A recent cyberattack against water utilities in Minnesota has revealed the extent of the weakness in many operational technology (OT) environments. Municipal water systems largely run on aging and outdated OT, often exposed to the internet. Small utilities also frequently lack the dedicated staff or sufficient budget for effective cybersecurity programs. This incident came on the heels of a joint advisory regarding Iranian interest in critical infrastructure programmable logic controllers (PLCs), issued by the United States Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA), and other government partners.
Exploring the Breach
The breach, affecting dozens of cities in Minnesota, was noticed and resolved relatively quickly. The water plant operator for the city of Braham, Minnesota discovered the water tower calling for water with the well offline. The water plant staff was able to trace the fault back to a compromised computerized control system rather than a mechanical failure.
With manual isolation of the affected areas and restoration from backups, the team managed to bring the plant back online within around 90 minutes. This pattern repeated in a similar manner across more than 30 communities, according to Minnesota IT Services (MNIT).
Piecing Together the Culprit
Officials have used the available information to attempt to attribute this incident to a threat actor. There were no ransom demands received, an anomaly that shifts analysts’ thinking toward state-linked motives. The coordinated attack also showed specific tradecraft and timing similarities across the different affected sites that point tentatively toward Iranian state-backed attackers.
However, this suspected attack origin is not final or certain: officials are careful to caution that it is preliminary, and likely attribution of the attack may shift as forensics and analysis continue to develop. Investigators have also raised the possibility that a non-state-affiliated actor could have deliberately mimicked common Iranian methods in order to stoke geopolitical tensions.
Activating the Response Machine
After the discovery of the attack, MNIT coordinated incident response with CISA, EPA, and FBI. In the wake of the event, CISA issued a new nationwide alert to warn critical infrastructure owners and operators about the observed increase in threat actors targeting PLCs and locking out operators.
In line with the far reach of CISA’s advisories and the suspected geopolitical motivations, this issue is not solely affecting Minnesota. CBS News cites the FBI reporting similar malicious activity against water systems technology in at least seven states. In all issued statements, state and city officials have confirmed that the attacks have not compromised the safety or supply of drinking water.
A Geopolitical Trip Wire
The broader geopolitical context of this incident is a large part of the suspected attribution, as this attack unfolded against a backdrop of active military and diplomatic conflict between the US and Iran. If the attribution to Iranian state-backed actors is able to be confirmed, this could sharpen the policy response from the US and further strain relations between the two nations. There is an existing precedent of similar activity launched by Iran-linked actors, such as the 2023 CyberAv3ngers attack on US systems and factories using Israeli-made water equipment.
Cyber operations against civilian infrastructure carry the risk of escalation that is distinct from traditional espionage efforts. “Under-resourced municipal utilities have become recurring targets for cyber adversaries because they provide an opportunity to disrupt essential services and expose systemic weaknesses,” says Matt Hartman, Chief Strategy Officer at Merlin Group. “Every disruption like this chips away at public trust, which is exactly why operational resiliency has to reach the communities that need it most.”
The Reckoning Ahead
This incident underscores the urgent need for investment in OT-specific cybersecurity efforts at the municipal level. The uncertainty of the attribution complicates both public messaging surrounding the incident and the policy response. In the aftermath of this attack, the sector faces a choice between reactive patching and structural investment in resilient systems. The case is likely to become a reference point in future debates about the regulation of cybersecurity in the water sector.