AIO APEX

Coordinated cyberattack disrupts operational controls at 30+ Minnesota water utilities

The Hacker News
Share:
Coordinated cyberattack disrupts operational controls at 30+ Minnesota water utilities

More than 30 community water systems across Minnesota were hit by a coordinated cyberattack on July 26 and 27 that targeted the operational technology controlling pumps, valves, and treatment processes, triggering a statewide cybersecurity response from Minnesota IT Services (MNIT). The attack knocked at least one treatment plant offline and forced several utilities to switch from automated to manual operation while investigators worked to contain the intrusion.

What happened on the ground

The City of Braham's water plant went offline entirely, with officials initially citing an "unknown reason" before confirming hours later that crews had identified a malicious cyberattack against the plant's computerized operating systems. Braham asked residents to minimize water use until treatment resumed; the plant was back online and filtering water "as expected" within about three hours.

Plymouth reported cellular communications failures at two water towers and multiple wastewater lift stations but kept services running manually. South St. Paul and Maple Plain both saw automated utility controls affected; Maple Plain declared a local state of emergency to support its response, though water service in both cities continued without interruption. MNIT said it is not aware of any utility asking residents to change their drinking water use as a result of the incident, and officials have stated the attack did not affect water quality.

Why "coordinated" is the operative word

Only four of the roughly 30 affected systems — Braham, Plymouth, South St. Paul, and Maple Plain — have been publicly named; the rest remain classified as nonpublic while the investigation continues. MNIT told reporters the incidents shared common characteristics in their timing, method of access, and the type of infrastructure targeted, which is what led the state to describe the activity as coordinated rather than a series of unrelated incidents. Investigators have identified similarities in how the systems were accessed but have not disclosed technical details publicly, and attribution has not been finalized — MNIT said the pattern is consistent with activity federal partners have observed in other states and sectors, though it's not yet confirmed whether a single actor is responsible for every incident.

A response built for critical infrastructure, not a single utility

MNIT is coordinating containment, investigation, and recovery with the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the FBI, and the affected utilities themselves. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota's chief information security officer.

The timing lines up with broader federal guidance: CISA, Australia's Cyber Security Centre, the FBI, and international partners published joint advice the same week on isolating vital operational technology systems during cyberattacks, aimed specifically at helping critical infrastructure operators maintain continuity of service when their control systems are compromised.

The pattern behind the incident

Water utilities have become an increasingly common target for this category of attack precisely because so many of them run on aging OT infrastructure with limited security budgets and small IT staffs relative to their responsibility. A single municipal water plant rarely has the resources of an enterprise security team, yet it controls infrastructure that, if disrupted broadly enough, has direct public health consequences. That mismatch — high consequence, low defensive capacity — is what makes a coordinated, multi-utility attack like this one a meaningfully different threat than a breach at any single company: the same access method or vulnerability, replicated across dozens of independently-run but similarly-configured systems, can cause simultaneous disruption at a scale no individual utility could have anticipated or resourced against on its own. As the investigation continues, that's likely to be the central lesson state and federal officials draw from Minnesota's response, as reported by The Hacker News and BleepingComputer.

Originally reported by The Hacker News. Read the original article for additional details.

View original source
Share:
Coordinated cyberattack disrupts operational controls at 30+ Minnesota water utilities | AIO APEX