Minnesota Water Utilities Hit by Coordinated Cyberattack 

A coordinated cyberattack hit more than 30 Minnesota water utilities.

Written By
Ken Underhill
Ken Underhill
Jul 29, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A coordinated cyberattack targeting more than 30 community water utilities across Minnesota has prompted a statewide cybersecurity response.

While no impacts to drinking water quality have been reported, the incident demonstrates how attacks against industrial control systems can temporarily disrupt essential public services.

Even though this is being reported as an attack against OT, is it possible the initial compromise occurred on the enterprise IT network, with OT fail-safes or safety mechanisms triggering as a result? 

“The challenge is that many security programs are still built to detect noisy attacks like ransomware or smash and grab intrusions,” said John Strand, Owner, Black Hills Information Security, Inc, in an email to eSecurityPlanet.

He added, “They’re much less effective at finding the low and slow activity that characterizes many nation-state operations.” 

Key takeaways of the Minnesota water utility incident

  • More than 30 Minnesota water utilities were targeted in a coordinated cyberattack that allegedly disrupted operational technology (OT) systems.
  • Utilities maintained water service through manual operations and contingency plans, with no reported impacts to drinking water quality.
  • Officials have not identified the threat actor involved or disclosed technical details.
  • The incident reinforces the need for layered OT security, including network segmentation, continuous monitoring, secure remote access, and tested incident response plans.

What happened during the Minnesota water utility cyberattack 

The coordinated attacks occurred on July 26 and 27 and targeted the operational technology (OT) systems used by more than 30 community water utilities across Minnesota. 

In response, Minnesota IT Services (MNIT) activated its statewide cyber incident response and coordinated with federal, state, local, Tribal, and private-sector partners to investigate the attacks and support affected utilities. 

As the investigation continues, officials have not publicly disclosed how the attackers gained access to the affected OT environments or identified the threat actor responsible.

One of the first publicly confirmed disruptions occurred in the City of Braham, where officials reported that the municipal water treatment plant had unexpectedly gone offline. 

Within a few hours, crews restored operations and confirmed the facility had resumed normal filtering and water treatment activities. 

Other Minnesota communities also reported temporary equipment malfunctions, prompting utilities to switch to manual operations or activate contingency plans while investigators responded. 

Advertisement

Despite the disruptions, state officials said residents have not been asked to change their drinking water usage, indicating the attacks affected operations rather than water quality or public safety. 

The incident also highlights the unique cybersecurity challenges facing operational technology environments. 

Unlike IT systems that manage business data, OT systems control physical processes such as water treatment, pumping, chemical dosing, and distribution. 

As a result, even attacks that do not involve ransomware or data theft can disrupt essential services by forcing operators to rely on manual controls until systems are restored. 

The investigation remains ongoing, and no technical details have been released as of publication. 

How organizations can reduce OT security risk

The incident also serves as a reminder that reducing OT risk requires a layered approach to securing systems and preparing for operational disruptions. 

  • Inventory OT assets and continuously monitor industrial networks to quickly detect unauthorized activity and emerging threats.
  • Segment operational technology from enterprise IT networks and minimize Internet-facing systems and remote management interfaces, like HMIs.
  • Secure remote and third-party access with multi-factor authentication, least privilege, and time-limited privileged access.
  • Establish a risk-based process for patching and hardening OT systems, including regular reviews of outdated software, firmware, and device configurations.
  • Continuously monitor industrial control systems for unusual commands, configuration changes, and other indicators of compromise.
  • Regularly back up PLCs, SCADA systems, HMI configurations, and other critical OT assets, and validate that they can be restored quickly after an incident.
  • Test incident response, business continuity, and manual operating procedures with both IT and OT teams to ensure critical services can be maintained and restored during a cyberattack.

A proactive OT security strategy helps reduce the attack surface, improve cyber resilience, and ensure essential operations can continue during and after an incident. 

Bottom line

The Minnesota incident is another reminder that protecting critical infrastructure requires treating IT and OT as interconnected security domains rather than separate environments. 

As geopolitical tensions increasingly spill into cyberspace, critical infrastructure operators should expect continued interest from both financially motivated threat actors and nation-state groups seeking to disrupt essential services or establish strategic access.

Whether the attack began in IT, OT, or both, organizations should improve visibility across both environments and validate resilience.

As IT and OT environments become increasingly connected, organizations can use Zero Trust to help strengthen security around OT systems.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.