READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Coordinated Cyberattack Hits 30-Plus Minnesota Water Systems, State Says No Threat to Drinking Water Yet

Coordinated Cyberattack Hits 30-Plus Minnesota Water Systems, State Says No Threat to Drinking Water Yet
A coordinated cyberattack struck the operational technology of more than 30 Minnesota community water systems on July 26 and 27. State officials say there's no indication residents need to change how they use their water, but they still won't say who did it or how.

More than 30 community water systems across Minnesota got hit by a coordinated cyberattack on the technology that actually runs their equipment, not just their websites. That happened July 26 and 27, according to Minnesota IT Services (MNIT), the state's central IT agency.

MNIT went public with it on July 28, activating its statewide cybersecurity incident response. That's the state's version of an all-hands-on-deck alert.

The target was operational technology, or OT. That's the industrial control equipment that actually opens valves, runs pumps, and manages treatment processes, not the office network. An attack on OT is a different animal than a typical data breach. It's an attack on physical infrastructure.

Right now, officials say there's no reason for residents to change how they use their drinking water. The Minnesota Department of Health told the public it has not received any requests from local communities to alter water use advisories, and the agency is working directly with the affected utilities to make sure public health protections stay in place.

What we don't know yet

MNIT has not disclosed who did this. No threat actor has been named. No attack vector, malware strain, or technical detail of the intrusion has been released.

That's a real gap, and it's fair for people to be uneasy about it. Water systems are exactly the kind of soft, dispersed target that state-linked hacking groups and criminal ransomware crews have both gone after in recent years, and not knowing which one this is matters for how seriously the public should take it.

But there's also a legitimate reason agencies sit on those details early in an investigation. Naming a threat actor prematurely can tip off the attacker that you know who they are, burn intelligence sources, and blow up an active FBI investigation before charges or attribution are locked down. CISA and the FBI have both operated that way in prior infrastructure incidents. Withholding technical specifics isn't automatically stonewalling. It can just be operational security.

Still, "we're investigating" isn't a substitute for eventual public accountability. Minnesota taxpayers and ratepayers deserve to know, once the investigation allows it, who attacked their water utilities and how the intrusion got in.

Who's actually working the case

This isn't just a state IT problem. The response roster includes the Minnesota Department of Public Safety, the Bureau of Criminal Apprehension's Minnesota Fusion Center, the Minnesota Department of Health, the Minnesota Pollution Control Agency, the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Environmental Protection Agency (EPA), the Federal Bureau of Investigation (FBI), and the local utilities themselves.

That's a genuinely broad federal-state-local coalition, which tells you Minnesota and federal officials are treating this as serious, not routine. MNIT Assistant Commissioner and state Chief Information Security Officer John Israel said cyberattacks against critical infrastructure require a whole-of-government response, and credited the state's cybersecurity investments and partnerships with letting agencies "rapidly coordinate their response, contain the incident, and reduce the risk of more severe disruptions to critical services."

The bigger pattern

Minnesota's water systems join a growing list of American utilities targeted by hackers going after industrial control systems rather than just data. CISA has warned for years that water and wastewater systems are chronically underfunded on cybersecurity relative to the risk, run by small municipal operators that often can't afford dedicated security staff.

MNIT runs the MNET network connecting all 87 Minnesota counties, roughly 300 cities, and 200 public higher education campuses. An attack that reaches across more than 30 separate water utilities in a 48-hour window suggests either a shared vulnerability across multiple systems or a single actor with the reach to hit many targets fast. MNIT hasn't said which.

The investigation is active. MNIT says it will keep sharing threat intelligence and providing technical assistance as recovery continues. What's still missing is the basic who, how, and why, and Minnesota residents relying on these utilities have every reason to expect those answers once the investigation permits disclosure.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
cyberinsiderOver 30 water systems in Minnesota hit by coordinated cyberattack - CyberInsider