Cyberattacks targeting the water utilities of Braham, South St. Paul, Plymouth, Maple Plain and St. Cloud, Minnesota disrupted automated control systems at multiple facilities, prompting operators to switch to manual operations.
In Braham, the attack temporarily shut down the city’s water treatment plant, but crews restored service in less than two hours, and officials said water quality, public safety and infrastructure were not affected.
Minnesota IT Services (MNIT) confirmed it is assisting the affected communities with incident response, forensic analysis, and recovery efforts. Officials said the attacks primarily targeted industrial control systems used to monitor and operate water infrastructure, and investigations into the incidents remain ongoing.
Denis Calderone, CTO, Suzu Labs:
“The reporting is early on these attacks and there is no way to definitively attribute who the threat actor is, but it’s awfully coincidental that attacks against water utility control systems in five Minnesota cities are coming this soon after CISA released advisory AA26-097A warning about exactly these kinds of targets. That advisory, updated just last week with expanded scope covering Siemens and Schneider PLCs alongside Rockwell, specifically names water and wastewater systems as a targeted sector. We can’t draw a line between the two yet, but it fits the pattern we’ve been tracking since April.
“The good news here is that every one of these cities was able to fall back to manual operations and maintain service. The fact that trained crews could step in and run these systems manually while the automated controls were compromised is what kept this from becoming a major public safety incident.
“With the little that is known about these attacks, we did find it particularly interesting that Plymouth city officials noted that the impact was limited to equipment connected via cellular communications. Water towers, lift stations, pump stations, these remote assets often connect back to the SCADA system over cellular modems, and in our experience secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis, so it’s not too surprising then that the vector of attack may have been via these cellular connections. Oftentimes, regarding SCADA and Industrial Control networks, the infrastructure is largely built out by the integrator which increases the chance that these connections get overlooked. We saw in the reporting that Braham’s city administrator is now asking for their system vulnerability study to be reevaluated, and I wouldn’t be surprised if that study never included those cellular communication paths in the first place.
“The prescriptive advice here is the same as it’s been all year: take control systems off the internet, segment OT networks from IT, change default credentials on every device in the environment, and put remote access behind a VPN. But the lesson from Minnesota is that you have to know all the links. Every communication path into your control environment needs to be inventoried and tested, including the cellular modems, the radio links, the backup communication channels that don’t show up on the network diagram because the diagrams just don’t go into that level of depth, or because some components are simply forgotten about because they were installed five years ago by a contractor who’s long gone. If you don’t know every way into your control systems, you can’t protect them.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“The encouraging news is that operators appear to have maintained safe water service through a mix of manual operations and resilient system design. If those facts hold, this demonstrates an important principle: cyber resilience isn’t about preventing every intrusion, it’s about ensuring cyber incidents don’t become public safety incidents. As cyber attacks increasingly target operational technology, organizations need the operational ability to find exposed systems, fix the highest-risk vulnerabilities, detect compromise when prevention fails, and contain attacks before they disrupt essential services.”
John Strand, Owner, Black Hills Information Security, Inc.:
“We’re seeing more breaches targeting public and critical infrastructure, and I think one of the biggest things people are missing is the difference between financially motivated attackers and nation-state adversaries. When a criminal group compromises a network, they’re often looking for a quick payday through ransomware or data theft. Nation-state operators frequently have a very different objective.
“Their goal is often to gain access and stay there. They want to establish persistence, quietly understand the environment, and position themselves so they can disrupt critical infrastructure whenever it serves their strategic interests. Water treatment facilities, power generation, transportation, and other essential services are attractive targets because they provide leverage long before an attack is ever launched.
“The challenge is that many security programs are still built to detect noisy attacks like ransomware or smash and grab intrusions. They’re much less effective at finding the low and slow activity that characterizes many nation-state operations. If organizations responsible for critical infrastructure aren’t investing in threat hunting, network telemetry, and behavioral analysis designed to uncover long-term persistence, there’s a real risk that sophisticated adversaries will remain inside those environments long before anyone realizes they’re there.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Five separate water utilities hit across Minnesota tells you this was coordinated targeting of a sector, not opportunistic scanning that happened to find a few open doors. The reassuring headline is that crews switched to manual and restored service fast, but manual fallback is a contingency, and contingencies have limits that vary by facility, by staffing, and by how long the disruption runs. What investigators need to establish is how the same attack pattern reached systems in Braham, South St. Paul, Plymouth, Maple Plain, and St. Cloud, because whatever that common thread is, it almost certainly exists in water infrastructure well beyond Minnesota.”
You’re a target. So you have to behave that way. Beef up your defences so that you don’t end up like these organizations. Otherwise you will end up like these organizations.
Related
This entry was posted on July 28, 2026 at 3:39 pm and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Cyberattacks target five Minnesota water utilities
Cyberattacks targeting the water utilities of Braham, South St. Paul, Plymouth, Maple Plain and St. Cloud, Minnesota disrupted automated control systems at multiple facilities, prompting operators to switch to manual operations.
In Braham, the attack temporarily shut down the city’s water treatment plant, but crews restored service in less than two hours, and officials said water quality, public safety and infrastructure were not affected.
Minnesota IT Services (MNIT) confirmed it is assisting the affected communities with incident response, forensic analysis, and recovery efforts. Officials said the attacks primarily targeted industrial control systems used to monitor and operate water infrastructure, and investigations into the incidents remain ongoing.
Denis Calderone, CTO, Suzu Labs:
“The reporting is early on these attacks and there is no way to definitively attribute who the threat actor is, but it’s awfully coincidental that attacks against water utility control systems in five Minnesota cities are coming this soon after CISA released advisory AA26-097A warning about exactly these kinds of targets. That advisory, updated just last week with expanded scope covering Siemens and Schneider PLCs alongside Rockwell, specifically names water and wastewater systems as a targeted sector. We can’t draw a line between the two yet, but it fits the pattern we’ve been tracking since April.
“The good news here is that every one of these cities was able to fall back to manual operations and maintain service. The fact that trained crews could step in and run these systems manually while the automated controls were compromised is what kept this from becoming a major public safety incident.
“With the little that is known about these attacks, we did find it particularly interesting that Plymouth city officials noted that the impact was limited to equipment connected via cellular communications. Water towers, lift stations, pump stations, these remote assets often connect back to the SCADA system over cellular modems, and in our experience secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis, so it’s not too surprising then that the vector of attack may have been via these cellular connections. Oftentimes, regarding SCADA and Industrial Control networks, the infrastructure is largely built out by the integrator which increases the chance that these connections get overlooked. We saw in the reporting that Braham’s city administrator is now asking for their system vulnerability study to be reevaluated, and I wouldn’t be surprised if that study never included those cellular communication paths in the first place.
“The prescriptive advice here is the same as it’s been all year: take control systems off the internet, segment OT networks from IT, change default credentials on every device in the environment, and put remote access behind a VPN. But the lesson from Minnesota is that you have to know all the links. Every communication path into your control environment needs to be inventoried and tested, including the cellular modems, the radio links, the backup communication channels that don’t show up on the network diagram because the diagrams just don’t go into that level of depth, or because some components are simply forgotten about because they were installed five years ago by a contractor who’s long gone. If you don’t know every way into your control systems, you can’t protect them.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“The encouraging news is that operators appear to have maintained safe water service through a mix of manual operations and resilient system design. If those facts hold, this demonstrates an important principle: cyber resilience isn’t about preventing every intrusion, it’s about ensuring cyber incidents don’t become public safety incidents. As cyber attacks increasingly target operational technology, organizations need the operational ability to find exposed systems, fix the highest-risk vulnerabilities, detect compromise when prevention fails, and contain attacks before they disrupt essential services.”
John Strand, Owner, Black Hills Information Security, Inc.:
“We’re seeing more breaches targeting public and critical infrastructure, and I think one of the biggest things people are missing is the difference between financially motivated attackers and nation-state adversaries. When a criminal group compromises a network, they’re often looking for a quick payday through ransomware or data theft. Nation-state operators frequently have a very different objective.
“Their goal is often to gain access and stay there. They want to establish persistence, quietly understand the environment, and position themselves so they can disrupt critical infrastructure whenever it serves their strategic interests. Water treatment facilities, power generation, transportation, and other essential services are attractive targets because they provide leverage long before an attack is ever launched.
“The challenge is that many security programs are still built to detect noisy attacks like ransomware or smash and grab intrusions. They’re much less effective at finding the low and slow activity that characterizes many nation-state operations. If organizations responsible for critical infrastructure aren’t investing in threat hunting, network telemetry, and behavioral analysis designed to uncover long-term persistence, there’s a real risk that sophisticated adversaries will remain inside those environments long before anyone realizes they’re there.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Five separate water utilities hit across Minnesota tells you this was coordinated targeting of a sector, not opportunistic scanning that happened to find a few open doors. The reassuring headline is that crews switched to manual and restored service fast, but manual fallback is a contingency, and contingencies have limits that vary by facility, by staffing, and by how long the disruption runs. What investigators need to establish is how the same attack pattern reached systems in Braham, South St. Paul, Plymouth, Maple Plain, and St. Cloud, because whatever that common thread is, it almost certainly exists in water infrastructure well beyond Minnesota.”
You’re a target. So you have to behave that way. Beef up your defences so that you don’t end up like these organizations. Otherwise you will end up like these organizations.
Share this:
Like this:
Related
This entry was posted on July 28, 2026 at 3:39 pm and is filed under Commentary. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.