Security Affairs
Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline|ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog|Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected|MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data|Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline|ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data|Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution|OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach|OpenAI’s Rogue AI Agent Breached Second Company, Report Says|VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims|Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure|JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover|New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide|U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog|Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected|MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline

Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than […]

Minnesota Water Utilities

Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts.

Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT).

“A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27. Minnesota IT Services (MNIT) immediately activated the state’s cybersecurity incident response capabilities.” reads the statement published by MNIT. “MNIT continues to collaborate with federal, state, local, Tribal, and private-sector partners to investigate the attack, support affected communities, and strengthen the security of Minnesota’s critical infrastructure.”

The agency activated its statewide incident response the moment it learned of the attack, and it’s still active as of this week.

Four cities went public with details: BrahamMaple Plain, Plymouth, and South St. Paul. Braham took the hardest hit of the group; the town of about 1,700 people had its water plant knocked offline entirely after attackers disabled the computerized controls running its well and treatment systems.

water utilities

Crews had the plant back up within roughly two hours, filtering and treating water normally again.

Plymouth got off comparatively easy. The city’s IT team disconnected the cellular-connected equipment at two of its water towers as a precaution, and the issue stayed contained to that cellular-connected equipment, according to the city’s own statement. Most of the affected utilities across the state kept running through backup procedures without ever going offline.

Minnesota IT Services is continuing to investigate the coordinated cyberattack against the state’s water utilities while helping affected operators contain the incident, assess the damage, and restore impacted systems. The agency is sharing threat intelligence and response guidance in coordination with state and federal partners, including the FBI, CISA, the EPA, the Minnesota Department of Health, and local utilities. Authorities are still analyzing the scope of the attack, but there is currently no indication that drinking water safety has been compromised, and no Minnesota community has been advised to change its water use.

MNIT’s chief information security officer, John Israel, put out a statement framing the response as proof the state’s investment in cybersecurity partnerships actually paid off.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said Israel. “MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services.”

Partners include a mix of state, local, federal, and Tribal entities now working the case together. That list includes Minnesota’s Department of Health, its Bureau of Criminal Apprehension fusion center, CISA, the EPA, and the FBI, all working alongside the affected utilities directly.

The attack has yet to be attributed, and the investigation is still ongoing. The timing lines up close enough with something else to raise an eyebrow, though: four days earlier, CISA and six other federal agencies had updated a warning about Iranian-affiliated hackers exploiting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, and Siemens, across US water and energy infrastructure broadly. Nobody’s confirmed a link between that advisory and what happened in Minnesota, and it would be premature to draw a straight line between the two just because they landed in the same week.

Minnesota’s health department says it hasn’t seen any city ask residents to change how they use their tap water, which is the detail worth holding onto here. Contingency plans, backup procedures, and manual overrides did what they’re supposed to do at a majority of the affected utilities: nothing dramatic happened, because the boring stuff worked. Sometimes the best cybersecurity story is the one where nobody outside the IT department even noticed.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, water utilities)