Cyber Incident Victim: City of Plymouth
Timeline
Summary
A cyberattack targeted the operating technology of over thirty water systems in Minnesota, including the city of Plymouth, prompting officials to take the affected plant offline and urge residents to conserve water while using a backup supply. Workers restored flow within a couple of hours by switching to manual control, and although the water supply was not compromised, similar outages led to boil‑water advisories in other states and raised concerns about a coordinated Iran‑linked campaign against critical infrastructure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 30, a water tower was observed in Plymouth, Minnesota. State officials reported that a cyberattack had targeted the operating technology of over thirty water systems in the state, including Plymouth’s, late in the previous month of July. As investigators examined the incident, crews took the affected water plant offline. To maintain service, the city advised residents to conserve water while drawing on a backup supply stored in a local tank. After approximately two hours, workers restored normal flow by switching the pump to manual control.

The disruption prompted temporary water‑conservation measures and reliance on the backup supply, but no contamination of the drinking water was detected. The attack was part of a broader, coordinated campaign that affected water and wastewater facilities in multiple states, with some localities issuing boil‑water notices and declaring brief states of emergency. In Plymouth, the annual Pie Day celebration at the Park Cafe proceeded as scheduled just days after the incident. The event demonstrated that the core water service was restored without lasting interruption for residents.
State information‑technology teams worked with local crews to identify the attack vector, which involved exposed industrial devices with default credentials still in place. The FBI confirmed that at least seven states had experienced similar intrusions on water and wastewater infrastructure and opened an investigation. WaterISAC convened a conference call for its members to share threat intelligence, and the EPA delivered a public webinar on cyber risks to the water sector. Operators responded by changing default passwords, disconnecting operational technology from corporate networks, and enabling firewalls where feasible. Officials noted that the incident underscored the need for additional resources and improved monitoring across the sector. The aftermath contributed to ongoing discussions about strengthening cybersecurity for water systems nationwide.
