Skip to main content

Hackers Disrupt Minnesota Water Utilities in Coordinated Cyberattack

Interior of a municipal water treatment plant with industrial controls and machinery, and a cityscape visible through large…

"The water plant was offline for an unknown reason," the City of Braham told residents on Monday — a terse notice that, within hours, became part of a wider cybersecurity alarm across Minnesota.

Scope and timeline of the attacks

On Sunday and Monday, July 26 and 27, hackers targeted operational technology (OT) systems at more than 30 community water systems across Minnesota, prompting Minnesota IT Services (MNIT) to activate its statewide cybersecurity incident response capabilities. MNIT described the activity as a "coordinated cyberattack" and moved to assess impacts and support affected utilities.

Local effects: Braham and other communities

City of Braham officials initially reported the city's water plant was offline for an "unknown reason." Roughly three hours later the city issued an update saying the plant was back online, "filtering and treating water as expected," and that crews had identified the outage as the result of "a malicious cyber-attack of computerized operating systems by unknown actors."

Local media also reported that other communities experienced temporary equipment malfunctions beginning Sunday. Those communities responded by switching to manual operations or implementing contingency plans to maintain normal services, according to the reporting cited by MNIT.

MNIT stated it was not aware of any requests from Minnesota cities asking residents to change their drinking water usage.

MNIT's multi-jurisdictional response

MNIT said its cybersecurity teams are working with federal, state, local, Tribal, and private-sector partners to investigate the incident and to strengthen the security of Minnesota's critical infrastructure. The agency described concrete actions its teams are taking: sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack.

CISA guidance, prior PLC warnings, and the broader threat context

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published guidance the day before MNIT's statement recommending that critical infrastructure organizations isolate key OT systems to ensure continuity of critical services during a cyberattack. The document is titled "CI Fortify – Advice for isolating vital systems" and was created jointly by CISA, the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.

While the actor behind the Minnesota water systems attacks remains unknown, government agencies have previously warned that critical infrastructure is frequently targeted by state-sponsored hackers for espionage or in preparation for disruptive and destructive activity in the event of a crisis or conflict. Earlier this year, U.S. agencies warned of Iranian-linked cyber activity that targeted programmable logic controllers (PLCs). A joint advisory issued in April stated that cyber actors associated with Iran had been exploiting exposed Rockwell Automation/Allen-Bradley PLC devices since March; that activity disrupted operations and caused financial losses across multiple sectors, including government services and facilities, water and wastewater systems, and the energy sector.

What this means for Minnesota utilities, federal partners, and residents

  • Local utilities: Utilities affected in this incident are operating contingency measures — manual operations and other pre-planned responses — while MNIT assists with containment, investigation, and remediation. The restored service in Braham shows one utility's contingency and recovery worked within hours.
  • Federal, state, and Tribal partners: MNIT's coordination with federal and other partners underscores a cross-jurisdictional investigative and recovery posture. Those partners also provide threat intelligence and guidance, including CISA's advice on isolating OT systems to preserve critical services.
  • Residents: Authorities reported no requests for changes to drinking water usage at the time of MNIT's statement, but communities experiencing equipment malfunctions enacted contingency plans to maintain service continuity while investigations proceed.

The technical and investigative work now underway will determine how the attackers gained access to OT environments, what was altered or extracted, and whether similar utilities remain vulnerable. MNIT's activation of statewide incident response and the application of CISA's "CI Fortify" recommendations frame the immediate priorities: contain the intrusion, restore safe operations, and harden isolated OT systems to avert further disruption. Who carried out the attacks remains unresolved; that unanswered question, and how broadly the vulnerabilities extend, will shape the next phase of the response.

Original story