Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

A Coordinated Cyberattack Targets Minnesota’s Community Water Systems, Exposing Critical Infrastructure Vulnerabilities

In a disturbing reminder of the growing threats to US critical infrastructure, more than 30 community water systems in Minnesota were hit by a coordinated cyberattack, forcing several cities to switch to manual operations for brief periods. The attack, which has been attributed to an Iran-backed actor, underscores the sector’s vulnerability to sophisticated cyberattacks and highlights the need for robust cybersecurity measures.

The attacks, which occurred on July 26 and 27, targeted automated systems in multiple communities, causing disruptions to water services. However, according to officials, the attacks did not compromise water supply or wastewater services in a major way. The city of Braham, Minnesota, was forced to urge residents to minimize water use due to an “unknown reason,” while the city of Maple Plain declared a local state of emergency to expedite response measures.

The cyberattack is particularly concerning given its timing and nature. Just days before the attack, the US Cybersecurity and Infrastructure Security Agency (CISA) updated a warning about Iranian-affiliated threat groups targeting programmable logic controllers (PLCs) and other Internet-connected operational technology (OT) devices at critical infrastructure organizations across the US. The advisory specifically identified PLCs from Rockwell Automation/Allen Bradley, Schneider Electric, and Siemens as being of interest to the attackers.

The attacks follow a disturbing trend of state-directed threat groups targeting critical infrastructure services in the US. Iranian state-directed groups, such as CyberAv3ngers, have been linked to several high-profile cyberattacks in recent years. Researchers believe that the operational tradecraft used in this attack bears the fingerprints of these groups, exploiting Internet-facing PLCs and native vendor engineering software to bypass authentication and extract project files.

The Minnesota attacks are a sobering reminder of the sector’s vulnerability to sophisticated cyberattacks. The US government has warned repeatedly about the risks posed by Iranian-affiliated threat groups targeting critical infrastructure services in the US. It is essential that water utilities and other critical infrastructure organizations prioritize cybersecurity measures, including implementing robust OT security controls, conducting regular vulnerability assessments, and training personnel on incident response.

As this incident highlights, the consequences of a successful cyberattack can be far-reaching, disrupting critical services and compromising public safety. It is imperative that policymakers, water utilities, and stakeholders work together to address these vulnerabilities and ensure the resilience of our critical infrastructure. By doing so, we can prevent such incidents from occurring in the future and protect the nation’s critical infrastructure from increasingly sophisticated cyber threats.


Source: Dark Reading — 2026-07-30