Minnesota Water System Cyber Incidents Trigger Statewide Security Response

Minnesota Water System Cyber Incidents Trigger Statewide Security Response

A coordinated cyberattack targeting operational technology affected more than 30 community water systems across Minnesota on July 26 and 27, prompting a statewide cybersecurity response involving multiple state and federal agencies. Several municipalities reported disruptions to water utility operations, although officials stated there were no active requests for residents to change their drinking water usage. Among the affected communities, Braham reported that its water treatment plant went offline and asked residents to reduce water consumption until treatment services resumed. Plymouth experienced cellular communication problems affecting two water towers and several wastewater lift stations, but officials continued operations through manual processes. South St. Paul and Maple Plain also confirmed that automated utility controls were impacted while maintaining water services. Maple Plain declared a local state of emergency to support its response efforts. Authorities have not publicly identified the threat actor, the products targeted, the vulnerability involved, or whether any data was stolen during the incidents.

Minnesota IT Services (MNIT) confirmed on July 28 that more than 30 water systems across the state had been impacted, although the severity of the disruption differed from one utility to another. According to the agency, investigators observed common characteristics across the attacks, including similar timing, methods of access, and the type of operational technology infrastructure targeted. These similarities led officials to classify the activity as a coordinated cyberattack. MNIT stated that the observed patterns were also consistent with activity previously reported by federal partners in other states and industries. However, investigators have not determined whether all of the attacks were carried out by a single threat actor. Officials added that similarities in the methods used to gain access had also been identified, but technical details have not been disclosed while the investigation remains active. Attribution has not yet been finalized as authorities continue to examine evidence collected from the affected systems.

The statewide response involves collaboration between MNIT, state agencies, Cybersecurity and Infrastructure Security Agency (CISA), Environmental Protection Agency, Federal Bureau of Investigation, and the impacted utilities. According to John Israel, Assistant Commissioner of MNIT and Minnesota Chief Information Security Officer, cyberattacks targeting critical infrastructure require a coordinated government response. Officials stated that rapid coordination helped contain the incidents and reduce the potential for more severe disruptions to essential public services. The attacks also occurred only days after United States agencies expanded an advisory regarding Iranian affiliated threat actors targeting internet facing programmable logic controllers manufactured by Rockwell Automation, Schneider Electric, Siemens, and potentially other vendors. In that separate campaign, investigators observed attackers extracting and modifying project files, manipulating information displayed through human machine interfaces and supervisory control and data acquisition systems, and disabling alarm and shutdown functions. Despite the timing, state and federal authorities have not publicly linked the Minnesota incidents to that campaign.

Security researchers have noted similarities between the Minnesota attacks and previously documented activity associated with CyberAv3ngers and other groups linked to Iran Islamic Revolutionary Guard Corps Cyber Electronic Command, although no official attribution has been announced. Scott Caveza, Senior Staff Research Engineer at Tenable, stated that the tactics observed remain consistent with techniques previously associated with those threat groups, which have targeted water and wastewater infrastructure since at least 2023. CISA has published defensive guidance for organizations operating critical infrastructure, recommending that operators log cellular modem connections, restrict controller access to authorized systems, inspect running project files for unauthorized changes, verify backup integrity before restoration, and confirm controller project files before returning systems to operational mode. As of July 29, 2026, MNIT confirmed that the investigation remained active, with response teams continuing to assess the affected water systems while supporting recovery efforts and sharing threat intelligence with partner agencies.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment