Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

Coordinated Cyberattacks Hit Minnesota Water Utilities, Leaving Thousands at Risk

A coordinated cyberattack has targeted operational technology (OT) systems at dozens of water utilities in Minnesota, sparking a joint investigation by state and federal agencies. The attack, which occurred on July 26 and 27, affected more than 30 community water systems across the state.

According to statements issued by several cities whose systems were compromised – including Maple Plain, Braham, South St. Paul, and Plymouth – automated control functions were disrupted in some cases. However, contingency procedures were activated, and in most instances, water and wastewater operations remained operational. In one instance, the City of Braham briefly took its water plant offline after detecting the cybersecurity incident, urging residents to minimize water use.

The affected cities assured citizens that drinking water remains safe and that water and wastewater services are functioning as usual. However, the attack highlights a growing concern: industrial control systems (ICS) made by prominent manufacturers like Siemens, Rockwell Automation, and Schneider Electric have been targeted in recent weeks. The US government has warned critical infrastructure organizations about potential attacks linked to Iranian threat groups.

Industry experts point out that the consequences of such attacks can be far-reaching and devastating. “When I read about cyberattacks affecting water systems,” said Harry Thomas, CTO and co-founder of OT security firm Frenos, “my mind doesn’t immediately go to attribution – it goes to the operator and the potential operational consequences.” Thomas explained that a denial of view or control can lead to temporary disruptions, while sustained losses may require hands-on intervention. Manipulation, on the other hand, can be even more hazardous as processes may be in an unknown state.

Denis Calderone, CTO of Suzu Labs, noted that remote assets often connect back to SCADA systems over cellular modems, which are often overlooked during risk and vulnerability analysis. “It’s not too surprising then that the vector of attack may have been via these cellular connections,” he said. Calderone pointed out that this highlights the importance of thorough security assessments and reevaluations.

The Minnesota water cyberattacks serve as a stark reminder that industrial control systems remain vulnerable to sophisticated attacks. With potentially thousands at risk, it’s crucial for utility operators and industry professionals to prioritize OT security and stay vigilant against emerging threats.

As the investigation continues, one takeaway is clear: in today’s interconnected world, the safety of our critical infrastructure depends on robust cybersecurity measures. Utility operators must remain proactive in assessing vulnerabilities and implementing effective countermeasures to prevent catastrophic losses.


Source: SecurityWeek — 2026-07-29