Aug 6 / Latest News

Coordinated Cyberattack Hits 30+ Minnesota Water Systems, Exposing OT Weaknesses Nationwide

Most people never think about the computer systems behind their kitchen faucet, but that routine was shaken in Minnesota and six other states after a coordinated cyberattack struck operational technology at more than 30 community water systems on July 26 and 27. Minnesota IT Services (MNIT) activated the state’s cybersecurity response and brought in federal agencies to investigate.

One water plant temporarily went offline, while other communities reported issues with automated controls and communications equipment. Workers switched to manual operations and backup procedures to keep water flowing. The FBI later confirmed that water and wastewater utilities in seven states were affected, noting that some activity degraded operations.

The attack targeted operational technology (OT) systems that control pumps, valves, and treatment machinery. In Braham, officials initially reported an unexplained outage before confirming a malicious cyberattack. Plymouth experienced communications problems involving water towers and lift stations, while South St. Paul and Maple Plain also reported incidents affecting automated controls. MNIT says more than 30 systems were targeted, though not all experienced outages.

Investigators have not issued a definitive attribution. A preliminary assessment reported by The New York Times suggests Iranian-linked hackers may be responsible, though officials caution the conclusion could change as more evidence emerges. CISA previously warned that Iranian-affiliated actors were targeting internet-exposed programmable logic controllers from multiple manufacturers, but federal agencies have not publicly tied that campaign to the Minnesota incidents.

The attack highlights broader risks facing U.S. water systems. The country has nearly 170,000 drinking water and wastewater facilities, many of which rely on internet-connected technology for remote monitoring. Smaller communities often struggle with outdated equipment, limited budgets, and minimal cybersecurity staffing, making them vulnerable to intrusions that exploit exposed or poorly secured OT systems.

A cyberattack does not automatically mean drinking water is unsafe. Minnesota officials reported no known impact on water quality and told residents they could continue normal use. However, the EPA warns that attackers could disrupt treatment processes or damage equipment, underscoring the importance of tested manual procedures when digital systems fail.

On July 28, CISA released new guidance titled “CI Fortify: Advice for Isolating Vital Systems,” urging critical infrastructure operators to separate essential OT from less trusted networks. The agency recommends removing unnecessary internet exposure, placing security controls in front of programmable controllers, changing default passwords, and ensuring employees have unique credentials. EPA inspections have found many water systems still using factory passwords or shared accounts, and more than 70% have violated basic federal risk assessment or emergency planning requirements.

While Minnesota’s incident did not result in contaminated water, it exposed how quickly attackers can disrupt essential services — and how urgently many communities need stronger OT security before the next intrusion occurs.