- by foxnews
- 31 Aug 2026
A coordinated cyberattack targeted operational technology at more than 30 community water systems on Sunday, July 26, and Monday, July 27. Minnesota IT Services, known as MNIT, activated the state's cybersecurity response and brought in federal agencies to help investigate.
One water plant temporarily went offline. Meanwhile, other communities reported problems involving automated controls or communications equipment. Workers switched to manual operations or used backup procedures to keep essential services running. Fortunately, state officials reported no active requests for residents to reduce or change their drinking water use.
"Some of that activity degraded water operations," the bureau said.
CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist
Our free CyberGuy Live class, "Sick of Spam?," has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You'll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.
Get the free replay and checklist now at CyberGuyLive.com.
The attack targeted operational technology, commonly called OT. These systems control physical equipment such as pumps, valves and treatment machinery. In Braham, city officials initially reported that the water plant had gone offline for an unknown reason. Crews restored the facility within hours and said it was again filtering and treating water as expected.
Officials later blamed the outage on a malicious cyberattack against computerized operating systems. The city relied on water already stored in its tower while crews worked on the problem. Plymouth reported communications problems involving two water towers and several wastewater lift stations. However, officials said water levels and water quality remained unaffected.
South St. Paul also identified a cybersecurity incident involving automated water utility controls. Public Works employees used established contingency procedures to maintain normal water and wastewater operations. Maple Plain publicly confirmed that its water utility technology had also been targeted.
In total, four communities have publicly described specific effects, although MNIT says attackers targeted more than 30 systems statewide. That difference is important. Being targeted does not mean every system suffered a shutdown. However, it shows that someone tried to reach a large number of local utilities within a short period.
Smaller communities often face the greatest challenge. The Government Accountability Office says water systems have widely different cybersecurity capabilities. Many also use older technology that can be difficult to update. At the same time, utilities must stretch limited budgets across essential repairs and regulatory requirements. Cybersecurity upgrades may compete with work that residents can see, such as replacing aging equipment.
A large utility may employ dedicated security professionals. A small town may rely on plant operators who already handle daily operations and after-hours problems. As a result, the communities with fewer resources may also have less ability to monitor suspicious activity around the clock.
A cyberattack against a water utility does not automatically mean the water has been contaminated. In Minnesota, officials reported no known impact on drinking water quality. They also told residents in publicly identified communities that normal water use could continue.
However, a successful attack can cause more serious consequences. The EPA warns that hackers could disrupt treatment or damage equipment. In a worst-case situation, attackers might also interfere with processes that protect water quality.
Manual operations can provide an important safety net. Minnesota workers used those procedures to keep systems running while investigators examined affected technology. Still, a manual backup only helps when employees know how to use it. Utilities need to test those procedures before screens go dark and alarms stop reporting correctly.
CISA published new international guidance on July 28 called "CI Fortify: Advice for Isolating Vital Systems." The guidance urges critical infrastructure operators to separate vital operational technology from less trusted networks. That isolation can help an essential service continue operating when another part of the organization becomes compromised.
Another EPA finding needs careful context. The agency says more than 70% of inspected systems violated basic federal risk assessment or emergency response planning requirements. That figure does not mean 70% had confirmed cybersecurity breaches. However, inspectors found serious digital security weaknesses at some of those facilities.
Residents cannot secure a municipal treatment plant themselves. However, a few steps can help you receive reliable information and avoid scams during an incident.
Check your city, county health department or water utility website for updates. Officials will tell you whether you need to reduce water use or boil tap water. Avoid making decisions based on an unverified neighborhood post.
A cyberattack may affect communications or automated equipment without changing water quality. Continue normal use unless local officials provide different instructions. However, follow any boil-water notice immediately if one appears.
A backup supply can help during any water interruption, whether it begins with a cyberattack or equipment failure. The CDC recommends storing at least one gallon of water per person each day for three days. Households may need more for pets or people with medical needs.
Minnesota contained a troubling attack without a known drinking water emergency. Workers restored Braham's plant while other utilities relied on manual controls or contingency procedures. However, the number of systems targeted should get the attention of every governor and mayor in America. Hackers apparently found a way to reach dozens of local utilities during the same two-day period. The preliminary suspicion involving Iranian hackers also raises the stakes. Still, investigators need more evidence before anyone treats that attribution as settled. Every community should know which water controls face the internet and whether workers can operate essential equipment manually. States should also help smaller towns that cannot afford their own cybersecurity teams.
How confident are you that your community could handle a cyberattack on its water system, and what would you want local officials to tell you first? Let us know by writing to us at CyberGuy.com.
Sign up for my FREE CyberGuy Report
Copyright 2026 CyberGuy.com. All rights reserved.
Pensacola Beach residents say large vacation rentals sleeping 30-40 guests drive noise, parking and trash problems as officials weigh a strict new registry.
read more