Coordinated Cyberattack Disrupts Over 30 Minnesota Water Utilities
A series of coordinated cyberattacks targeted operational technology (OT) systems across more than 30 community water systems in Minnesota. The incidents, occurring over a Sunday and Monday, prompted a statewide cybersecurity response and highlighted the critical vulnerability of essential infrastructure.
# Coordinated Cyberattack Disrupts Over 30 Minnesota Water Utilities

The **Minnesota IT Services (MNIT)** agency has activated its cybersecurity incident response capabilities across the entire state following a series of coordinated cyberattacks. These attacks targeted operational technology (OT) systems at over 30 local water utilities.
## Attacks Impact Water Operations
The incidents unfolded on Sunday and Monday, July 26 and 27. The **City of Braham** was among the first to report issues, stating early Monday that its water plant was "offline for an unknown reason." Crews worked quickly to troubleshoot the problem, restoring services within approximately three hours.
An update from the **City of Braham** later confirmed the outage was "a result of a malicious cyber-attack of computerized operating systems by unknown actors."
Other communities in Minnesota also reported temporary equipment malfunctions since Sunday, responding by switching to manual operations or implementing contingency plans to maintain normal water services.
## Statewide Response and Investigation
**MNIT** is now collaborating with federal, state, local, Tribal, and private-sector partners to investigate the coordinated attacks. The agency's primary focus is to fortify the security posture of Minnesota's critical infrastructure.
**MNIT** cybersecurity teams are actively assessing the cyber impacts, sharing threat intelligence, providing guidance on response efforts and best practices, and assisting affected utilities in containing, investigating, and remediating damages. As of now, **MNIT** is not aware of any requests for residents to alter their drinking water usage.
## CISA Advises Critical Infrastructure on System Isolation
In response to the growing threat landscape, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**, in conjunction with the **Australian Signals Directorate's Australian Cyber Security Centre (ACSC)**, the **FBI**, and other international partners, published guidance titled "CI Fortify β Advice for isolating vital systems." This document recommends that critical infrastructure organizations isolate key OT systems to ensure the continuity of essential services during a cyberattack.
While the specific threat actor behind the Minnesota attacks remains unknown, government agencies frequently highlight that critical infrastructure is a prime target for state-sponsored hackers. These activities often aim for espionage or to prepare for potentially disruptive and destructive actions during times of crisis or conflict.
Earlier this year, the U.S. issued warnings about **Iranian** hackers specifically targeting programmable logic controllers (**PLCs**) within critical infrastructure organizations. A joint advisory in April detailed that cyber actors associated with **Iran** had been exploiting exposed **Rockwell Automation/Allen-Bradley PLC** devices since March, leading to operational disruptions and financial losses across sectors including government services, water and wastewater systems, and energy.