Key Takeaways
- More than 30 community water systems in Minnesota experienced a coordinated cyberattack on July 28, targeting operational technology.
- No ransomware was detected and water service remained uninterrupted thanks to manual backup procedures.
- Cities such as Plymouth, Maple Plain, South St. Paul, and Braham reported temporary equipment malfunctions that were quickly isolated and restored.
- Residents noted no noticeable disruption, but emphasized the vital importance of reliable water service for daily life.
- Water utilities are classified as critical infrastructure; Minnesota logged nine cyberattacks on such systems in all of 2023, yet this incident alone surpassed that total.
- Governor Tim Walz’s 2022 executive order mandated annual health‑department assessments, mandatory reporting, and response plans for critical infrastructure.
- State agencies, including MNIT, the Minnesota Bureau of Criminal Apprehension, and the FBI, are collaborating with local, tribal, and federal partners to investigate and strengthen defenses.
- Ongoing efforts focus on sharing intelligence, restoring affected utilities safely, and improving resilience against future cyber threats.
Overview of the Coordinated Cyberattack
On Sunday, July 27, and continuing into Monday, July 28, more than 30 community water systems across Minnesota were hit by a synchronized cyberattack aimed at their operational technology (OT) networks. Minnesota IT Services (MNIT) confirmed that the intrusions targeted the control systems that manage pumps, treatment processes, and distribution valves. Notably, investigators found no ransomware payload or evidence that attackers attempted to extort money; instead, the activity appeared designed to disrupt normal operations. Despite the breadth of the assault, state officials stressed that public water service continued without interruption, attributing this resilience to pre‑existing contingency plans and the ability to switch to manual operation when automated controls faltered.
Immediate Impact and Backup Responses
The affected utilities reported temporary malfunctions in supervisory control and data acquisition (SCADA) panels, sensors, and related hardware. In many cases, the anomalies triggered automatic alarms that prompted operators to initiate manual overrides. Plymouth’s public works director, Michael Thompson, explained that the city activated its backup plan to run critical facilities by hand, ensuring that water pressure, quality, and volume remained within regulatory limits. Similar actions were taken in other municipalities, where crews isolated compromised segments, restarted equipment manually, and monitored water quality through routine sampling. The swift transition to manual control prevented any loss of service or degradation of water safety, illustrating the value of redundancy in critical infrastructure design.
City‑Level Experiences
Plymouth was among the first to notice issues, with technology glitches appearing Sunday night. Officials there reported no discernible hiccup for residents and praised the effectiveness of their manual operation protocol. In Maple Plain and South St. Paul, utility staff described comparable patterns: intermittent SCADA failures that were contained within minutes to a few hours. Braham’s Mayor Nate George provided a concise account, stating that the town’s water system was offline for under two hours Monday morning after crews isolated the affected portion. He emphasized that water never ran out and that service resumed with minimal interruption once manual controls were engaged. Across these jurisdictions, the common theme was rapid detection, containment, and restoration without compromising public health or safety.
Resident Perspective on Service Continuity
Local residents echoed the officials’ confidence in the system’s resilience. Kiley Gay, a Plymouth mother, noted that she observed no change in water pressure, taste, or availability during the incident. She underscored how essential reliable water is for everyday activities such as drinking, cooking, and bathing, and acknowledged that any disruption would have had a significant impact on her family. Her testimony highlights the public’s reliance on uninterrupted water service and reinforces why maintaining operational continuity—even amid cyber threats—is a top priority for utilities and regulators alike.
Critical Infrastructure Context and Prior Trends
Water utilities are designated as critical infrastructure because their failure can jeopardize public health, safety, and economic stability. According to an annual report from MNIT, Minnesota recorded a total of nine cyberattacks on critical‑infrastructure entities throughout all of 2023. The July 2024 incident, affecting more than 30 water systems in a single coordinated wave, therefore eclipses the yearly total from the previous year by a wide margin. This surge underscores an evolving threat landscape where adversaries increasingly target OT environments, seeking to exploit the growing convergence of industrial controls with networked IT systems. The event serves as a stark reminder that even sectors traditionally viewed as low‑profile for cybercrime are now attractive targets.
State‑Level Policy and Preparedness Measures
In response to rising risks, Governor Tim Walz issued an executive order in 2022 that declared critical infrastructure to be facing increasingly sophisticated cyberattacks. The order mandated annual security assessments certified by the Minnesota Department of Health, required mandatory reporting of cyber incidents, and obligated utilities to develop and test response plans. These measures were intended to create a baseline of preparedness and to ensure that agencies could quickly share threat intelligence. The recent attack tested the effectiveness of those provisions; while the automated detection mechanisms succeeded in alerting operators, the scale of the incident highlighted the need for further refinement of monitoring tools and faster coordination across jurisdictions.
Investigation, Collaboration, and Next Steps
Following the discovery of the widespread assault, MNIT launched a coordinated response involving local governments, tribal authorities, and federal partners. The Minnesota Bureau of Criminal Apprehension and the FBI are actively participating in the investigation to identify the attackers, determine their motives, and ascertain whether any data was exfiltrated or manipulated. John Israel, MNIT assistant commissioner and the state’s chief information security officer, emphasized that “cyberattacks against critical infrastructure require a coordinated, whole‑of‑government response.” Efforts are now focused on sharing forensic findings, hardening OT networks against similar intrusion techniques, and updating incident‑response playbooks based on lessons learned.
Future Resilience and Defensive Strategies
Looking ahead, Minnesota officials intend to bolster the cybersecurity posture of its water utilities through several initiatives. These include expanding real‑time monitoring of OT environments, conducting regular red‑team exercises that simulate attacks on control systems, and investing in segmentation strategies that isolate critical control functions from broader corporate networks. Additionally, the state plans to provide grant funding and technical assistance to smaller communities that may lack dedicated cybersecurity staff, ensuring that all water systems—regardless of size—can implement basic defenses such as multi‑factor authentication, patch management, and employee awareness training. By integrating these measures with the existing statutory framework, Minnesota aims to reduce the likelihood of future successful attacks and to maintain uninterrupted, safe water service for its residents.

