Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

A coordinated cyberattack targeting more than 30 community water systems in Minnesota has sent shockwaves through the critical infrastructure sector, highlighting the growing threat to often poorly protected operational technology (OT). The attacks, attributed by US government officials to an Iran-backed actor, disrupted automated systems in some communities, forcing them to switch to manual operations for brief periods.

The attacks come just days after a warning from the US Cybersecurity and Infrastructure Security Agency (CISA) about Iran-affiliated threat groups targeting programmable logic controllers (PLCs) and other Internet-connected OT devices at critical infrastructure organizations across the US. The advisory specifically identified PLCs from Rockwell Automation/Allen Bradley, Schneider Electric, and Siemens as being of interest to the attackers, while warning that any Internet-exposed PLC could be a potential target.

The attacks appear to have been carried out by manipulating project files and altering data displayed on human machine interface (HMI) and SCADA systems. While some communities were forced to switch to manual operations, officials in Minnesota have reported that water supply, water safety, and wastewater services were not significantly affected. However, the disruptions caused concern among residents and prompted some cities to declare local states of emergency.

The city of Braham, Minn., was one such community that was impacted by the attacks. On July 27, its mayor urged residents to minimize water use due to an unknown issue at its water plant. The following day, however, the issue had been resolved without any disruption to water services. Similar disruptions were reported in other communities, including Maple Plain and South St. Paul.

While officials in Minnesota have not directly attributed the attacks to Iran, some researchers believe that the operational tradecraft bears the fingerprints of Iranian threat groups. Scott Caveza, senior staff research engineer at Tenable, notes that the tactics mirror those used by known Iranian threat groups, such as exploiting Internet-facing PLCs and native vendor engineering software to bypass authentication and extract project files.

The attacks serve as a stark reminder of the growing cyber-risks facing critical infrastructure sectors in the US. With more than 30 community water systems impacted, it’s clear that these sectors are vulnerable to disruption. The attacks also highlight the need for better protection and preparedness measures to prevent such disruptions from happening in the future.

In light of this incident, we urge all organizations operating OT systems to review their security posture and ensure that they have robust protections in place to prevent similar attacks. This includes implementing regular security updates, conducting thorough risk assessments, and developing contingency plans for potential disruptions. By taking proactive measures, organizations can reduce their exposure to cyber-risks and minimize the impact of future attacks.


Source: Dark Reading — 2026-07-30