Overview
- State officials discovered the intrusions on Sunday and Monday when automated operational‑technology systems at more than 30 community water utilities showed signs of malicious access.
- Investigators have tentatively linked the attacks to Iranian‑affiliated hackers because the intruders targeted programmable logic controllers and sought disruption rather than money, but authorities have not made a definitive attribution.
- Some towns briefly lost automated control of wells or treatment plants and used manual workarounds or short conservation requests, and there are no confirmed reports of drinking‑water contamination.
- Minnesota IT Services is working with the FBI, CISA and the EPA on response and remediation while CISA has issued guidance urging operators to remove internet‑exposed PLCs or isolate them with VPNs or gateways.
- Security experts warn the incidents fit a broader pattern of probing of internet‑connected industrial controls, highlight chronic underfunding of local utilities, and leave open the risk of similar attacks in other states as forensics continue.