30 Water Utilities Went Dark Overnight. Here's What Every Business Leader Needs to Know.
A coordinated cyberattack hit more than 30 Minnesota water systems in 48 hours. One plant went offline. The lesson isn't just about water — it's about every OT system your business depends on.
On the morning of July 27, residents in Braham, Minnesota — a small city of about 1,700 people — were asked to minimize water use. Not because of a drought. Not because of a pipe break. Because a cyberattack had shut down the computerized controls at their water treatment plant.
By the time state officials finished their count, more than 30 Minnesota community water systems had been targeted in a coordinated cyberattack spanning July 26 and 27. Maple Plain declared a local state of emergency. Plymouth disconnected cellular-connected equipment at water towers and wastewater lift stations to stop the spread. South St. Paul's automated water controls went dark.
Drinking water remained safe in every case. State and federal investigators are still working to attribute the attack. But the operational disruption was real, the coordination was deliberate, and the lesson cuts across every industry.
This Isn't Just a Water Utility Problem
The temptation when you read a story like this is to file it under "critical infrastructure — not my problem." Most business leaders don't run water utilities. But the attack pattern here applies to a much broader universe.
The Minnesota attacks targeted what security professionals call OT — operational technology. These are the computerized systems that control physical processes: water treatment, manufacturing lines, HVAC systems, building management systems, hospital equipment, logistics networks. OT is increasingly networked, increasingly internet-connected, and almost universally under-secured compared to traditional IT environments.
If your business relies on any physical process controlled by software — and most do — you have OT exposure. You may just not know it yet.
The specific vulnerability pattern here involves cellular-connected industrial control systems with minimal authentication. Plymouth's own statement gave it away: "The issue is limited to equipment connected via cellular communications within the system." Those are OT devices that someone plugged into a cellular modem for remote access, probably years ago, probably because it was convenient. Nobody applied the same security scrutiny they would to a corporate laptop.
What We Know About the Attack
Minnesota IT Services confirmed the attacks were "coordinated" — meaning a single actor or coordinated group hit dozens of systems in a short window, not random opportunists stumbling across vulnerable systems one at a time.
Federal and state investigators haven't made a formal attribution, but cybersecurity researchers were quicker to connect the dots. Tenable's analysis noted the attack pattern is consistent with CyberAv3ngers, an Iranian-affiliated threat group formally linked to Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command. CISA had issued an updated advisory on July 22 — just four days before the Minnesota attacks — specifically warning that the same group had expanded its targeting to Schneider Electric and Siemens industrial control systems, in addition to Rockwell Automation systems already on the list.
Whether or not Iran is ultimately confirmed as the source, the implications are the same: nation-state and nation-state-adjacent actors are actively probing internet-connected operational technology. Water systems are targets. So are food processors. Manufacturing plants. Energy management systems. Anything with a programmable logic controller (PLC) that can be reached over the internet.
The Unpatched Problem That Isn't Going Away
Here's the detail that should concern every business leader, regardless of industry: the primary vulnerability exploited in this category of attack — CVE-2021-22681, an authentication bypass in Rockwell Automation Logix controllers — has no patch. Rockwell has said publicly that this specific flaw cannot be fully addressed with a software update. Their guidance is to apply defense-in-depth mitigations instead.
That's an uncomfortable reality. You can't patch your way out of this one. You have to architect your way out of it — through network segmentation, taking OT systems off direct internet exposure, and implementing secure gateway access with multi-factor authentication for any remote access to industrial systems.
This is also a pattern. The nginx vulnerability disclosed earlier this month had been sitting undetected for 15 years. GhostLock, a Linux kernel flaw, had been exploitable since 2011. The pattern isn't an aberration — it's a feature of legacy OT and infrastructure software that was built before security was a design priority.
Three Questions Every Business Leader Should Be Asking
First: Do you know what OT systems your business is running?
This sounds basic, but many organizations have OT blind spots. Building management systems, HVAC controls, manufacturing equipment, physical security systems — these often live outside the visibility of the IT security team. They were installed by facilities teams, by contractors, by equipment vendors. They get upgraded infrequently. The question isn't whether you have OT exposure — it's whether you know where it is.
Second: Which of those systems are internet-connected, and should they be?
Remote access to OT systems is operationally convenient. It's also a significant attack surface. The Minnesota attacks specifically targeted cellular-connected infrastructure — the convenience path someone chose years ago that opened a door an attacker walked through. Every internet-connected OT system should be on a list, reviewed for necessity, and protected by a secure access gateway with MFA if remote access is genuinely required. Systems that don't need internet connectivity should be isolated.
Third: What happens to your operations if those systems go offline for 48 hours?
Braham got lucky — their crews restored the water plant within about two hours by operating manually. Plymouth kept operating through manual procedures. But not every business has a manual fallback. The question to ask now, before an incident, is: what's our continuity plan if our OT systems are knocked offline? How long can we operate manually? What do we lose, and who do we need to notify?
A state of emergency is a lot more disruptive than the conversation you have with your IT and facilities teams today.
The Bottom Line
Thirty water utilities in Minnesota went dark in a 48-hour window. The attacks were coordinated. The systems targeted were reachable because they were convenient, not because they were designed to be accessible. Nobody was hurt, and drinking water stayed safe — but the operational disruption was real, the response was expensive, and the investigation continues.
If you're waiting for your industry to make the news before you take OT security seriously, you're already behind. The actors targeting water utilities in Minnesota aren't selective about industry — they're selective about what's exploitable.
Know your attack surface. Control your remote access. Build your manual fallback. These aren't theoretical recommendations — they're what the cities of Plymouth, South St. Paul, and Braham are wishing they'd done before July 26.
---
TrustPoint Cyber helps business leaders understand their operational technology exposure, build resilient access controls, and develop continuity plans for exactly this kind of scenario. If you're not sure where your OT risk sits, let's talk.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.