Key Takeaways
- More than 30 Minnesota community water utilities experienced a coordinated OT cyberattack on July 26‑27, though no service disruption or water‑quality impact has been confirmed.
- Minnesota IT Services (MNIT) activated its cybersecurity incident response immediately and is working with state, federal, and local partners to investigate and remediate the incident.
- Officials have not attributed the attack publicly, but security researchers at Tenable note similarities to the Iran‑linked group CyberAv3ngers, an Iran‑linked threat actor that targets small utilities using exposed PLCs and consumer remote‑access tools.
- CISA, together with allied cyber agencies, released new guidance (CI Fortify) urging owners to isolate essential OT systems and maintain robust recovery plans to keep services running under degraded conditions.
- The incident highlights a broader shortage of engineers skilled in both control‑systems and network security, a gap that threatens the long‑term resilience of critical infrastructure.
Attack Timeline and Scope
On July 26 and July 27, a coordinated cyber intrusion targeted the operational technology (OT) networks of over thirty community water utilities across Minnesota. The attackers focused on systems that monitor and control treatment, pumping, and distribution processes, attempting to gain unauthorized access to programmable logic controllers (PLCs) and supervisory control and data acquisition (SCADA) interfaces. While the exact number of compromised devices remains under investigation, the scale of the effort suggests a deliberate campaign aimed at multiple small‑to‑mid‑sized municipal water providers rather than an isolated incident.
MNIT’s Incident Response Activation
Minnesota IT Services (MNIT) confirmed the breach in a public statement released July 28 and immediately activated its cybersecurity incident response capabilities. The agency’s Security Operations Center (SOC) began collecting logs, isolating affected assets, and coordinating with utility IT and OT teams to contain the threat. MNIT’s response included deploying forensic analysts, issuing temporary network‑segmentation directives, and establishing a joint task force to share real‑time intelligence with the impacted utilities.
Interagency Collaboration and Investigation
Following the initial containment, MNIT has been working closely with a broad set of partners, including the Minnesota Department of Health, the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and local law‑emergency management offices. This collaborative effort aims to trace the attackers’ foothold, determine whether any data exfiltration occurred, and develop remediation steps tailored to each utility’s unique OT environment. The investigation remains active, with analysts continuously assessing which specific systems were compromised and evaluating the effectiveness of applied mitigations.
Leadership Emphasis on Whole‑of‑Government Approach
John Israel, MNIT Assistant Commissioner and Minnesota’s Chief Information Security Officer, stressed that defending critical infrastructure requires a unified, whole‑of‑government response. “MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks,” Israel said. His remarks underscore the state’s commitment to breaking down silos between IT, OT, public‑health, and emergency‑management sectors to present a coordinated front against sophisticated threats.
Impact Assessment and Public Health Safeguards
The Minnesota Department of Health is directly engaging with the impacted water systems to verify that drinking‑water safety and quality have not been compromised. To date, no municipality has issued a boil‑water notice or advised residents to alter their water usage, indicating that the attack has not yet disrupted service delivery or introduced contaminants. Health officials continue to monitor water‑quality parameters and stand ready to issue public guidance should any changes be detected.
Public Disclosures from Affected Municipalities
Four cities have publicly acknowledged their involvement in the incident: Braham, Plymouth, South St. Paul, and Maple Plain. The City of Maple Plain issued a statement noting that certain details remain withheld to avoid jeopardizing ongoing cybersecurity work or inadvertently aiding the attackers. Officials affirmed that, as of the statement’s release, there had been no interruption to water or wastewater service and no evidence that the safety or quality of the city’s drinking water had been affected. Similar reassurances were echoed by the other three municipalities, though they too cautioned that the situation is still under active review.
CISA’s Fortify Guidance on OT Isolation
On July 28, CISA, in partnership with Australia’s Signals Directorate, the UK’s National Cyber Security Centre, and Canada’s Centre for Cyber Security, published CI Fortify – Advice for Isolating Vital Systems. The guidance urges owners and operators of operational technology to isolate essential OT assets from corporate IT networks, thereby preserving critical functions even if a breach occurs. CISA recommends maintaining robust isolation and recovery plans, employing manual or alternative SCADA pathways, and regularly exercising these plans to ensure that essential services can continue under degraded conditions. The advisory specifically highlights the value of network segmentation, strict access controls, and validated backup configurations as foundational defenses against state‑sponsored threat actors.
Tenable’s Analysis Pointing to CyberAv3ngers
Although no official attribution has been made, security researchers at Tenable have identified technical and behavioral patterns consistent with the Iran‑linked threat group known as CyberAv3ngers. Tenable’s analysts observed that the attackers’ focus on small water utilities, the use of legacy remote‑access tools, and the timing of the intrusion align closely with prior campaigns attributed to this group. The researchers emphasized that the targeting appears structural rather than random, reflecting a deliberate strategy to exploit municipalities that lack dedicated OT security personnel and operate under tight budget constraints.
Tactics: Exposed PLCs and Consumer Remote‑Access Tools
According to Tenable, CyberAv3ngers frequently gains initial access by exploiting programmable logic controllers (PLCs) that are inadvertently exposed to the internet or managed through consumer‑grade remote‑access applications such as TeamViewer and AnyDesk. These tools, while convenient for maintenance, often lack the stringent authentication and logging controls required for critical‑infrastructure environments. Once inside, the attackers can manipulate PLC logic, alter set‑points, or disrupt communication between field devices and SCADA servers, potentially causing operational anomalies without immediately triggering traditional IT‑focused alerts.
Workforce Shortage in OT Security
Help Net Security highlighted a parallel challenge facing the OT sector: a dwindling pool of engineers who possess deep expertise in both control‑systems engineering and cybersecurity. Much of this specialized knowledge resides in an aging workforce that is retiring faster than utilities can recruit and train replacements. The shortage exacerbates vulnerabilities, as many small utilities struggle to implement comprehensive security architectures, conduct regular threat‑hunting, or maintain up‑to‑date patch management for legacy OT equipment.
Outlook and Recommendations for Strengthening OT Resilience
The Minnesota water‑utility incident serves as a stark reminder that even modest‑sized critical‑infrastructure assets are attractive targets for sophisticated, state‑aligned actors. To reduce risk, utilities should adopt the segmentation and isolation practices outlined in CISA’s Fortify guidance, invest in multi‑factor authentication for remote‑access tools, and conduct regular tabletop exercises that simulate OT‑focused cyber incidents. Simultaneously, state and federal programs must address the OT‑security workforce gap by funding apprenticeship programs, certifications, and knowledge‑transfer initiatives that attract the next generation of engineers equipped to defend both the cyber and physical layers of water‑system operations. Continued vigilance, information sharing, and investment in resilient architecture will be essential to safeguarding public health and maintaining confidence in essential services.