Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

A coordinated cyberattack has brought over 30 community water systems in Minnesota to their knees, with hackers targeting operational technology (OT) systems that manage critical infrastructure. The attacks, which occurred on Sunday and Monday, July 26 and 27, have left residents of several communities without access to safe drinking water, prompting a state-wide response from the Minnesota IT Services agency.

The City of Braham was one of the first to report an outage at its water plant, with officials stating that the facility was “offline for an unknown reason.” However, within three hours, the city announced that the issue had been resolved and the plant was back online, filtering and treating water as expected. It wasn’t until later that officials confirmed that the outage was indeed caused by a malicious cyberattack on the computerized operating systems.

Other communities in the region also reported temporary equipment malfunctions, with some switching to manual operations or implementing contingency plans to maintain normal services. The scope of the attack is still unclear, but it’s estimated that over 30 water utilities were affected, leaving thousands of people without access to safe drinking water.

The Minnesota IT Services agency is working closely with federal, state, local, and private sector partners to investigate the incident and fortify the security of Minnesota’s critical infrastructure. As part of its response efforts, MNIT is sharing threat intelligence and providing guidance on best practices for responding to cyberattacks. The agency has also emphasized that it is not aware of any requests from cities in the region for residents to change their drinking water usage.

The attack highlights the vulnerability of critical infrastructure to cyber threats. According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), state-sponsored hackers often target such systems as a means of espionage or in preparation for disruptive activities in case of crisis or conflict. The threat actor behind the Minnesota water systems cyberattacks remains unknown, but experts warn that critical infrastructure is a prime target for nation-state actors.

The incident also serves as a reminder that even seemingly minor disruptions can have significant consequences. As CISA notes in its guidance on isolating vital systems during cyberattacks, critical infrastructure organizations should prioritize continuity of services and take proactive measures to prevent similar incidents from occurring in the future. By staying vigilant and taking steps to strengthen their defenses, security teams can minimize the impact of a potential attack.

For readers who manage or work with critical infrastructure, this incident serves as a stark reminder that cybersecurity is an ongoing battle. While we may not know the specifics of the threat actor behind the Minnesota water systems cyberattacks, we do know that such attacks are increasingly common and can have devastating consequences. To stay ahead of potential threats, it’s essential to prioritize regular security testing and training, as well as maintaining open communication channels with stakeholders in case of an incident. By taking proactive steps to strengthen their defenses, critical infrastructure organizations can minimize the risk of a similar attack occurring in the future.


Source: Bleeping Computer — 2026-07-29