A coordinated cyberattack targeted more than 30 community water systems across Minnesota, prompting a statewide cybersecurity response after several utilities experienced operational disruptions, including one water treatment facility shutdown.
The incidents occurred on July 26 and 27 and affected water and wastewater infrastructure in multiple communities. State officials said the impact varied between systems, with some experiencing communication problems while others reported disruptions to automated controls.
Multiple Water Utilities Report Operational Problems
Several Minnesota communities publicly confirmed disruptions linked to the cyber incident.
The city of Braham reported that its water treatment plant went offline and asked residents to reduce water consumption while operations were restored.
Plymouth officials said cellular communication issues affected two water towers and several wastewater lift stations. The city maintained operations by switching to manual procedures.
South St. Paul and Maple Plain also reported problems involving automated utility controls but were able to continue providing services. Maple Plain declared a local emergency to support its response efforts.
Minnesota IT Services (MNIT) said it was not aware of any active public health concerns requiring residents to change their drinking-water usage.
Investigation Underway Into Attack Method
Officials have not publicly identified the attackers, targeted technologies, exploited vulnerabilities, or confirmed whether any sensitive information was stolen.
MNIT confirmed that more than 30 water systems were affected but said the severity differed between individual utilities.
“The nature and extent of the impact varied by system,” the agency said, noting that investigators were still determining the full scope of the disruption.
Authorities identified similarities in the timing, access methods, and infrastructure targeted across the affected systems, leading officials to describe the activity as coordinated. However, investigators have not confirmed whether all incidents were carried out by the same threat actor.
State and Federal Agencies Join Response Effort
MNIT is coordinating with multiple organizations, including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the Federal Bureau of Investigation, and affected water providers.
Officials said the coordinated response helped contain the incident and reduce the risk of broader impacts to essential services.
John Israel, assistant commissioner at MNIT and Minnesota’s chief information security officer, emphasized that attacks against critical infrastructure require cooperation across government agencies and utility operators.
Possible Links to Broader Infrastructure Threats Investigated
The Minnesota incidents occurred shortly after U.S. agencies issued warnings about cyber activity targeting industrial control systems and internet-connected programmable logic controllers.
Federal authorities previously warned that Iranian-linked threat groups had targeted industrial systems used in critical infrastructure sectors, including water and wastewater facilities. Attackers in those campaigns were observed attempting to modify operational settings, access industrial project files, and interfere with control systems.
Officials have not confirmed any connection between those attacks and the Minnesota incidents.
Cybersecurity company Tenable said the tactics appeared consistent with activity historically associated with groups targeting industrial environments, while noting that the Minnesota attack has not been officially attributed to any specific actor.