Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.”

​The attacks occurred on Sunday and Monday, July 26 and 27, and targeted operational technology (OT) systems at local water utilities.

In a statement early Monday, the City of Braham said that the water plant was “offline for an unknown reason.”

“Crews are actively troubleshooting the problem and will restore services as soon as possible,” the city said in a communication to its residents.

An update from the City of Braham about three hours later informed that the water plant was back online, filtering and treating water “as expected” and that residents could return to normal water use.

“Crews identified that the water plant outage was a result of a malicious cyber-attack of computerized operating systems by unknown actors,” city officials said.

According to local media, other communities reported temporary equipment malfunctions since Sunday and switched to manual operations or implemented contingency plans to maintain normal services [1, 2].

MNIT is working with federal, state, local, Tribal, and private-sector partners to investigate the incident and to fortify the security of Minnesota’s critical infrastructure.

“As MNIT cybersecurity teams assess the cyber impacts, they are sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack,” MNIT says.

The agency said it was not aware of any requests from Minnesota cities for residents to change their drinking water usage.

In guidance published yesterday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends critical infrastructure organizations isolate key OT systems to ensure continuity of critical services in the event of a cyberattack.

​Titled “CI Fortify – Advice for isolating vital systems,” the document was created by CISA, the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners.

Although the threat actor behind the Minnesota water systems cyberattacks remains unknown, the government agencies note that critical infrastructure is often targeted by state-sponsored hackers for espionage or in preparation for disruptive and destructive activities in case of crisis or conflict.

Earlier this year, the U.S. warned of Iranian hackers targeting programmable logic controllers (PLCs) in critical infrastructure organizations.

A joint advisory from multiple U.S. agencies in April said that cyber actors associated with Iran had been exploiting exposed Rockwell Automation/Allen-Bradley PLC devices since March.

The activity disrupted operations and caused financial losses across multiple sectors, including government services and facilities, water and wastewater systems, and the energy sector.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

CISA shares advice on isolating vital systems during cyberattacks

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Closing the Identity Gaps in Critical Infrastructure Security

Coca-Cola says Fairlife ransomware attack halts US dairy production

Japan’s largest taxi operator shuts systems after cyberattack

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Ernst & Young data breach claimed by ShinyHunters extortion gang

OpenAI models used Artifactory zero-days to escape to the internet

Your Scanners Are Green. Your Pipeline Might Not Be. Here’s How to Close the Gap.

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Overdue a password health-check? Audit your Active Directory for free

Uncover shadow AI apps, agents, and risky data sharing. Get started in 5 min.

Rev5 is ending. See what your FedRAMP 20x transition really requires

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.