skip to content
Keyboard

News

​Minnesota continues response to cyber activity affecting community water systems

7/30/2026 2:37:01 PM

ST. PAUL, Minn. (July 30, 2026) —State, local, and federal officials continue to respond to malicious cyber activity targeting technology at more than 30 community water systems across Minnesota.

The investigation remains active, and Minnesota has not attributed the activity to a specific actor.

Minnesota activated its coordinated cyber-response capabilities after learning of the activity. State agencies are working directly with impacted water systems to contain the activity, assess potential impacts, restore normal operations, and reduce the risk of further disruption.

At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use. Minnesota officials will continue to work with local water systems and provide updates if public guidance changes.

What the state knows

Most confirmed cases involved technology that water systems use to remotely monitor and control equipment. This included programmable logic controllers (PLCs), and the computer screens operators use to manage them, known as human-machine interfaces (HMIs).

In this situation, “impacted” means investigators confirmed malicious activity involving a system’s technology. It does not mean every affected community experienced a disruption to water service.

Minnesota’s response to this cyber activity remains focused on protecting public services, supporting local operators, and reducing the potential for additional impacts.

Attribution remains under investigation

Minnesota is not attributing this activity to a specific actor at this time. Attribution requires investigators to analyze technical evidence alongside broader national and international threat intelligence.

Since learning of this activity, we have assessed its impact, identified methods of access and worked with local partners to better protect Minnesota systems ,” said John Israel, Minnesota’s Chief Information Security Officer. “We have provided relevant information to the federal government, which is evaluating this activity in the broader national context and leading efforts to determine whether it can be attributed to a specific threat actor .”

Investigators have identified similarities among the incidents, including their timing and the types of technology involved. However, the investigation has not determined that every incident was carried out by the same actor.

MNIT will not release system-specific forensic findings, network indicators, or access details while the investigation remains active. Disclosing that information could affect the investigation or create additional risks for affected and potentially vulnerable systems.

The state continues to assess whether specific equipment issues or operational disruptions resulted directly from malicious activity. Local water-system operators make decisions about taking equipment offline or requesting water conservation based on the conditions within their systems. Questions about a specific community’s operational decisions should be directed to that utility.

Statewide response continues

Minnesota IT Services is coordinating response efforts with the Minnesota Department of Public Safety, Bureau of Criminal Apprehension’s Minnesota Fusion Center, Minnesota Department of Health, Minnesota Pollution Control Agency, Cybersecurity and Infrastructure Security Agency, U.S. Environmental Protection Agency, Federal Bureau of Investigation, and local water utilities. These efforts include:

  • Helping communities contain malicious activity and secure affected technology.
  • Supporting forensic analysis, system recovery, and restoration.
  • Sharing threat information with water systems across Minnesota.
  • Identifying and addressing potentially vulnerable technology.
  • Coordinating with federal cybersecurity and law enforcement officials.

Minnesota has established cybersecurity capabilities and partnerships to help state and local governments prepare for, respond to and recover from cyber incidents.

Guidance for water systems

Water and wastewater systems should identify operational technology (OT) that can be accessed from the internet and take immediate steps to secure it. Recommended actions include:

  • Remove unnecessary internet access from PLCs, HMIs, and other OT.
  • Replace default credentials and use strong, unique passwords.
  • Require multi-factor authentication for remote access whenever the technology supports it.
  • Review remote-access logs and configurations for suspicious activity.
  • Separate OT from business and administrative networks.
  • Maintain an accurate inventory of OT and its external connections.
  • Maintain offline backups and test incident-response and recovery plans.
  • Promptly report suspected cyber activity to state and federal officials.

Water-system operators can review additional technical guidance in the Cybersecurity and Infrastructure Security Agency’s cybersecurity advisory .


About Minnesota IT Services

Minnesota IT Services, led by the state’s Chief Information Officer, is the Information Technology agency for Minnesota’s executive branch, providing enterprise and local IT services to over 70 agencies, boards, and commissions. MNIT employs more than 2,800 people. Together, we build, maintain, and secure the State’s IT infrastructure, applications, projects, and services. MNIT sets IT strategy, direction, policies, and standards for enterprise IT leadership and planning. We also serve Minnesotans by connecting all 87 counties, 300 cities, and 200 public higher education campuses across the state on the MNET network. Through public-private partnerships, our team proactively protects the state’s information systems and the private data of 5.7 million Minnesotans. 

Previous announcements

General

Digital Government

Cybersecurity

Digital Government

Public Safety

Cybersecurity

Security