLC troubleshooting from homeEasy, highly exposedBetter, still bidirectional riskDisallowed by design; use on-site or tightly controlled break-glass proceduresSend SCADA telemetry to corporate dashboardsEasy, bidirectionalCommon, policy-dependentSupported outbound through the diodePrevent foreign actors from rewriting ladder logicRelies on passwords & patchingRelies on correct config foreverNo inbound network path to rewrite logic remotelyDetect attacks on IT without infecting OTShared networks spread riskSegmentation helps if perfectOT remains isolated even if IT is fully compromised

How Domain Systems Implements This

Domain Systems manufactures Expanse Data Diodes, hardware-enforced unidirectional fiber links designed for this IT/OT boundary problem. The industrial use case is straightforward:

  1. Keep the OT / SCADA / PLC network truly isolated from the internet.
  2. Place a transmit-side diode module on the OT boundary.
  3. Place a receive-side diode module on the IT or monitoring network.
  4. Forward historian data, syslog, SNMP traps, screen mirrors, file drops, or other outbound telemetry as required.
  5. Enforce that no return path exists for remote engineering sessions, malware callbacks, or command injection.

Where operators still need complex protocol behavior across that one-way link, the Expanse Network Stack (ENS) provides software that makes unidirectional transfers operationally usable, including file movement and protocol bridging patterns, without turning the diode back into a bidirectional firewall.

This is the same class of technology long used in nuclear, defense, and high-security government environments: hardware-enforced cross-domain control, adapted for municipal and industrial reality.

Keep the air gap, keep the data flowing: Data diodes preserve the security property of an air gap while still allowing the outbound data flows modern operations demand: monitoring, compliance reporting, centralized visibility, and security analytics.

Why Firewalls Alone Fall Short

Firewalls help. For high-consequence OT they leave too much residual risk.

A firewall is a computer running software that decides which packets may pass. Adversaries routinely find ways around or through that decision layer: stolen credentials, mis-ordered rules, compromised jump hosts, vulnerable VPN appliances, or trusted vendor connections. In Minnesota-style campaigns, attackers often reach field PLCs through cellular paths that never entered the firewall's worldview.

A data diode removes the decision. There is no inbound packet to allow.

If your safety case for a water plant depends on "we configured the ACL correctly," you are betting public health on perpetual human perfection. If your safety case depends on "there is no physical receive path into OT," you are betting on physics.


A Practical Architecture for Water and Wastewater OT

Utilities evaluating lessons from Minnesota should aim for a design that looks like this in principle:

1. Remove direct internet exposure immediately

Inventory every PLC, RTU, HMI, modem, and cellular gateway. Anything with a public address or carrier-reachable management interface is an emergency remediation item. CISA's guidance is explicit on this point.

2. Rebuild remote sites with isolation in mind

Remote water towers and lift stations often need connectivity for telemetry. That requirement does not justify inbound engineering access from the internet. Prefer architectures where field sites can report outbound status, while configuration changes require on-site presence or a controlled, audited process.

3. Put a unidirectional boundary between OT and IT

Corporate networks will get phished. Billing systems will get ransomware. Email will get malware. None of that should be able to traverse into the control network. A diode-enforced boundary makes "IT is on fire, OT keeps pumping" an achievable operating state. That reverses Colonial Pipeline's forced shutdown dynamic and directly mitigates Minnesota-style OT targeting.

4. Treat vendor engineering software as high risk

The AA26-097A campaign shows adversaries using the same engineering tools operators trust. Engineering workstations should be isolated, allowlisted, and never dual-used as general internet PCs.

5. Keep offline backups of PLC logic

If ladder logic or project files are altered, you need clean offline copies on secured media and a tested restore procedure. Assume display data can lie.

6. Plan for manual operations, then engineer so you rarely need them

Minnesota communities survived because operators could fall back to manual control. That resilience is admirable. It does not scale to simultaneous multi-site pressure loss across a region. Prevention through architecture is cheaper than heroic overnight recovery as a standing strategy.


What City Leaders and Utility Boards Should Ask This Week

If you are a mayor, city manager, utility director, or cooperative board member, ask your operators and integrators these questions in plain English:

  1. Which of our PLCs or cellular modems can be reached from the public internet today?
  2. If corporate email is ransomware'd tomorrow, can that malware reach the water plant network?
  3. Do we have a hardware-enforced one-way path for monitoring data, or only software firewalls?
  4. Who can change PLC logic remotely, from where, and how is that authenticated?
  5. When was the last time we tested restoring controller logic from an offline backup?
  6. Are vendor remote-access tools permanent fixtures or break-glass exceptions?

If the answers are vague, your community is running on hope. Hope does not count as a control.


The Serious Reality: This Is Coming Closer to Home

The Minnesota water systems hack will be remembered either as a near miss that finally forced a sector-wide retrofit, or as an early chapter in a longer series of municipal disruptions. The ingredients for the worse outcome are already present: exposed industrial devices, escalating Iranian-affiliated and proxy cyber operations, unfinished attribution debates that consume news cycles while the architecture stays the same, and thousands of towns that still treat OT cybersecurity as optional IT hygiene.

President Trump said Minnesota was "grossly incompetent." Governor Walz said this is modern warfare. Engineers should hear both statements as incomplete. Incompetence without exposure is limited. Warfare without an attack surface stalls. The combination of geopolitical cyber pressure and internet-reachable controllers is what puts ordinary communities on the map for foreign and opportunistic actors alike.

We are looking at the tip of the iceberg. The submerged mass is every pump station, substation, treatment skid, and manufacturing line still wired for convenience instead of isolation.

OT systems that can affect public safety should be air-gapped from the internet. Data diodes are how organizations keep that air gap real while still moving the operational data they need. After Minnesota, that requirement belongs on every municipal agenda.

Next step for operators: If you are responsible for water, wastewater, energy, or other industrial control environments and want to evaluate hardware-enforced unidirectional boundaries, Domain Systems can help you design an Expanse Data Diode deployment that preserves monitoring and reporting while eliminating inbound remote attack paths into OT. Contact [email protected].


This article is based on publicly available government advisories and news reporting as of August 2, 2026. Attribution of the Minnesota incidents remains under active investigation; technical analysis of the broader Iranian-affiliated PLC campaign is drawn from CISA and partner agency publications.

References

Footnotes

  1. Minnesota IT Services reporting and state statements on the July 26–27, 2026 coordinated cyberattack against more than 30 Minnesota community water systems. Summarized in AP News and SecurityWeek. ↩

  2. Sweeping cyberattack on water systems in multiple states has US officials on edge, CNN, July 31, 2026. ↩

  3. U.S. investigating if Iran was behind cyberattack on water systems in 7 states, including Minnesota and Michigan, CBS News. ↩ ↩2

  4. CISA alert urging water and wastewater operators to remove publicly exposed PLCs and OT from the internet following coordinated PLC-targeting activity. July 30, 2026 coverage via SecurityWeek. ↩

  5. President Trump remarks at Camp David Cabinet meeting blaming Minnesota and Gov. Tim Walz for the water-systems cyberattack. Quoted in ABC News, Fox News, and AP Fact Focus. ↩

  6. Governor Tim Walz public response stating other states were hit and framing the incident as modern warfare. Reported by CBS Minnesota and PolitiFact. ↩

  7. Reporting that U.S. and state officials familiar with the probe assessed Iranian hackers as likely responsible, while formal attribution remained incomplete. Cited in multiple outlets including Fox News summaries of New York Times reporting. ↩

  8. CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure, originally published April 7, 2026. ↩

  9. July 22, 2026 update to AA26-097A expanding observed targeting to Schneider Electric and Siemens PLCs and documenting project-file exfiltration and AOI manipulation. See CISA advisory page and analysis from Tenable and IOActive. ↩

  10. Coordinated cyberattack on Minnesota water utilities / CyberAv3ngers analysis, Tenable Research Special Operations, July 2026. ↩ ↩2

  11. Discussion of unpatchable authentication weaknesses in affected Rockwell Logix ecosystems and vendor guidance toward segmentation and defense-in-depth. Summarized in Tenable's Minnesota / AA26-097A FAQ linked above. ↩