
Minnesota officials have activated a statewide cybersecurity response after a coordinated cyberattack targeted the operational technology (OT) of more than 30 community water systems across the state.
Authorities say there is currently no indication that residents need to alter their drinking water use, while investigations and recovery efforts remain ongoing.
The attack took place on July 26 and 27, prompting Minnesota IT Services (MNIT) to immediately activate its cybersecurity incident response capabilities. According to an announcement published on July 28, MNIT is coordinating with federal, state, local, Tribal, and private-sector partners to investigate the incident, assist affected utilities, and strengthen defenses protecting critical infrastructure.
As part of the response, MNIT cybersecurity teams are assessing the impact of the attack, sharing threat intelligence and indicators of compromise, and helping affected organizations contain, investigate, recover from, and remediate the incident. The agency is also monitoring for related malicious activity while coordinating with state and federal cybersecurity partners.
The response involves the Minnesota Department of Public Safety, the Bureau of Criminal Apprehension's Minnesota Fusion Center, the Minnesota Department of Health (MDH), the Minnesota Pollution Control Agency, the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Environmental Protection Agency (EPA), the Federal Bureau of Investigation (FBI), and local water utilities.
Minnesota IT Services is the state's central IT agency, providing technology services to more than 70 executive branch agencies, boards, and commissions. The organization also manages the MNET network, which connects all 87 Minnesota counties, approximately 300 cities, and 200 public higher education campuses, while supporting cybersecurity initiatives across the state's public sector.
Officials said the investigation remains active and responders are continuing to evaluate affected systems. MDH is working directly with impacted utilities to ensure public health protections remain in place and, at this time, has not received any requests from Minnesota communities to advise residents to change their drinking water use.
“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer. He said the state's cybersecurity investments and partnerships enabled agencies to rapidly coordinate their response, contain the incident, and reduce the risk of more severe disruptions to critical services.
MNIT said it will continue to support affected communities by sharing threat intelligence, providing technical assistance, and coordinating recovery efforts with government and industry partners. The agency has not disclosed the threat actor, attack vector, or technical details of the intrusion, and it remains unclear whether the incident affected water treatment processes or was limited to operational technology networks.
Organizations operating critical infrastructure should ensure OT environments are segmented from corporate IT networks, apply security updates where feasible, monitor for unusual activity, review remote access controls, and coordinate with government cybersecurity agencies if suspicious activity is detected. MNIT said additional information will be released as the investigation progresses.







Leave a Reply