A coordinated cyberattack targeting more than 30 community water utilities across Minnesota has prompted a statewide cybersecurity response.
While no impacts to drinking water quality have been reported, the incident demonstrates how attacks against industrial control systems can temporarily disrupt essential public services.
Even though this is being reported as an attack against OT, is it possible the initial compromise occurred on the enterprise IT network, with OT fail-safes or safety mechanisms triggering as a result?
“The challenge is that many security programs are still built to detect noisy attacks like ransomware or smash and grab intrusions,” said John Strand, Owner, Black Hills Information Security, Inc, in an email to eSecurityPlanet.
He added, “They’re much less effective at finding the low and slow activity that characterizes many nation-state operations.”
Key takeaways of the Minnesota water utility incident
- More than 30 Minnesota water utilities were targeted in a coordinated cyberattack that allegedly disrupted operational technology (OT) systems.
- Utilities maintained water service through manual operations and contingency plans, with no reported impacts to drinking water quality.
- Officials have not identified the threat actor involved or disclosed technical details.
- The incident reinforces the need for layered OT security, including network segmentation, continuous monitoring, secure remote access, and tested incident response plans.
What happened during the Minnesota water utility cyberattack
The coordinated attacks occurred on July 26 and 27 and targeted the operational technology (OT) systems used by more than 30 community water utilities across Minnesota.
In response, Minnesota IT Services (MNIT) activated its statewide cyber incident response and coordinated with federal, state, local, Tribal, and private-sector partners to investigate the attacks and support affected utilities.
As the investigation continues, officials have not publicly disclosed how the attackers gained access to the affected OT environments or identified the threat actor responsible.
One of the first publicly confirmed disruptions occurred in the City of Braham, where officials reported that the municipal water treatment plant had unexpectedly gone offline.
Within a few hours, crews restored operations and confirmed the facility had resumed normal filtering and water treatment activities.
Other Minnesota communities also reported temporary equipment malfunctions, prompting utilities to switch to manual operations or activate contingency plans while investigators responded.
Despite the disruptions, state officials said residents have not been asked to change their drinking water usage, indicating the attacks affected operations rather than water quality or public safety.
The incident also highlights the unique cybersecurity challenges facing operational technology environments.
Unlike IT systems that manage business data, OT systems control physical processes such as water treatment, pumping, chemical dosing, and distribution.
As a result, even attacks that do not involve ransomware or data theft can disrupt essential services by forcing operators to rely on manual controls until systems are restored.
The investigation remains ongoing, and no technical details have been released as of publication.
How organizations can reduce OT security risk
The incident also serves as a reminder that reducing OT risk requires a layered approach to securing systems and preparing for operational disruptions.
- Inventory OT assets and continuously monitor industrial networks to quickly detect unauthorized activity and emerging threats.
- Segment operational technology from enterprise IT networks and minimize Internet-facing systems and remote management interfaces, like HMIs.
- Secure remote and third-party access with multi-factor authentication, least privilege, and time-limited privileged access.
- Establish a risk-based process for patching and hardening OT systems, including regular reviews of outdated software, firmware, and device configurations.
- Continuously monitor industrial control systems for unusual commands, configuration changes, and other indicators of compromise.
- Regularly back up PLCs, SCADA systems, HMI configurations, and other critical OT assets, and validate that they can be restored quickly after an incident.
- Test incident response, business continuity, and manual operating procedures with both IT and OT teams to ensure critical services can be maintained and restored during a cyberattack.
A proactive OT security strategy helps reduce the attack surface, improve cyber resilience, and ensure essential operations can continue during and after an incident.
Bottom line
The Minnesota incident is another reminder that protecting critical infrastructure requires treating IT and OT as interconnected security domains rather than separate environments.
As geopolitical tensions increasingly spill into cyberspace, critical infrastructure operators should expect continued interest from both financially motivated threat actors and nation-state groups seeking to disrupt essential services or establish strategic access.
Whether the attack began in IT, OT, or both, organizations should improve visibility across both environments and validate resilience.
As IT and OT environments become increasingly connected, organizations can use Zero Trust to help strengthen security around OT systems.





