A coordinated cyberattack struck operational technology systems at more than 30 community water utilities across Minnesota on July 26 and 27, 2024. Minnesota IT Services (MNIT) confirmed the incident in a statement released July 28, noting that the attack specifically targeted OT systems used to manage water infrastructure operations.
MNIT activated its cybersecurity incident response capabilities immediately after learning of the intrusion. The agency stated it is working with a broad set of partners to contain the threat and assess the full scope of the compromise. The coordinated nature of the attack, hitting multiple facilities simultaneously, suggests a deliberate campaign rather than opportunistic targeting.
Operational technology systems in water utilities control critical functions including water treatment, distribution, and monitoring. Successful compromise of these systems could potentially affect water quality, pressure, or availability for affected communities. The statement did not specify whether any water services were disrupted or if the attackers gained control of physical processes.
The incident highlights ongoing vulnerabilities in critical infrastructure, particularly in smaller municipal utilities that may lack dedicated cybersecurity resources. Water systems have become increasingly attractive targets for both cybercriminals and nation-state actors, with several high-profile attacks on water facilities reported in recent years across the United States.
Water utilities affected by the attack should immediately review their OT security posture, segment networks to isolate critical systems, and implement enhanced monitoring for suspicious activity. Organizations should verify that all remote access to OT systems requires multi-factor authentication and that default credentials have been changed. MNIT has not released information about indicators of compromise or specific vulnerabilities exploited, but utilities should assume similar tactics may be used against other facilities and take preventive measures accordingly.
Source: https://www.helpnetsecurity.com/2026/07/30/minnesota-water-utilities-coordinated-cyberattack/



Targeting small utility infrastructure reveals a shift toward attacking the distributed edges of our critical systems. These operators face the same pressures as national grids but without the dedicated resources to defend against sophisticated actors. We see this tension play out as local providers struggle to maintain visibility into their own networks. My recent analysis shows how European regulatory frameworks provide a blueprint for these smaller entities to share security intelligence and standardize their defenses. By adopting these structural requirements, we create a collective defense that protects individual communities through shared technical standards rather than relying on isolated efforts. This transition toward collaborative oversight is the logical next step for securing our essential services.
https://cyrilsimonnet.substack.com/p/europe-already-wrote-the-rule-minnesota