Key Takeaways
- A coordinated cyber‑attack last week disrupted water‑system controls in more than 30 Minnesota municipalities, prompting a ripple of alerts across at least seven states.
- The intrusion targeted internet‑connected equipment such as pumps, sensors, and SCADA (Supervisory Control and Data Acquisition) units that regulate water quality, treatment, and pressure.
- No drinking‑water supplies were altered or rendered unsafe, but the incident highlighted vulnerabilities in aging infrastructure and the growing sophistication of threat actors.
- New Hampshire’s Department of Environmental Services (DES) has issued advisories and is collaborating with federal agencies, including CISA, to audit and strengthen utility defenses.
- Industry leaders, such as Pennichuck Water’s John Boisvert, stress the importance of protecting internet‑facing devices, updating firewalls, and conducting regular penetration testing.
- Ongoing efforts focus on employee training, incident‑response planning, and adopting a “defense‑in‑depth” strategy that layers technical, procedural, and human safeguards.
- Federal grant programs and state‑level funding are being pursued to help smaller utilities afford necessary cybersecurity upgrades.
- Experts warn that attacks on water systems could escalate, potentially threatening public health if contaminants are introduced or service is disrupted.
- Continuous monitoring, threat‑intelligence sharing, and regular tabletop exercises are recommended to keep utilities ahead of evolving cyber threats.
- Residents are encouraged to stay informed through utility communications and to report any unusual water‑quality observations promptly.
Background of the Minnesota Cyber‑Incident
Last week, a coordinated cyber‑attack struck more than 30 municipalities across Minnesota, targeting the supervisory control and data acquisition (SCADA) systems that manage water treatment plants, distribution pumps, and pressure sensors. The attackers gained unauthorized access to internet‑connected devices, manipulating operational parameters in an attempt to disrupt service. While the breach did not result in contaminated water or a loss of pressure, it demonstrated how threat actors could exploit relatively simple vulnerabilities—such as outdated firmware or weak passwords—to gain a foothold in critical infrastructure. Federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency (EPA), issued immediate alerts urging water utilities nationwide to review their remote‑access configurations and patch known vulnerabilities.
Immediate Impacts and National Ripple Effect
In the days following the Minnesota incident, at least seven states reported similar probing attempts or low‑level intrusions against their water utilities. Although none of these attempts succeeded in altering water quality or causing service outages, the pattern indicated a coordinated campaign rather than isolated events. The New York Times reported that the attackers appeared to be testing the resilience of water‑system defenses, possibly gathering intelligence for future, more disruptive operations. Public‑health officials emphasized that, as of now, no drinking water has been deemed unsafe, but they urged utilities to treat the activity as a warning sign and to bolster their cyber posture before any actual harm could occur.
New Hampshire’s Response Through DES
The New Hampshire Department of Environmental Services (DES) acted swiftly, issuing statewide advisories that outlined specific steps utilities should take to detect and mitigate potential intrusions. DES spokesperson Jim Martin explained that the agency is working closely with federal partners, local governments, and utility operators to disseminate threat‑intelligence, conduct vulnerability assessments, and recommend concrete defensive measures. DES has also facilitated webinars and tabletop exercises aimed at improving incident‑response coordination among the state’s roughly 200 public water systems, ranging from large municipal utilities to small rural districts.
Federal Collaboration and CISA Involvement
A cornerstone of New Hampshire’s strategy is its partnership with the Cybersecurity and Infrastructure Security Agency (CISA). CISA personnel have been conducting on‑site audits of select utilities, reviewing firewall configurations, intrusion‑detection systems, and access‑control policies. In addition, CISA is providing tailored guidance on securing remote‑access points—such as virtual private networks (VPNs) and mobile‑device management tools—that are often exploited by adversaries seeking to pivot into operational technology (OT) networks. The joint DES‑CISA effort includes sharing indicators of compromise (IOCs) and offering free scanning services to help utilities identify exposed services on the internet.
Industry Perspective: Pennichuck Water’s Approach
John Boisvert, who oversees Pennichuck Water—the state’s largest investor‑owned utility—highlighted the specific risks posed by internet‑enabled equipment like pumps and pressure regulators. He noted that if these devices are left unprotected, attackers could manipulate flow rates, trigger false alarms, or even shut down treatment processes. Boisvert credited DES and CISA for helping his organization audit existing security protocols, upgrade firewalls, and implement multi‑factor authentication (MFA) for remote administrators. He also stressed the importance of regular penetration testing and staff training to recognize phishing attempts that often serve as the initial entry point for cyber intrusions.
Technical Defenses Being Strengthened
Across New Hampshire, utilities are adopting a layered‑defense approach, commonly referred to as “defense‑in‑depth.” This includes:
- Network Segmentation – isolating OT networks from corporate IT networks to limit lateral movement.
- Patch Management – establishing strict schedules for applying firmware and software updates to pumps, sensors, and SCADA servers.
- Endpoint Hardening – disabling unnecessary services, changing default credentials, and employing application whitelisting on control‑system devices.
- Intrusion Detection & Prevention – deploying OT‑specific IDS/IPS solutions that can recognize anomalous command patterns indicative of manipulation attempts.
- Continuous Monitoring – leveraging security information and event management (SIEM) platforms to aggregate logs from firewalls, VPNs, and control systems for real‑time alerting.
These measures aim to reduce the attack surface while ensuring that legitimate operational activities remain uninterrupted.
Human Factors and Workforce Readiness
Technology alone cannot guarantee security; human vigilance is equally critical. Utilities are therefore investing in regular cybersecurity awareness training that covers phishing recognition, safe password practices, and proper incident‑reporting procedures. Many organizations are conducting quarterly tabletop simulations that mimic cyber‑attack scenarios, allowing operators to practice decision‑making under pressure and to refine communication protocols with state and federal agencies. By fostering a culture of security awareness, New Hampshire aims to ensure that every employee—from field technicians to senior managers—understands their role in protecting the water supply.
Funding and Support for Smaller Utilities
Smaller, rural water systems often lack the financial resources to implement advanced cybersecurity tools. Recognizing this disparity, New Hampshire is pursuing state‑level grant programs and leveraging federal infrastructure‑security funding to subsidize upgrades for these utilities. Initiatives include providing discounted firewall appliances, offering free vulnerability‑scanning services, and sponsoring shared‑services models where multiple small systems pool resources to afford a dedicated cybersecurity analyst. Such collaborative approaches help bridge the gap between large, well‑funded utilities and their smaller counterparts, strengthening the state’s overall resilience.
Looking Ahead: Evolving Threats and Preparedness
Experts warn that the recent attacks may be a precursor to more sophisticated operations aimed at causing physical harm or public‑health crises. Potential future scenarios include the introduction of contaminants through tampered chemical‑dosing pumps, the disruption of pressure regulation leading to pipe bursts, or the ransomware‑style encryption of SCADA databases that could halt service until a ransom is paid. To stay ahead, New Hampshire utilities are encouraged to:
- Participate in information‑sharing hubs such as the Water Information Sharing and Analysis Center (WaterISAC).
- Adopt the National Institute of Standards and Technology (NIST) Cybersecurity Framework tailored for critical infrastructure.
- Conduct annual risk assessments that incorporate both cyber and physical security considerations.
- Maintain up‑to‑date incident‑response plans that delineate clear roles, communication chains, and recovery procedures.
By integrating these practices, the state aims to transform its water sector from a reactive posture to a proactive, resilient defense capable of withstanding emerging cyber threats.
Conclusion
The Minnesota cyber‑attack served as a stark reminder that water utilities are attractive targets for adversaries seeking to disrupt essential services. New Hampshire’s swift response—through DES advisories, federal collaboration, utility‑led hardening efforts, workforce training, and targeted funding—demonstrates a comprehensive strategy to safeguard the state’s drinking‑water infrastructure. While no harm has come to consumers thus far, ongoing vigilance, investment, and cooperation will be essential to ensure that the Granite State’s water supply remains safe, reliable, and resilient in the face of an evolving cyber threat landscape.

