Skip to content
Critical InfrastructureICSOT SecuritySCADACVE

Minnesota's water war: what 30 simultaneous OT attacks tell ICS defenders

3 min read
Share

Minnesota's water war: what 30 simultaneous OT attacks tell ICS defenders

On July 26 and 27, 2026, a coordinated cyberattack hit operational technology systems at more than 30 Minnesota community water utilities in under 48 hours. Braham's water treatment plant went fully offline, forcing the city to ask residents to minimize water use. Plymouth reported cellular communications failures at two water towers and multiple wastewater lift stations. South St. Paul and Maple Plain both had automated control disruptions. Maple Plain declared a local state of emergency. Minnesota's Chief Information Security Officer John Israel confirmed statewide MNIT engagement with the FBI and other federal partners.

No threat actor has been attributed. The attack vector targeted OT systems directly, not the IT side of the utilities, which is the detail that separates this incident from the more familiar pattern of ransomware hitting a utility's business systems and disrupting operations indirectly.

What the attack pattern tells us

Three things stand out. First, the coordination: more than 30 systems targeted within a 48-hour window implies a pre-positioned intrusion rather than opportunistic scanning. Attackers with pre-positioned access across multiple utilities can time their strikes to maximize pressure. Second, the OT targeting: reaching SCADA and control systems requires either a direct path from the internet to those systems, or lateral movement from a compromised IT environment. Either path represents a known and addressable gap. Third, the absence of attribution: water utility OT attacks have been claimed by hacktivists (Cyber Av3ngers in 2023), state actors, and opportunistic ransomware groups. Without attribution, defenders should plan for the worst-case scenario: a persistent, organized actor that may still have access.

The ICS exposure checklist that applies right now

After every major utility attack, the same gaps reappear. This is the short list of things to check today:

  • Audit every internet-facing HMI and SCADA interface. Tools like Shodan and Censys return results for your IP ranges in minutes. If your control system UI is reachable from the public internet, close it now.
  • Segment IT and OT networks. Flat networks between IT and OT environments turn a business-system compromise into a control-system compromise. Even basic firewall segmentation with strict allowlisting substantially raises the cost of lateral movement.
  • Apply patches to SCADA and historian software. Forescout's 2026 Riskiest Connected Devices Report found routers and switches in OT environments averaging 32 vulnerabilities per device. Patch cycles in OT are longer than in IT, but deferred patches accumulate into exploitable attack surfaces.
  • Review remote access credentials and VPN configurations for OT environments. Credential reuse between IT and OT accounts is a common initial access path.
  • Test your manual operation procedures. Braham ran on manual operations while the plant was offline. Knowing your manual fallback paths before an incident is not optional.

The bigger picture

Water utility OT attacks are not new. The 2021 Oldsmar incident where an attacker briefly changed lye levels in the water supply, the Aliquippa attack in 2023, and now Minnesota follow the same arc: underfunded utilities with internet-exposed control systems and limited dedicated OT security staffing. The policy response (EPA cybersecurity rules, CISA water sector guidance) has not yet translated into uniform baseline security across the sector.

For organizations with similar OT exposure, the actionable takeaway is not to wait for a sector-specific incident. This attack pattern, coordinated multi-target OT intrusions, is portable across any sector with internet-accessible control systems.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are assessing OT security posture or responding to a similar incident.

Related articles