More than 30 community water systems across Minnesota were targeted during a coordinated cyberattack on July 26 and 27, 2026, prompting the state to activate its cybersecurity incident-response capabilities.
The attack was directed at operational technology, commonly called OT: the computers, controllers, communication equipment and software used to monitor and operate physical infrastructure. At a water utility, these systems may control wells, pumps, water pressure, treatment equipment, chemical levels and distribution networks.
This was not merely an attack on office computers, email accounts or customer records. The intruders reportedly reached technology connected to the physical operation of water facilities.
Although several communities experienced equipment failures or temporary outages, Minnesota officials said they were unaware of any city requiring residents to stop using their drinking water. There was also no confirmed evidence that water quality had been compromised.
The incident nevertheless demonstrates why attacks against operational technology must be taken seriously. When hackers interfere with systems that control physical equipment, the consequences can extend beyond lost files or stolen information.
What happened in Minnesota?
Minnesota IT Services, also known as MNIT, confirmed that attackers targeted operational technology at more than 30 community water systems over the two-day period.
Several cities publicly reported problems, including Braham, Plymouth, South St. Paul and Maple Plain.
In Braham, the city’s water plant went offline on the morning of July 27. The computerized controls operating the city’s well and treatment plant were disrupted, temporarily leaving the community dependent on water already stored in its water tower.
City crews restored the plant within a few hours. Officials later said the outage had resulted from a malicious cyberattack against the plant’s computerized operating systems.
Other affected utilities reported equipment malfunctions, communication failures or problems with automated controls. Some operators switched to manual procedures or activated contingency plans while systems were investigated and restored.
The disruptions were limited enough that residents were generally able to continue using their water normally. That successful recovery should not obscure what the attackers reached: equipment responsible for operating an essential public service.
What is operational technology?
Operational technology includes hardware and software that monitors or controls machines and physical processes.
In a water system, OT may include:
- Programmable logic controllers, or PLCs, that operate pumps, valves and treatment equipment
- Supervisory control and data acquisition systems, commonly called SCADA systems
- Human-machine interfaces that allow operators to view conditions and control equipment
- Sensors that measure water pressure, tank levels, flow rates and chemical concentrations
- Remote-access systems used by employees, contractors or equipment vendors
- Communications links connecting wells, pumping stations, treatment plants and storage facilities
These systems provide enormous benefits. A small utility can monitor equipment located miles apart, receive immediate warnings about a malfunction and adjust operations without sending someone to every facility.
The same connectivity can create an opening for attackers when equipment is exposed directly to the Internet, protected by default passwords, connected through insecure remote-access software or left running with outdated firmware.
Many industrial devices were originally designed for reliability and long service life, not for constant exposure to modern cyber threats. Some remain in service for decades and cannot be patched or replaced as easily as an ordinary computer.
Why could an attack on a water system become dangerous?
Water utilities depend on several overlapping protections, including automated alarms, safety controls, routine testing and trained human operators. Compromising one computer does not automatically allow an attacker to poison a city’s water.
However, attackers who obtain sufficient control could potentially interfere with pumps, pressure, tank levels, alarms or treatment processes.
A loss of pumping capacity could reduce water pressure or interrupt service. Low pressure is a public-health concern because contaminated groundwater can enter damaged pipes through cracks or leaks. That is one reason utilities may issue boil-water notices after a major loss of pressure.
Attackers might also attempt to alter chemical dosing, disable alarms or display false information to operators. Even when independent safety systems prevent unsafe water from reaching the public, manipulating equipment could damage pumps, overflow tanks, flood parts of a facility or force employees to operate the system manually.
In Minnesota, officials did not report contamination or a public-health emergency. The concern is that attackers demonstrated access to systems capable of influencing real-world operations.
Who was responsible?
As of August 1, investigators had not publicly attributed the Minnesota attack to a specific country, criminal group or hacking organization.
Federal and state officials said the timing, methods of access and targeted equipment shared characteristics with other coordinated attacks against critical infrastructure. Iranian-affiliated hackers have previously targeted Internet-connected industrial controllers used by water and wastewater facilities, and federal agencies issued warnings earlier in 2026 about attacks against exposed programmable logic controllers.
That history makes Iranian involvement one possibility, but similarity is not proof. Attackers can imitate another group’s methods, use misleading names or plant evidence intended to influence investigators.
Until the FBI, CISA or another responsible agency releases a formal assessment, claims about who conducted this attack should be treated as preliminary.
The attacks may extend beyond Minnesota
The Minnesota incidents may be part of a broader campaign rather than an isolated attack against one state.
By August 1, reports indicated that water systems in at least seven states had experienced related malicious activity. Michigan disclosed attacks affecting nine water systems, while federal investigators continued examining incidents elsewhere.
Reported actions included changing passwords, altering network configurations, interfering with automated equipment and forcing facilities to reset systems or move to manual operations. Some facilities reportedly experienced pressure problems or flooding, although authorities said the affected systems continued to provide safe water.
This broader activity suggests that attackers may be searching for similar Internet-exposed equipment across multiple utilities rather than individually selecting each town.
An attacker can scan the Internet for a particular controller, remote-access service or configuration weakness. Once vulnerable installations are found, the same technique can be repeated against many organizations in a short period.
Small utilities face a difficult security problem
Large cities may have dedicated cybersecurity departments, round-the-clock monitoring and substantial technology budgets. A small community water system may have only a handful of employees responsible for treatment, maintenance, testing, regulatory compliance and emergency response.
That difference matters because a small town’s water is no less essential than the water serving a major city.
Smaller utilities may depend heavily on equipment vendors and outside contractors. Remote access can be necessary because a specialist may be located hours away from the facility. Removing that access entirely may make maintenance and emergency support more difficult.
The goal is therefore not simply to disconnect everything without considering the operational consequences. Utilities need to identify which connections are truly necessary, protect them appropriately and have a tested method for isolating critical systems when an attack occurs.
Minnesota activates a statewide response
MNIT activated Minnesota’s cybersecurity incident-response capabilities after learning of the attacks.
The response involved state, federal, local, Tribal and private-sector organizations, including:
- Minnesota IT Services
- The Minnesota Department of Public Safety
- The Minnesota Bureau of Criminal Apprehension and Minnesota Fusion Center
- The Minnesota Department of Health
- The Minnesota Pollution Control Agency
- The Cybersecurity and Infrastructure Security Agency
- The Environmental Protection Agency
- The Federal Bureau of Investigation
- Local water utilities
Responders shared threat intelligence and indicators of compromise, helped utilities investigate affected systems, assisted with containment and recovery, and monitored for related malicious activity.
Minnesota Chief Information Security Officer John Israel said the state’s response worked as intended, allowing organizations at multiple levels of government to coordinate quickly and help prevent more serious effects on essential services.
That coordination is important because a small utility may not have the personnel or equipment necessary to conduct a complex forensic investigation alone.
CISA advises utilities to prepare for isolation
The Minnesota attack occurred as CISA and international partners released guidance called CI Fortify: Advice for Isolating Vital Systems.
The guidance recommends that critical-infrastructure operators prepare in advance to separate vital operational systems from corporate networks, remote-access services, Internet-facing equipment and other less-trusted connections.
Organizations should identify the minimum equipment needed to continue providing their essential service. They should then document every connection to that equipment and determine where those connections can be disabled or physically disconnected during an emergency.
An effective isolation plan should answer several questions:
- Which systems must remain operational?
- Which connections can be safely disconnected?
- Who has authority to order the isolation?
- What conditions should trigger it?
- How will employees communicate if normal networks are unavailable?
- Can operators continue running the facility manually?
- What outside services or vendors will become unavailable?
- How will administrators verify that the isolation remains effective?
- How will systems eventually be cleaned, rebuilt and reconnected?
CISA recommends maintaining an offline or printed copy of the plan. An emergency document stored only on the compromised network may be inaccessible precisely when employees need it.
Isolation is more than unplugging a cable
Physical separation can be one of the strongest ways to protect vital equipment, but isolation can also introduce new risks.
Disconnected systems may no longer receive security updates or centralized monitoring. Employees may rely more heavily on USB drives and other removable media, potentially creating another route for malware. Remote facilities may lose communications, and outside technicians may no longer be able to troubleshoot equipment.
An isolation plan must therefore be designed and tested before an emergency.
CISA recommends testing the complete process rather than checking individual firewalls or switches separately. Hidden dependencies may not become apparent until an organization attempts to operate without its normal network, cloud services, telephone systems or vendor connections.
A plan that exists only on paper may fail when an actual attack begins.
What utilities should examine
Water and wastewater operators should determine whether industrial controllers, human-machine interfaces or remote-access services are reachable directly from the public Internet.
Basic protective measures include:
- Removing unnecessary Internet exposure from PLCs and other operational equipment
- Changing default usernames, passwords and authentication keys
- Using multifactor authentication for remote access wherever the equipment supports it
- Restricting remote connections to approved employees, vendors and locations
- Separating business networks from operational technology networks
- Installing supported firmware and security updates
- Disabling unused services and communication protocols
- Monitoring OT traffic for unexpected commands or overseas connections
- Maintaining offline backups of configurations and controller project files
- Testing manual operating procedures
- Keeping current contact information for state and federal incident responders
- Developing and rehearsing an emergency isolation plan
Utilities should also know what normal activity looks like. An organization cannot easily identify an unauthorized change if it does not maintain an inventory of its equipment, network connections, software versions and authorized users.
What residents should and should not conclude
The Minnesota attack does not mean that residents should assume their tap water is unsafe.
Public water systems routinely test water quality, and local authorities issue notices when residents need to boil water, limit consumption or take other precautions. No statewide drinking-water restriction resulted from the Minnesota attack.
Residents should rely on notices from their water utility, municipal government, public-health department or emergency-management agency rather than rumors circulating on social media.
It is still reasonable for households to maintain an emergency water supply. Cyberattacks are only one possible cause of a water outage; storms, earthquakes, broken pipes, power failures and equipment malfunctions can produce similar disruptions.
Emergency guidance commonly recommends storing at least one gallon of water per person per day for drinking and sanitation. Households should account for pets, medications and accessibility needs and should rotate stored water according to the container manufacturer’s instructions.
This was a warning, even without a disaster
The Minnesota water attack did not produce the catastrophic outcome people may imagine when they hear that hackers reached a treatment plant. Water continued flowing, operators activated backup procedures, affected equipment was restored and state and federal responders coordinated their work.
That is good news.
It is also evidence that attackers are actively seeking access to the machinery supporting basic public services.
Cybersecurity discussions often focus on stolen passwords, exposed Social Security numbers, ransomware payments and leaked corporate files. Operational-technology attacks introduce another dimension: a computer intrusion may change what a pump, valve, motor or treatment system does in the physical world.
The Minnesota incident should not be exaggerated into a claim that hackers poisoned the water. There is no confirmed evidence that they did.
It should also not be dismissed because the worst outcome did not occur.
More than 30 water systems were targeted in a coordinated campaign. At least one community temporarily lost computerized control of its well and treatment plant. Related attacks may have reached utilities across several states.
The defenses, contingency plans and human operators prevented a more serious emergency. The next step is making certain that every utility, including those serving small communities with limited resources, is prepared to do the same.
Sources for further reading
The following are sources for further reading. If you read this and you know people who may need this type of info, please share this blog post and the accompanying reading material.
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Hackers Target More Than 30 Minnesota Water Systems in Coordinated Cyberattack
More than 30 community water systems across Minnesota were targeted during a coordinated cyberattack on July 26 and 27, 2026, prompting the state to activate its cybersecurity incident-response capabilities.
The attack was directed at operational technology, commonly called OT: the computers, controllers, communication equipment and software used to monitor and operate physical infrastructure. At a water utility, these systems may control wells, pumps, water pressure, treatment equipment, chemical levels and distribution networks.
This was not merely an attack on office computers, email accounts or customer records. The intruders reportedly reached technology connected to the physical operation of water facilities.
Although several communities experienced equipment failures or temporary outages, Minnesota officials said they were unaware of any city requiring residents to stop using their drinking water. There was also no confirmed evidence that water quality had been compromised.
The incident nevertheless demonstrates why attacks against operational technology must be taken seriously. When hackers interfere with systems that control physical equipment, the consequences can extend beyond lost files or stolen information.
What happened in Minnesota?
Minnesota IT Services, also known as MNIT, confirmed that attackers targeted operational technology at more than 30 community water systems over the two-day period.
Several cities publicly reported problems, including Braham, Plymouth, South St. Paul and Maple Plain.
In Braham, the city’s water plant went offline on the morning of July 27. The computerized controls operating the city’s well and treatment plant were disrupted, temporarily leaving the community dependent on water already stored in its water tower.
City crews restored the plant within a few hours. Officials later said the outage had resulted from a malicious cyberattack against the plant’s computerized operating systems.
Other affected utilities reported equipment malfunctions, communication failures or problems with automated controls. Some operators switched to manual procedures or activated contingency plans while systems were investigated and restored.
The disruptions were limited enough that residents were generally able to continue using their water normally. That successful recovery should not obscure what the attackers reached: equipment responsible for operating an essential public service.
What is operational technology?
Operational technology includes hardware and software that monitors or controls machines and physical processes.
In a water system, OT may include:
These systems provide enormous benefits. A small utility can monitor equipment located miles apart, receive immediate warnings about a malfunction and adjust operations without sending someone to every facility.
The same connectivity can create an opening for attackers when equipment is exposed directly to the Internet, protected by default passwords, connected through insecure remote-access software or left running with outdated firmware.
Many industrial devices were originally designed for reliability and long service life, not for constant exposure to modern cyber threats. Some remain in service for decades and cannot be patched or replaced as easily as an ordinary computer.
Why could an attack on a water system become dangerous?
Water utilities depend on several overlapping protections, including automated alarms, safety controls, routine testing and trained human operators. Compromising one computer does not automatically allow an attacker to poison a city’s water.
However, attackers who obtain sufficient control could potentially interfere with pumps, pressure, tank levels, alarms or treatment processes.
A loss of pumping capacity could reduce water pressure or interrupt service. Low pressure is a public-health concern because contaminated groundwater can enter damaged pipes through cracks or leaks. That is one reason utilities may issue boil-water notices after a major loss of pressure.
Attackers might also attempt to alter chemical dosing, disable alarms or display false information to operators. Even when independent safety systems prevent unsafe water from reaching the public, manipulating equipment could damage pumps, overflow tanks, flood parts of a facility or force employees to operate the system manually.
In Minnesota, officials did not report contamination or a public-health emergency. The concern is that attackers demonstrated access to systems capable of influencing real-world operations.
Who was responsible?
As of August 1, investigators had not publicly attributed the Minnesota attack to a specific country, criminal group or hacking organization.
Federal and state officials said the timing, methods of access and targeted equipment shared characteristics with other coordinated attacks against critical infrastructure. Iranian-affiliated hackers have previously targeted Internet-connected industrial controllers used by water and wastewater facilities, and federal agencies issued warnings earlier in 2026 about attacks against exposed programmable logic controllers.
That history makes Iranian involvement one possibility, but similarity is not proof. Attackers can imitate another group’s methods, use misleading names or plant evidence intended to influence investigators.
Until the FBI, CISA or another responsible agency releases a formal assessment, claims about who conducted this attack should be treated as preliminary.
The attacks may extend beyond Minnesota
The Minnesota incidents may be part of a broader campaign rather than an isolated attack against one state.
By August 1, reports indicated that water systems in at least seven states had experienced related malicious activity. Michigan disclosed attacks affecting nine water systems, while federal investigators continued examining incidents elsewhere.
Reported actions included changing passwords, altering network configurations, interfering with automated equipment and forcing facilities to reset systems or move to manual operations. Some facilities reportedly experienced pressure problems or flooding, although authorities said the affected systems continued to provide safe water.
This broader activity suggests that attackers may be searching for similar Internet-exposed equipment across multiple utilities rather than individually selecting each town.
An attacker can scan the Internet for a particular controller, remote-access service or configuration weakness. Once vulnerable installations are found, the same technique can be repeated against many organizations in a short period.
Small utilities face a difficult security problem
Large cities may have dedicated cybersecurity departments, round-the-clock monitoring and substantial technology budgets. A small community water system may have only a handful of employees responsible for treatment, maintenance, testing, regulatory compliance and emergency response.
That difference matters because a small town’s water is no less essential than the water serving a major city.
Smaller utilities may depend heavily on equipment vendors and outside contractors. Remote access can be necessary because a specialist may be located hours away from the facility. Removing that access entirely may make maintenance and emergency support more difficult.
The goal is therefore not simply to disconnect everything without considering the operational consequences. Utilities need to identify which connections are truly necessary, protect them appropriately and have a tested method for isolating critical systems when an attack occurs.
Minnesota activates a statewide response
MNIT activated Minnesota’s cybersecurity incident-response capabilities after learning of the attacks.
The response involved state, federal, local, Tribal and private-sector organizations, including:
Responders shared threat intelligence and indicators of compromise, helped utilities investigate affected systems, assisted with containment and recovery, and monitored for related malicious activity.
Minnesota Chief Information Security Officer John Israel said the state’s response worked as intended, allowing organizations at multiple levels of government to coordinate quickly and help prevent more serious effects on essential services.
That coordination is important because a small utility may not have the personnel or equipment necessary to conduct a complex forensic investigation alone.
CISA advises utilities to prepare for isolation
The Minnesota attack occurred as CISA and international partners released guidance called CI Fortify: Advice for Isolating Vital Systems.
The guidance recommends that critical-infrastructure operators prepare in advance to separate vital operational systems from corporate networks, remote-access services, Internet-facing equipment and other less-trusted connections.
Organizations should identify the minimum equipment needed to continue providing their essential service. They should then document every connection to that equipment and determine where those connections can be disabled or physically disconnected during an emergency.
An effective isolation plan should answer several questions:
CISA recommends maintaining an offline or printed copy of the plan. An emergency document stored only on the compromised network may be inaccessible precisely when employees need it.
Isolation is more than unplugging a cable
Physical separation can be one of the strongest ways to protect vital equipment, but isolation can also introduce new risks.
Disconnected systems may no longer receive security updates or centralized monitoring. Employees may rely more heavily on USB drives and other removable media, potentially creating another route for malware. Remote facilities may lose communications, and outside technicians may no longer be able to troubleshoot equipment.
An isolation plan must therefore be designed and tested before an emergency.
CISA recommends testing the complete process rather than checking individual firewalls or switches separately. Hidden dependencies may not become apparent until an organization attempts to operate without its normal network, cloud services, telephone systems or vendor connections.
A plan that exists only on paper may fail when an actual attack begins.
What utilities should examine
Water and wastewater operators should determine whether industrial controllers, human-machine interfaces or remote-access services are reachable directly from the public Internet.
Basic protective measures include:
Utilities should also know what normal activity looks like. An organization cannot easily identify an unauthorized change if it does not maintain an inventory of its equipment, network connections, software versions and authorized users.
What residents should and should not conclude
The Minnesota attack does not mean that residents should assume their tap water is unsafe.
Public water systems routinely test water quality, and local authorities issue notices when residents need to boil water, limit consumption or take other precautions. No statewide drinking-water restriction resulted from the Minnesota attack.
Residents should rely on notices from their water utility, municipal government, public-health department or emergency-management agency rather than rumors circulating on social media.
It is still reasonable for households to maintain an emergency water supply. Cyberattacks are only one possible cause of a water outage; storms, earthquakes, broken pipes, power failures and equipment malfunctions can produce similar disruptions.
Emergency guidance commonly recommends storing at least one gallon of water per person per day for drinking and sanitation. Households should account for pets, medications and accessibility needs and should rotate stored water according to the container manufacturer’s instructions.
This was a warning, even without a disaster
The Minnesota water attack did not produce the catastrophic outcome people may imagine when they hear that hackers reached a treatment plant. Water continued flowing, operators activated backup procedures, affected equipment was restored and state and federal responders coordinated their work.
That is good news.
It is also evidence that attackers are actively seeking access to the machinery supporting basic public services.
Cybersecurity discussions often focus on stolen passwords, exposed Social Security numbers, ransomware payments and leaked corporate files. Operational-technology attacks introduce another dimension: a computer intrusion may change what a pump, valve, motor or treatment system does in the physical world.
The Minnesota incident should not be exaggerated into a claim that hackers poisoned the water. There is no confirmed evidence that they did.
It should also not be dismissed because the worst outcome did not occur.
More than 30 water systems were targeted in a coordinated campaign. At least one community temporarily lost computerized control of its well and treatment plant. Related attacks may have reached utilities across several states.
The defenses, contingency plans and human operators prevented a more serious emergency. The next step is making certain that every utility, including those serving small communities with limited resources, is prepared to do the same.
Sources for further reading
The following are sources for further reading. If you read this and you know people who may need this type of info, please share this blog post and the accompanying reading material.
Share this:
Like this:
Related
Discover more from Jared's Technology podcast network
Subscribe to get the latest posts sent to your email.
Published in article commentary