Coordinated Cyberattack Targets More Than 30 Minnesota Water Systems, Prompting State and Federal Response

The CyberSec Guru

Updated on:

30+ Minnesota Water Systems Hit by Coordinated Cyberattack

If you like this post, then please share it:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Why your support matters: Zero paywalls: Keep the main content 100% free for learners worldwide.

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

A coordinated cyberattack targeting operational technology (OT) at more than 30 community water systems across Minnesota has triggered a large-scale incident response involving Minnesota IT Services (MNIT), the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), the Federal Bureau of Investigation (FBI), and the Minnesota Fusion Center. The attacks occurred between July 26 and July 27, disrupting automated operating controls at multiple municipal water utilities, although officials say there is currently no evidence that drinking water quality or public safety was affected.

The incident represents one of the largest publicly disclosed coordinated cyber campaigns against municipal water infrastructure in the United States in recent years. While investigators have not identified the threat actor, malware family, or initial access technique, the attacks highlight the growing focus of adversaries on operational technology environments rather than traditional enterprise IT networks. At the time of writing, authorities have not attributed the activity to any specific nation-state or cybercriminal group, and no ransom demand or political motive has been publicly disclosed. Currently, CyberAv3ngers, which is an Iran-linked group is suspected to have carried out the attacks. This is yet another big development in the US-Iran War

What Happened?

According to MNIT, attackers targeted operational technology supporting more than 30 community water systems over a 48-hour period. Minnesota activated its statewide cybersecurity incident response capabilities shortly after the attacks were detected, with federal agencies joining the investigation to assist with technical analysis, threat intelligence, containment, and recovery efforts.

Only a handful of affected municipalities have been publicly identified so far, including Braham, Plymouth, South St. Paul, and Maple Plain. Officials have not released the names of the remaining impacted utilities, and the state has not disclosed how many of the targeted organizations were successfully compromised versus merely subjected to intrusion attempts.

Investigators have also withheld details regarding the attack vector, any exploited vulnerabilities, the software or hardware vendors involved, and whether the affected organizations shared common remote management infrastructure or industrial control system components.

Braham Experienced the Most Significant Operational Disruption

The most visible operational impact occurred in the City of Braham, approximately 50 miles north of Minneapolis.

On the morning of July 27, city officials announced that the municipal water treatment plant had unexpectedly gone offline. Less than two hours later, operators restored the facility and determined that the outage resulted from what the city described as a malicious cyberattack against computerized operating systems controlling the plant.

According to city officials, the attackers disabled operating controls responsible for managing the well and water treatment process, temporarily shutting down the facility until public works personnel restored normal operations. Importantly, officials stated that the intrusion caused no physical damage to plant equipment, did not contaminate drinking water, and did not require residents to boil or restrict water usage.

The relatively quick restoration suggests that plant operators retained the ability to recover systems locally and return equipment to service without prolonged interruption.

Other Communities Report Similar Activity

Plymouth reported cyber activity affecting computerized systems associated with water towers and sanitary sewer lift stations beginning overnight on July 26. South St. Paul disclosed an attack involving its municipal water utility, while Maple Plain also confirmed cybersecurity-related disruptions.

📬 Stay Ahead of Cyber Threats

Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.

Subscribe to the Newsletter →

Although each municipality reported different operational impacts, officials consistently emphasized that drinking water remained safe and that no evidence indicated compromise of water quality or treatment processes.

Braham officials also indicated they were aware of several additional Minnesota communities experiencing similar attacks, reinforcing the state’s assessment that the activity formed part of a coordinated campaign rather than isolated incidents.

Why Operational Technology Was the Target

Unlike conventional cyberattacks that primarily seek to steal data, attacks against water utilities increasingly focus on industrial control systems responsible for operating physical infrastructure.

Modern municipal water systems rely on Supervisory Control and Data Acquisition (SCADA) environments consisting of programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), engineering workstations, sensors, pumps, valves, chemical dosing systems, reservoirs, and telemetry networks.

Water Treatment Plant Network
Water Treatment Plant Network

These components continuously exchange information that allows operators to monitor water pressure, treatment chemistry, storage levels, flow rates, pump status, and equipment health while remotely controlling physical processes.

When attackers interfere with these operational systems, the objective is often disruption rather than data theft. Manipulating control logic or disabling operator interfaces can force facilities into manual operation, temporarily halt pumping or treatment processes, interrupt communications with remote sites, or trigger automated safety shutdowns designed to prevent equipment damage.

Based on the information released so far, the Minnesota attacks appear to have primarily affected operating controls rather than physical treatment processes. Publicly available information does not indicate that attackers altered chemical dosing, manipulated sensor readings, or attempted to contaminate drinking water. Authorities have likewise not reported damage to PLC firmware or destruction of industrial equipment.

What Authorities Have Not Confirmed

Despite widespread reporting, several critical questions remain unanswered.

Officials have not publicly confirmed:

  • The identity of the threat actor.
  • Whether ransomware or destructive malware was involved.
  • The initial access method.
  • Whether vulnerabilities were exploited.
  • Whether compromised credentials enabled access.
  • Whether a common vendor or software platform linked the affected utilities.
  • Whether internet-exposed HMIs, VPN appliances, remote desktop services, or third-party remote management products were involved.
  • Whether attackers maintained persistent access before launching the coordinated activity.

Because of these unknowns, attributing the campaign or speculating about attacker motivations would be premature.

Why Water Utilities Continue to Face Elevated Cyber Risk

Municipal water infrastructure has become an increasingly attractive target because many facilities operate aging industrial control systems that were originally designed for reliability and continuous operation rather than cybersecurity.

Historically, many SCADA environments functioned as isolated networks. Over time, utilities introduced remote monitoring, centralized management, cloud connectivity, contractor access, and integration with enterprise IT systems. While these capabilities improve operational efficiency, they also expand the attack surface if appropriate segmentation and authentication controls are not implemented.

Federal agencies have repeatedly warned that internet-accessible industrial control components remain one of the most common weaknesses observed across the water sector. Exposed HMIs, weak authentication, default credentials, insufficient network segmentation, and insecure remote access continue to appear during cybersecurity assessments conducted by EPA and CISA.

Minnesota itself requires community public water systems using operational technology to perform annual cybersecurity assessments, reflecting growing recognition that cyber resilience has become a core component of water system safety.

The Broader Threat Landscape

The Minnesota incident did not occur in isolation.

Earlier this year, EPA, CISA, the FBI, and the NSA jointly warned that Iranian-affiliated threat actors were actively targeting operational technology within U.S. drinking water and wastewater systems. That advisory described ongoing efforts to exploit weaknesses in industrial environments supporting critical infrastructure, although there is currently no public evidence linking those campaigns to the Minnesota attacks.

Separately, EPA has reported identifying hundreds of cybersecurity weaknesses across U.S. water systems during nationwide assessments and continues to encourage utilities to strengthen authentication, reduce internet exposure, improve asset inventories, and implement stronger operational security practices.

Response and Ongoing Investigation

Minnesota IT Services is coordinating the state’s technical response while working alongside local governments, the FBI, CISA, the EPA, and the Minnesota Fusion Center.

According to MNIT, incident responders are assisting affected utilities with forensic analysis, threat intelligence sharing, recovery operations, and determining the overall scope of the coordinated campaign. Officials caution that identifying the complete impact of attacks against operational technology environments requires detailed examination of system logs, industrial devices, network traffic, and engineering workstations, meaning the investigation may continue for some time.

As of publication, no boil-water notices have been issued in connection with these incidents, and authorities continue to state that public drinking water remains safe across the identified communities.

Conclusion

The coordinated attacks against more than 30 Minnesota community water systems underscore how operational technology has become a primary target for threat actors seeking to disrupt critical infrastructure rather than steal information. Although the attacks temporarily affected automated operating controls at several facilities, officials report no evidence that drinking water safety was compromised or that physical damage occurred.

Much of the technical picture remains unknown. Investigators have not disclosed the intrusion method, exploited vulnerabilities, malware, or any attribution, making speculation inappropriate at this stage. As forensic work continues, this incident will likely become an important case study in how coordinated attacks against municipal operational technology are detected, contained, and investigated, while reinforcing the need for continued investment in cybersecurity across the water sector.

Sources:

Buy me A Coffee!

Support The CyberSec Guru’s Mission

🔐 Fuel the cybersecurity crusade by buying me a coffee! Your contribution powers free tutorials, hands-on labs, and security resources.

Why your support matters:
  • Writeup Access: Get complete writeup access within 12 hours
  • Zero paywalls: Keep the main content 100% free for learners worldwide

Perks for one-time supporters:
☕️ $5: Shoutout in Buy Me a Coffee
🛡️ $8: Fast-track Access to Live Webinars
💻 $10: Vote on future tutorial topics + exclusive AMA access

“Your coffee keeps the servers running and the knowledge flowing in our fight against cybercrime.”☕ Support My Work

Buy Me a Coffee Button

If you like this post, then please share it:

News

Discover more from The CyberSec Guru

Subscribe to get the latest posts sent to your email!

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from The CyberSec Guru

Subscribe now to keep reading and get access to the full archive.

Continue reading