Aerial view of circular tanks and treatment basins at a water and wastewater facility.

Cyberattack Hits 30+ Minnesota Water Systems

Attackers disrupted automated controls at utilities across the state. Investigators have not named the culprit as recent federal warnings focus on internet-exposed industrial equipment.

More than 30 Minnesota water systems were targeted in a coordinated cyberattack Sunday and Monday, disrupting automated controls and briefly knocking one city’s water treatment plant offline.

Minnesota IT Services said the attacks targeted technology used by community water systems July 26 and 27. Four communities — Braham, Plymouth, South St. Paul and Maple Plain — have publicly disclosed incidents. Drinking water remained safe, and officials have issued no boil-water advisories.

In Braham, attackers disabled computerized operating controls, shutting down the city’s well and water treatment plant. Public works crews restored the plant in about two hours. Plymouth disconnected cellular-connected equipment at two water towers and several wastewater lift stations while crews reconfigured the equipment and continued operations manually, according to Tenable’s Research Special Operations team.

The attacks hit operational technology, or OT – the computers and electronic controllers that operate physical equipment. In a water system, those systems can control pumps, valves, water towers, treatment equipment and wastewater operations. Breaking into an office computer can expose data. Breaking into OT can interfere with equipment that moves or treats water.

Remote access opens a door

Utilities have legitimate reasons to connect those systems remotely.

The Government Accountability Office told Congress May 21 that internet-connected technology lets utilities control pumps and other infrastructure across large, geographically dispersed systems. Those connections also increase the ability of attackers on the internet to reach critical operational systems.

GAO said nearly 170,000 drinking water and wastewater systems operate nationwide. Their security capabilities vary widely. Aging technology, workforce shortages and limited budgets make upgrades difficult, while spending required to deliver safe water can compete with cybersecurity investments.

EPA said in a February report that its Office of Water identified cybersecurity vulnerabilities at 277 water systems during 2025 and helped address 350 individual weaknesses. Problems included technology controlling drinking water and wastewater processes. EPA urged utilities to reduce OT exposure to the public internet and strengthen authentication and access controls.

Attackers don’t always need fancy exploits

Research released in March by Claroty’s Team82 found attackers frequently reached industrial systems through exposed remote-access services rather than sophisticated malware.

Team82 examined more than 200 verified attacks against cyber-physical systems during 2025. It found 82% involved attackers using VNC, a remote desktop protocol, to reach internet-exposed systems. Sixty-six percent involved compromise of HMI or SCADA systems — the software and screens operators use to monitor and control industrial processes.

Water and wastewater, manufacturing and power generation accounted for more than 45% of the attacks Team82 examined. Claroty CTO and Team82 head Amir Preminger said attackers were using “relatively low-tech means” against sectors where disruption could have dangerous consequences.

Preminger made the comment March 18 as Claroty released the results of its yearlong analysis; it was not a comment on the Minnesota attacks.

Iran warning came days earlier

The Minnesota attacks began four days after federal agencies expanded a warning about Iranian-affiliated hackers targeting internet-facing programmable logic controllers, or PLCs.

PLCs are rugged industrial computers that tell physical equipment what to do, for example, start a pump, open a valve or shut machinery down when operating conditions become unsafe.

The federal advisory, originally issued April 7 and updated July 22, said Iran-affiliated attackers had disrupted PLCs across U.S. water, energy and government facilities since at least March. The update broadened the known targeting from Rockwell Automation equipment to Schneider Electric and Siemens devices.

Investigators also found attackers retrieving PLC project files and, at one victim, modifying code responsible for alarms and safe operating parameters, according to the advisory.

The activity is serious because attackers do not need to destroy a controller to create risk. Changing the instructions a PLC follows, or changing what operators see on their control screens, can interfere with the physical process the computer controls.

Recent Iran-linked operations have already raised concerns about attackers moving beyond conventional IT systems toward infrastructure where disruption carries physical consequences.

Joe Slowik, director of threat research and cyber engineering at Dataminr, warned that manipulation of safety controls could allow attacks to move from digital disruption toward physical consequences.

“Critical systems and assets, such as PLCs, should never, under any circumstances, be directly accessible to the open internet,” Slowik wrote in a company blog post in response to CISA’s July 22 Iran advisory. His post was not an analysis of the Minnesota incident.

Slowik also warned that the expanded Iranian activity now includes process manipulation and degradation of safety mechanisms, opening the door to “various physical impact scenarios.” His analysis said loss of integrity in OT systems can cause equipment damage and, in extreme cases, endanger people.

There is no public evidence linking those Iranian actors to the Minnesota attacks.

Federal and state investigators have not attributed the incidents. Tenable said the timing and operational pattern resemble recent Iran-linked activity but stopped short of attribution.

Similar targets, technology and timing give investigators something to examine. They do not identify the attacker.

Secure the connection, not just the controller

The problem is also not solved by cutting utilities off from remote access.

NIST in June finalized security guidance specifically for remote access to water and wastewater OT. The agency said utilities increasingly depend on connectivity to monitor pumping stations, water quality and other distributed operations, but that internet-connected systems increase opportunities for attack.

NIST’s guidance lays out architectures designed to let operators reach remote systems without leaving sensitive equipment directly exposed to the internet.

For Minnesota officials, they are still trying to figure out how the attackers got in, whether the affected systems shared technology or configurations, and who was behind the coordinated attack.

Photo by Ivan Bandura on Unsplash

Total
0
Shares
Previous Article
LogoKit Phishing and Victim-Specific Login Pages

LogoKit Builds Phishing Pages Around Each Victim

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading