Coordinated Cyberattack Targets More Than 30 Minnesota Water Utilities

Plymouth, MN Water Tower/Source: Plymouth Public Works

EXECUTIVE SUMMARY

A coordinated malware campaign struck operational technology networks at more than 30 Minnesota water and wastewater utilities between July 26 and July 27, forcing the Braham water treatment plant offline and prompting Minnesota IT Services (MNIT) to activate a statewide emergency cybersecurity response. Plymouth and South St. Paul also reported disrupted cellular communications at water towers and lift stations. Officials confirmed no impact to drinking water quality and no customer data breach.

ANALYSIS

The attack targeted industrial control systems and supervisory control and data acquisition (SCADA) environments used to operate physical water treatment and distribution infrastructure. In Braham, the breach shut down the treatment plant entirely, requiring the city to ask residents to conserve water while restoration efforts proceeded. Plymouth reported cellular communication failures at two water towers and multiple wastewater lift stations. South St. Paul and Maple Plain also confirmed operational impact. At least four cities publicly disclosed breaches, with MNIT reporting the total affected community count at more than 30.

MNIT activated its emergency cybersecurity incident response capability and is coordinating with federal partners including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI Cyber Division. CISA issued advisory guidance for water sector operators within hours of the initial notifications. Investigators have not publicly attributed the intrusion to a specific actor, but officials noted that critical water infrastructure is a documented priority target for state-sponsored cyber groups seeking to pre-position access for future disruption operations.

The geographic scope distinguishes this attack from prior water sector intrusions. Rather than targeting a single facility, the campaign simultaneously breached more than 30 separate systems across communities ranging from small rural towns to suburban municipalities in the Minneapolis corridor. That simultaneity points toward a coordinated delivery mechanism: either a common software supply chain compromise affecting systems used by multiple utilities, a shared internet-exposed remote access path, or a botnet-style rollout of pre-loaded malware configured to execute simultaneously across pre-compromised targets.

Water utilities are among the most underprotected segments of US critical infrastructure. Many small and mid-sized systems operate with minimal IT staff, outdated SCADA systems that predate modern cybersecurity design standards, and no real-time intrusion detection. The Minnesota campaign follows a 2021 incident in Oldsmar, Florida, where an attacker briefly elevated sodium hydroxide levels in a water treatment system before an operator intervened. MNIT's statewide coordination response is a replicable model, but the attack confirms that the threat surface for US water systems remains broad and largely unsecured outside major metropolitan utilities.

SOURCES

Previous
Previous

DOJ Charges Hamas Financier Based in Istanbul; UK Arrests on US Request

Next
Next

Greek Anarchists Firebomb Three Ruling Party Homes in Thessaloniki, Killing One