Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks
July 30, 2026 – Published on Dark Reading
A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don’t appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota’s IT Services (MNIT) unit.
The US has more than 148,000 public drinking-water systems and when publicly owned wastewater treatment systems are included, that number goes up to between 165,000 and 170,000, points out Patrick Gillespie, OT practice director at GuidePoint Security. Many of these organizations are small, rural, or municipally operated and have limited cybersecurity personnel, funding, procurement capacity, and access to specialized OT expertise.
“While large investor-owned utilities may be able to fund preventative measures like security monitoring, incident-response retainers, and dedicated security teams, many small community systems cannot,” Gillespie says. “This is what makes the water sector a really attractive target for bad actors.”
Read More HERE.