Skip to content
Rush Commerce
Software & Dev3 min read

30+ Minnesota water utilities hit in coordinated OT attack

More than 30 Minnesota water utilities were hit in a coordinated OT attack on July 26-27. What internet-reachable controllers mean for your business.

Somebody spent a weekend turning off water plants. On July 26 and 27, operational technology at more than 30 Minnesota community water utilities was hit in a coordinated attack, and Minnesota IT Services activated a statewide incident response alongside the FBI, CISA, EPA, and state health agencies. Nobody has been charged, nobody has been formally blamed, and the drinking water was fine. The interesting part isn't the attribution. It's that the Minnesota water utilities attack didn't require a zero-day — it required equipment that answers the internet.

What actually happened

Four cities have gone public. Per SecurityWeek, Braham lost operating controls for its well and treatment plant and went temporarily offline. Plymouth reported problems with equipment connected over cellular modems — water towers, lift stations, pump stations phoning home to SCADA. South St. Paul and Maple Plain kept service running after automated controls were disrupted. Every one of them fell back to running the plant by hand.

Context matters here. CISA, the FBI, NSA, EPA and Cyber Command issued advisory AA26-097A in April about Iranian-affiliated actors exploiting internet-exposed programmable logic controllers, and updated it on July 22 — four days before Minnesota — to add Siemens and Schneider Electric devices alongside Rockwell, plus project-file exfiltration. No agency has attributed the Minnesota incidents to anyone, and officials have been careful to say so.

The mechanism is dull, which is the point. Help Net Security reports that Tenable's researchers see small utilities exposed through consumer remote-access tools — TeamViewer, AnyDesk — or PLC interfaces sitting directly on the public internet. CISA's guidance is equally unglamorous: keep isolation and recovery plans good enough that essential service continues manually or over an alternate SCADA path.

Why the Minnesota water utilities attack matters for your business

You don't run a water plant. You do run a building. Somewhere on your network there's a camera NVR, an HVAC controller, a door access panel, a fridge temperature sensor, a scale, a label printer — each installed by a vendor who wanted remote support and left a cellular modem or an AnyDesk session behind. Nobody wrote it down. It doesn't show up in your MSP's asset list because your MSP didn't install it.

Two questions, this week. First: what did a vendor put on our network, and how do they reach it? Walk the building; the answer isn't in a spreadsheet. Second, and this is the one Braham got right: if the automation stops, can we still operate? Every affected utility ran manually and kept the water on. That's not luck — that's a runbook and people who've rehearsed it.

Key takeaways

  • 30+ Minnesota community water systems were hit in a coordinated OT attack on July 26-27; MNIT ran a statewide response with FBI, CISA and EPA
  • Braham's well and treatment plant went offline; Plymouth lost cellular-connected tower and lift-station comms; all affected cities fell back to manual operation
  • No formal attribution — but CISA updated advisory AA26-097A on July 22 on Iranian-affiliated exploitation of internet-exposed PLCs
  • The exposure pattern is consumer remote-access tools and controllers reachable from the internet, not novel exploits
  • Inventory what your vendors connected, then prove you can run the business with the automation switched off

Automation you can't run without is a single point of failure. We map every device and remote-access path a vendor left on your network, then write the manual-fallback runbook your team can actually execute at 2am. See how we build it.

Sources: Minnesota IT Services, SecurityWeek, Help Net Security, Tenable.

  • #ot-security
  • #plc
  • #cisa
  • #remote-access
  • #critical-infrastructure
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.