# Coordinated Attacks Hit Dozens of Minnesota Water Utilities — And the Sector Isn't Ready
When automated controls start behaving erratically at one water plant, it's an incident. When it happens across dozens of utilities in the same state inside what appears to be a coordinated campaign, it's a warning shot at the entire sector.
Minnesota's water and wastewater utilities are at the center of exactly that scenario. State and federal agencies have confirmed intrusions disrupting operational technology controls at multiple municipal facilities — the kind of systems that manage chemical dosing, pump operations, and pressure regulation. The kind of systems where a misconfiguration doesn't just take a website offline. It affects what comes out of the tap.
## Who Runs America's Water Infrastructure
Before anyone frames this as a sophisticated nation-state operation against hardened critical infrastructure, let's be precise about who actually operates most American water utilities: small municipalities with lean budgets, aging equipment, and IT staff who may also handle everything from the city's email accounts to the parks department's WiFi.
The Environmental Protection Agency has been sounding alarms about this for two years. In a 2024 enforcement alert, the agency found that 70 percent of water systems it inspected violated the Safe Drinking Water Act's cybersecurity provisions — including some with critical or high-risk vulnerabilities. The sector isn't underprepared because people don't care. It's underprepared because a water district serving 12,000 residents in rural Minnesota doesn't have a CISO.
That's the actual attack surface. Dozens of targets, one coordinated campaign.
## What OT Compromise Actually Looks Like Here
Operational technology attacks on water utilities follow a playbook that's been documented enough times to recognize. Attackers gain initial access — often through internet-exposed human-machine interfaces, compromised remote access tools, or vendor connections — and then pivot into the control network. The disruption to "automated controls" referenced by officials could mean anything from tampered setpoints on chemical feed pumps to locked-out SCADA dashboards to manipulated sensor readings that cause operators to make incorrect manual interventions.
The 2021 Oldsmar, Florida incident remains the clearest public case of what this looks like at its most alarming: someone remotely increased sodium hydroxide levels to 111 times the normal concentration before a plant operator caught it. That attack was eventually attributed to a former employee, not a nation-state. Which should comfort nobody. If a disgruntled ex-employee can nearly poison a city's water supply by logging into an unsecured remote desktop, a coordinated threat actor with actual resources can do far worse.
The Cyber Av3ngers campaign in late 2023 — attributed to Iranian-backed hackers — targeted Unitronics programmable logic controllers at water utilities across multiple U.S. states, including in Pennsylvania. That campaign exposed just how many small water systems were running internet-accessible PLCs with default credentials. Some of them didn't know what a Unitronics device was until a federal alert told them they probably had one.
## The "Coordinated" Detail Is the Story
Isolated intrusions at individual water systems are not news at this point. They happen regularly, and most never surface publicly. What makes the Minnesota situation different — and what state and federal agency involvement signals — is the coordinated nature of the attacks.
Coordination implies shared infrastructure, shared tactics, and a threat actor that deliberately targeted the sector rather than stumbling into it. That's either a criminal group testing operational disruption as leverage (ransomware operators have increasingly moved toward OT systems because downtime is more immediately painful than data theft), a state-sponsored actor probing U.S. critical infrastructure resilience, or both. The line between those categories has been blurring for years.
Volt Typhoon, the Chinese state-sponsored group, spent years pre-positioning in U.S. critical infrastructure — water, power, communications — not to cause immediate disruption but to establish persistent access that could be activated during a geopolitical crisis. CISA and the FBI warned specifically about this in early 2024. Whether Minnesota's situation connects to that campaign is not yet confirmed, but the coordinated targeting of multiple utilities in a single state fits the pattern of reconnaissance and capability demonstration rather than opportunistic criminal activity.
## What's Not Getting Enough Attention
Federal response is warranted and necessary. But the response pattern to water sector incidents has become predictable: an alert goes out, affected utilities get incident response support, new guidance gets published, and then the underlying structural problems — underfunding, aging OT equipment with no patch path, no network segmentation between IT and OT environments — remain exactly as they were.
The EPA's attempt to mandate cybersecurity assessments for water utilities was challenged in court and ultimately abandoned in 2023. The sector currently operates without enforceable federal cybersecurity standards equivalent to what NERC CIP requires of the electric grid. That gap is not a bureaucratic footnote. It's the reason a coordinated campaign against dozens of water utilities is possible in the first place.
---
## HackWire Analysis
The Minnesota water utility campaign deserves to be read against a longer arc than a single SecurityWeek headline allows.
Water and wastewater OT attacks have been increasing in frequency and sophistication since at least 2020, but the sector occupies a strange position in critical infrastructure policy: everyone acknowledges it's essential, and almost no one has given it the regulatory teeth to force meaningful security investment. The electric grid has NERC CIP. Financial institutions have DISA STIG requirements, FFIEC guidance, and actual enforcement. Water utilities have voluntary guidance and a patchwork of state-level rules that vary enormously in rigor.
The coordinated element here is what should be driving urgency. Individual utility compromises are noise. Simultaneous targeting of dozens of facilities suggests either a threat actor that has already done significant reconnaissance — mapping which utilities share vendor infrastructure, remote access platforms, or similar SCADA configurations — or one that found a common vulnerability across a vendor ecosystem and weaponized it at scale.
Defenders in this sector need to do three things immediately: audit every internet-exposed OT asset (Shodan will tell you what attackers already know), enforce multi-factor authentication on every remote access pathway without exception, and segment IT from OT networks if that hasn't happened. These are not novel recommendations. The fact that they still need to be made is the indictment.
For state-level policymakers watching this play out in Minnesota: voluntary guidance has had its chance. The next coordinated campaign might not just disrupt automated controls. It might contaminate something.
— HackWire Editorial
---
## Related Coverage