Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

Cyber Attackers Disrupt Minnesota Water Utilities, Highlighting Vulnerabilities in Critical Infrastructure

A coordinated cyber attack has left over 30 community water systems in Minnesota reeling, highlighting the vulnerability of critical infrastructure to malicious actors. The attackers targeted operational technology (OT) systems at local water utilities, causing temporary equipment malfunctions and forcing some plants to switch to manual operations.

The incident unfolded on Sunday and Monday, July 26-27, with multiple water utilities reporting issues. One affected community, Braham, was forced to shut down its water plant due to a “malicious cyber attack” on its computerized operating systems. However, officials were able to quickly identify the issue and restore services within hours.

The Minnesota IT Services (MNIT) agency has activated its cybersecurity incident response capabilities in response to the attack, working closely with federal, state, local, Tribal, and private-sector partners to investigate and contain the damage. MNIT is sharing threat intelligence and providing guidance on response efforts to affected utilities, emphasizing the importance of isolating key OT systems to ensure continuity of critical services.

The attackers’ motives are unclear, but experts warn that critical infrastructure is often targeted by state-sponsored hackers for espionage or in preparation for disruptive and destructive activities in case of crisis or conflict. This incident follows a joint advisory from multiple U.S. agencies in April, which highlighted the threat posed by Iranian hackers targeting programmable logic controllers (PLCs) in critical infrastructure organizations.

The Minnesota water utility attack serves as a stark reminder that even seemingly secure systems are vulnerable to cyber threats. In today’s interconnected world, it is no longer sufficient for security teams to simply log successful attacks and alert on just 14% of incidents. The remaining 86% can move undetected through an organization’s environment, causing significant damage before being detected.

To mitigate this risk, organizations must prioritize proactive security measures, such as regular breach and attack simulation testing. This type of testing can help identify vulnerabilities in SIEM and EDR rules, ensuring that threats are not slipping by detection. By taking a proactive approach to cybersecurity, organizations can better protect their critical infrastructure from the ever-evolving threat landscape.

As this incident demonstrates, even the most seemingly secure systems can be vulnerable to cyber attacks. It is essential for security teams to remain vigilant and prioritize ongoing testing and evaluation of their defenses to stay ahead of malicious actors.


Source: Bleeping Computer — 2026-07-29