A coordinated cyberattack struck operational technology at more than 30 community water systems across Minnesota over the weekend of July 26 and 27, prompting a statewide cybersecurity response involving state, local and federal agencies. The cities of Braham, Plymouth, South St. Paul and Maple Plain have publicly confirmed disruptions ranging from plant outages to communications failures affecting automated controls.
In Braham, a community of roughly 1,700 people, the attack disabled computerized operating controls and briefly knocked the city’s well and water treatment plant offline. Local officials asked residents to minimize water use while the plant was down, and public works crews reportedly restored operations within about two hours by switching to manual controls.
Plymouth reported cellular communications failures at two water towers and at multiple wastewater lift stations, though the city said it kept its systems running by shifting to manual operation. South St. Paul and Maple Plain both reported that automated utility controls were affected but that services continued uninterrupted, with Maple Plain declaring a local state of emergency to support its response efforts, according to local reporting.
Minnesota IT Services, the state’s central technology agency known as MNIT, said it was not aware of any active requests for residents to change their drinking water use as a result of the attack. Officials have so far declined to publicly identify the attacker, the specific products or vulnerabilities exploited, or whether any data was stolen during the intrusion.
“At this point, we can confirm that more than 30 water systems throughout the state were impacted,” MNIT said in a statement. “The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions.”
MNIT said the incidents shared common characteristics in their timing, their methods of access, and the type of infrastructure targeted, findings that point toward a coordinated campaign rather than a series of unrelated intrusions. The agency is working alongside the Cybersecurity and Infrastructure Security Agency, the Environmental Protection Agency, the FBI and the affected local utilities to investigate the incident and secure systems going forward.
MNIT Assistant Commissioner John Israel said the whole of government response allowed agencies to contain the incident and prevent more serious impacts to critical services. Security researchers who have reviewed the incident have noted it fits a broader pattern of attacks targeting operational technology at small and mid sized water utilities, which often run on limited cybersecurity budgets and legacy industrial control systems.
The episode adds to a string of recent warnings from CISA and federal partners about the vulnerability of US water infrastructure to both criminal and state-linked hacking groups, and is likely to intensify calls for additional funding to harden operational technology at utilities nationwide.
Sources: The Hacker News, CBS Minnesota, SecurityWeek