More than 30 community water systems across Minnesota were caught in the same coordinated cyberattack over the weekend, exposing how one incident can disrupt critical infrastructure across multiple communities at once.
State and federal agencies are continuing to investigate who was behind the attacks and how they spread.
Several communities temporarily lost automated control of parts of their water systems, but service continued as utility crews switched to manual procedures. Officials say drinking water remained safe throughout the incident, and no changes to public water use have been requested.
The attacks also come as federal agencies continue warning that foreign threat groups are targeting industrial control systems used to operate essential services.
Why It Matters: Cyber incidents involving operational technology can interrupt essential operations even when physical infrastructure remains intact. As IT and OT become more connected, recovery planning is becoming just as important as prevention.
- A Statewide Incident: What first appeared to be isolated disruptions soon expanded into a statewide response. Minnesota officials said technology supporting more than 30 community water systems came under attack on July 26 and 27, prompting Minnesota IT Services to activate its incident response program. As more communities identified similar issues, state and federal officials joined local utilities to assess the damage and restore affected systems.
- Water Service Never Stopped: Several communities lost automated control of parts of their water systems, including Braham, South St. Paul, Maple Plain, and Plymouth. Utility crews switched to manual operations while technicians restored the affected systems, allowing water treatment and distribution to continue. Officials said drinking water remained safe throughout the response.
- The Attack Focused on Control Systems: The attacks were aimed at the systems used to operate water treatment facilities rather than the facilities themselves. In Braham, automated controls were disabled long enough for the treatment plant to go offline before operators restored service. Even without physical damage, the disruption affected day-to-day operations.
- Federal Warnings Came Days Earlier: The attacks followed an updated CISA advisory warning that Iranian-affiliated threat actors were targeting internet-facing programmable logic controllers. Authorities have not tied the Minnesota incident to any known group, but it arrived as federal agencies were already urging organizations to pay closer attention to industrial control systems.
- Recovery Took Time: Bringing automated controls back online was only part of the response. Utilities worked carefully through the affected systems before returning them to service, while state and federal agencies continued investigating the attacks and helping communities recover.
‘Coordinated cyberattack’ targets over 30 water systems in Minnesota – USA Today

