OPERATION SHADOW HUNT
Intelligence Briefing
Public Release – 29 July 2026
TO: All Municipal, County, State, and National Officials; Law Enforcement Partners; Critical Infrastructure Operators; Election Administrators; IT Professionals; and Concerned Citizens
FROM: Phillip C. Parrish – Operation Shadow Hunt (Independent Intelligence Collection)
SUBJECT: Coordinated Probing of Minnesota Municipal Operational Technology and Election-Related Systems – Indicators of Persistent Remote-Access Risk Ahead of the 11 August 2026 Primary
CLASSIFICATION: UNCLASSIFIED // FOR PUBLIC DISTRIBUTION AND IMMEDIATE ACTION
1. Executive Summary
Between approximately 21–27 July 2026, Minnesota experienced a tight sequence of observable activity against municipal systems that share remote-access characteristics. Public accuracy testing of election equipment revealed limited sampling of tabulators, active wireless networks (including Pollpad WiFi Secure–Mobile and multiple county SSIDs), and visible modem-process functionality. Days later, a coordinated cyberattack targeted operational technology at more than 30 community water systems statewide, primarily via cellular and wireless links. Temporary equipment malfunctions occurred; water quality and public service were preserved. No formal attribution has been released.
This sequence occurred inside a federally warned threat environment. On 22 July 2026, CISA, FBI, EPA, NSA and partners updated Advisory AA26-097A warning of ongoing Iranian-affiliated exploitation of internet-connected programmable logic controllers across Water and Wastewater Systems, Energy, and Government Services and Facilities (including local municipalities). The actors manipulate project files, HMI/SCADA displays, and critical shutdown/alarm logic to cause disruption.
The 11 August 2026 primary recreates the elevated testing-and-operations tempo that increases connectivity surfaces. Mid-level IT professionals, bureaucrats, and administrators continue to treat the residual risk as theoretical or overstated. That institutional posture itself functions as a vulnerability. The patterns are consistent with reconnaissance, capability testing, and psychological effect. The threat is active. It will be exploited if the open doors remain unaddressed.
2. Core Observed Indicators (Minnesota)
Election Accuracy Testing Window (mid-to-late July 2026)
• Rice County observations (~21 July): Only 3 of 35 DS200 precinct tabulators tested; single DS450 central-count machine (absentee and mail ballots) tested once.
• Live wireless environment documented in the testing room: Pollpad WiFi Secure–Mobile, multiple Rice County networks (RC-Guardian, RC_Internal, RC_IoT, RC_Mobile, RC_Public), vehicle hotspot, and Bluetooth activity.
• Machine interface displayed “Current Signal Strength” indicators and a “Begin Modem Process” option.
• Requests for serial numbers and current software/firmware versions were refused on site; formal data request filed.
• Multiple counties conducted required public accuracy tests in the same window ahead of the primary, consistent with Minnesota law requiring tests at least three days before equipment use.
Coordinated Water Systems Campaign (26–27 July 2026)
• More than 30 community water systems targeted.
• Operational technology (wells, treatment controls, pumps, automated functions, and cellular-linked communications) disrupted. Systems shifted to manual operation. No lasting service outage or water-quality impact reported. No ransom detected.
• Named systems included Braham (well and plant offline under two hours), Plymouth (cellular communications to towers and lift stations), Maple Plain, and South St. Paul. The remainder remain nonpublic under state law.
• Minnesota IT Services activated a statewide response with federal partners including the FBI, CISA, and EPA. The investigation remains active; no formal attribution has been issued as of 29 July.
Cross-Cutting Connectivity Pattern
Cellular and wireless links appear in both the water operational-technology incidents and the election-equipment testing environment. Poll Pads are designed to use Wi-Fi or cellular connectivity to reach the ePulse management suite. Certain ES&S DS200-class tabulators have historically been equipped with cellular or wireless modem capability in multiple jurisdictions, creating ongoing questions about residual remote exposure even when systems are described as isolated.
3. Federal and Broader Context
On 22 July 2026, CISA, the FBI, EPA, NSA and additional partners updated joint Advisory AA26-097A. The update warns of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology devices, specifically programmable logic controllers from Rockwell Automation/Allen-Bradley, with expanded observations against Schneider Electric and Siemens devices. Targeted sectors explicitly include Water and Wastewater Systems, Energy, and Government Services and Facilities (local municipalities). Observed effects include malicious interaction with project files, manipulation of human-machine interface and SCADA displays, and disabling of critical shutdown and alarm logic, producing operational disruption.
The temporal proximity (advisory update 22 July followed by the Minnesota water systems campaign 26–27 July) and technical overlap (cellular and wireless industrial controls in municipal water systems) are operationally relevant. Officials have not attributed the Minnesota incidents to this specific campaign, yet the characteristics align with the warned tactics, techniques, and procedures.
Broader patterns reinforce the concern: industrial cellular routers, serial-to-IP converters, and modem-linked SCADA/OT devices remain frequent targets; managed-service-provider and third-party remote-access tools create persistent privileged pathways that blend into legitimate operations; and limited-disruption attacks on water and municipal systems serve both technical mapping and psychological signaling purposes.
4. Institutional Vulnerability
Many mid-level IT professionals, municipal administrators, and bureaucrats continue to treat these indicators as overstated or unrelated. Vendor assurances and minimum statutory process compliance often substitute for adversarial threat modeling. Concerns about outsourcing-created remote-access pathways have been raised and, in some cases, discounted. The result is residual exposure that persists because the people with day-to-day authority do not fully internalize the risk.
Federal agencies are actively warning of state-linked targeting of municipal and water operational-technology surfaces. Ground observation in Minnesota documented modem-process functionality and live wireless environments during official election-equipment testing. A coordinated campaign then reached more than 30 water systems via similar links. Denial does not close the doors.
5. Near-Term Vector: 11 August 2026 Primary
The primary recreates the elevated-tempo conditions observed in July: equipment powered on, networks and connectivity features activated for testing and operations, temporary configurations introduced across dozens of jurisdictions simultaneously, and staff focused on process execution. This is a predictable window. Actors who map soft municipal surfaces do not require perfect, permanent access on day one. They require opportunity, cover, and the continued under-appreciation of residual remote-access risk.
6. Call to Action
To every participant already collecting under Operation Shadow Hunt:
Continue disciplined documentation. Preserve photographs, screenshots, network observations, contemporaneous notes, and chain of custody. File and pursue formal data requests for serial numbers, firmware versions, modem and wireless configurations, testing logs, and third-party remote-access inventories. Share verified indicators with trusted law-enforcement and infrastructure partners. The collection effort is not complete.
To mid-level IT professionals, system administrators, and municipal staff who have been dismissive or whose prior concerns were dismissed:
Lock onto the facts. Federal agencies updated warnings on 22 July about Iranian-affiliated targeting of municipal and water operational technology via internet- and cellular-connected programmable logic controllers. Minnesota water systems were hit via cellular and wireless links days later. Modem-process screens and live wireless environments were observable during official accuracy testing of election equipment. Vendor remote-access pathways exist by design in outsourced environments. These are documented realities. Expand testing beyond minimum statutory samples. Audit and disable unnecessary modem and remote functions where feasible. Improve segmentation, continuous monitoring, and logging of third-party access. Demand transparency. Address the residual risk publicly. The systems under your stewardship form part of the attack surface.
To officials at every level and law-enforcement partners:
Treat the July sequence as a live indicator set. Require expanded public disclosure of affected systems where law permits. Mandate pre-primary audits of election-equipment connectivity configurations and firmware. Coordinate tightly with federal partners on the specific tactics warned in Advisory AA26-097A and observed against Minnesota municipal operational technology. Investigate the full scope of third-party remote access across critical and election-adjacent systems. Support those inside the system willing to surface uncomfortable facts.
To all who refuse to accept compromised critical infrastructure and eroded public confidence as normal:
The pattern is visible. The primary is days away. State-sponsored actors, criminal groups, and those seeking to degrade trust do not need cinematic-level compromise. They need the doors left open by complacency and institutional disbelief. Close them. Document. Report. Pressure for accountability. Support internal truth-tellers. The integrity of water systems, public services, and election administration is foundational.
It is happening. It will continue if the threats, behaviors, and patterns are not taken seriously.
Operation Shadow Hunt continues. Get after it.
Phillip C. Parrish
Independent Collection – Operation Shadow Hunt
Public Release for Immediate Distribution
End of Briefing.
###