← All Briefings
Briefings


Coordinated Attack Knocks Out 30 Minnesota Water Utilities

Hackers took operational technology offline at more than 30 Minnesota community water systems on July 26 and 27, prompting the Minnesota IT Services agency to activate statewide cybersecurity incident response. Braham, Plymouth, and South St. Paul are among the systems named in the disclosure. Water treatment OT typically sits behind a single internet-facing HMI or a remote-access product installed for vendor maintenance, and thirty simultaneous outages across unrelated municipal systems is not what an isolated intrusion looks like. It is what a shared vulnerability in one product looks like, hit once and replayed across every customer running it.

MNIT has not published which remote-access product or HMI vendor sits behind the affected systems, and until that name surfaces, every water utility running the same unpatched interface is still exposed on the same clock the first thirty were. The Cybersecurity and Infrastructure Security Agency has spent three years telling water utilities to pull default credentials and internet-facing HMIs off Ovarro TBox and Unitronics controllers after Iranian-linked intrusions in 2023 and 2024. The control that would have changed the outcome here is the same one: take the remote interface off the public internet before the next disclosure names it instead of MNIT.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.