On July 26 and 27, a coordinated cyberattack targeted the operational technology of more than 30 Minnesota community water systems, prompting the state to activate its full cybersecurity incident‑response network.

According to Minnesota IT Services (MNIT), the assault was confined to the control systems that manage water treatment and distribution. The agency confirmed that the systems were not compromised in a way that would affect the quality or safety of the water. Residents in the affected communities were not advised to alter their drinking‑water habits, and the Minnesota Department of Health (MDH) reported that no municipalities had issued any advisories.

Four cities – Plymouth, South St. Paul, Maple Plain, and Braham – publicly disclosed the incidents. Each city stated that the impact was contained and that normal water service continued. None of the municipalities reported service interruptions or health concerns.

In response, MNIT has been working with the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, and other federal partners to investigate the source of the attack and to support the affected utilities. The state’s incident‑response team is also collaborating with local emergency‑management agencies and private‑sector cybersecurity firms to assess vulnerabilities and strengthen defenses.

"Cyberattacks against critical infrastructure require a coordinated, whole‑of‑government response," said MNIT Assistant Commissioner and Chief Information Security Officer John Israel. "Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services."

Water systems are classified as critical infrastructure because they provide essential public services. The attack highlighted the growing risk to operational technology that controls water treatment plants, pumps, and monitoring equipment. While the MDH did not see any immediate health risks, the incident underscores the need for regular cybersecurity assessments and updates to legacy systems.

State officials are continuing to investigate the attack’s origin and to evaluate the extent of any potential data exposure. MNIT is also reviewing its own cybersecurity posture and is working to share lessons learned with other state agencies and local utilities.

The incident comes amid a broader national trend of cyberattacks on public water systems. Minnesota’s response demonstrates the state’s commitment to protecting essential services and to maintaining public confidence in the safety of drinking water.

As the investigation proceeds, officials have not yet identified the perpetrators. The state has not issued a public advisory beyond the statements from the affected cities. Residents can continue to use their tap water as usual.

The Minnesota Department of Health remains monitoring the situation and will issue guidance if any changes to water quality or usage are warranted. MNIT will continue to coordinate with federal partners and will provide updates as more information becomes available.

The state’s next steps include a full technical review of the affected systems, the implementation of enhanced monitoring tools, and the development of a statewide cybersecurity framework for public utilities. The investigation is ongoing, and officials have indicated that they will keep the public informed as new details emerge.