Additional Coverage:
- Water cyberattack hits at least 7 states (foxnews.com)
A recent coordinated cyberattack disrupted operational technology at over 30 community water systems across Minnesota and six other states, highlighting vulnerabilities in the infrastructure that delivers clean water to millions.
The incident began on July 26 and 27, when Minnesota IT Services (MNIT) activated the state’s cybersecurity response team and enlisted federal agencies to investigate the breach. One water treatment plant in Braham temporarily went offline, while other communities experienced issues with automated controls and communication equipment. Despite these challenges, manual operations and backup procedures ensured continuous water service, and officials confirmed there was no need for residents to alter or reduce their water usage.
The FBI has reported that water and wastewater utilities across seven states were affected, with some operations experiencing degraded functionality. This attack raises concerns about the resilience of local utilities nationwide and their ability to maintain operations if hackers compromise their control systems.
Operational technology (OT) – the computerized systems that manage physical equipment like pumps and valves – was the target. Braham’s water plant was restored within hours after initially going offline due to what officials later confirmed was a cyberattack.
In Plymouth, communication issues impacted water towers and wastewater stations, but water quality and levels remained stable. South St.
Paul and Maple Plain also reported cyber incidents affecting their water utility systems, with crews relying on contingency plans to maintain normal operations.
Though more than 30 systems were targeted, only four communities have detailed their specific impacts publicly. Investigators have not officially attributed the attack, but a report from The New York Times cited sources suggesting Iranian hackers may be responsible. President Donald Trump, however, rejected this claim, and authorities caution that the investigation is ongoing and attribution could change.
The timing is notable, as the Cybersecurity and Infrastructure Security Agency (CISA) issued warnings earlier this year about Iranian-affiliated hackers targeting programmable logic controllers-devices commonly used in water and critical infrastructure. CISA’s alerts have expanded to include equipment from several manufacturers, emphasizing the growing cyber threat landscape.
This event underscores the risks faced by America’s roughly 170,000 water and wastewater systems. Many utilities rely on internet-connected technology for remote monitoring and control, which, if not properly secured, can provide a pathway for cyber intrusions. Smaller communities, often constrained by limited budgets and older technology, may be particularly vulnerable due to less robust cybersecurity defenses and fewer dedicated staff.
Officials stress that a cyberattack does not necessarily mean water contamination. Minnesota authorities confirmed no known impact on water quality and encouraged residents to continue normal water use unless otherwise directed. Nevertheless, the Environmental Protection Agency (EPA) warns that hackers could disrupt treatment processes or damage equipment, potentially compromising water safety.
Manual operations served as a critical fallback in Minnesota, but experts emphasize the importance of regular training and testing of these contingency procedures. On July 28, CISA released new guidance advising infrastructure operators to isolate vital operational technology from less secure networks to maintain service continuity during cyber incidents.
Additional recommended protections include removing unnecessary internet exposure, changing default passwords, providing unique login credentials for employees, and monitoring access closely. EPA inspections have revealed concerning lapses, such as default passwords in use and shared or outdated accounts, highlighting areas for improvement.
For residents, officials recommend staying informed through official city or health department channels, adhering to any boil-water or water use advisories, and being vigilant against scams that often accompany service disruptions. It is advised to avoid responding to unsolicited messages or calls regarding water service and to verify communications via official utility contact information.
The Minnesota cyberattack serves as a wake-up call for municipalities nationwide to assess their cybersecurity posture, particularly for critical water infrastructure. Ensuring that communities can operate essential services manually and strengthening digital defenses should be priorities for local and state governments alike.
How prepared is your community to respond to a cyberattack on its water system? What information would you expect from local officials during such an event? Share your thoughts and concerns at CyberGuy.com.
Read More About This Story:
- Water cyberattack hits at least 7 states (foxnews.com)