30+ Minnesota Water Utilities Got Hacked

30+ Minnesota Water Utilities Got Hacked

August 19, 2026

The vulnerability has nothing to do with water.

 

What happened

In July 2026, hackers carried out a coordinated attack on more than 30 Minnesota water utilities, shutting down well and treatment plant controls and briefly taking one facility offline. Drinking water stayed safe throughout, but that’s almost beside the point. This isn’t a water story. It’s a SCADA and OT story, and it applies just as much to an oil and gas operator in the Permian Basin as it does to a municipal water plant. 

 

The concern

Water utilities run on OT, operational technology, the systems that run physical equipment like pumps, valves, and treatment controls, as opposed to the IT systems running email and finance. The specific system doing that work is called SCADA: a combination of hardware and software that monitors, gathers data on, and controls those OT processes both near and far. 

One affected utility, Plymouth, said its exposure came through equipment connected via cellular signal rather than the main network. Like a lot of industrial organizations, including remote oil and gas equipment such as wellheads and compressor stations across the Permian Basin, Minnesota’s water utilities connect field equipment back to SCADA over cellular and other wireless links. The gap: most vulnerability assessments check the main network and skip the wireless side of OT entirely. 

That’s not a new trick. Iran-linked hackers used the same kind of weak point to get into Israeli water facilities back in 2020, and hit a Pennsylvania water authority through similar OT access in 2023. It’s a known playbook that a lot of operators, in water and well beyond it, still haven’t closed off. Federal agencies had already flagged this exact kind of threat, Iran-linked actors targeting internet-facing OT devices, including the specific equipment brands used in Minnesota, in the water sector months before this happened. A warning is only useful if someone reads it and does something about it. 

A few things are still unresolved, and they matter. This wasn’t hobby-level hacking. Hitting 30-plus utilities in a single weekend takes coordination and resources most attackers don’t have. Attribution hasn’t been made, and neither has motive. Whether this reflects weak security at these specific utilities, or a flaw in SCADA equipment used at hundreds of sites nationwide, is still an open question. 

What we would do 

This incident isn’t really a water story. It’s an OT story, and that should worry anyone running SCADA-connected equipment out in the middle of nowhere, water utility or industrial operator alike. 

Water towers and pump stations that phone home over cellular or other wireless links use the same basic OT setup as remote wellheads, compressor stations, and pipeline equipment in industries like oil and gas, the Permian Basin being one clear example. Different commodity, same blind spot: remote OT connected wirelessly that nobody folded into the regular security review. 

Here’s where Guardian would have helped: 

  • Asset visibility. We discover and map every connected asset, wireless-linked OT included, the same way an attacker would. 
  • One source of truth. OT and IT feeding separate systems is how gaps like this hide. We bring it into a single view, so nothing sits outside anyone’s watch. 
  • Continuous monitoring. Not a once-a-year checkup. We catch anomalous activity on remote OT as it happens. 
  • Tested response plans. The utilities that stayed operational did it with rehearsed manual failover. We build and test that before an incident, not during one. 
  • Fast action on threat intel. Federal agencies flagged this exact threat months in advance. We turn warnings into action the day they land, not after headlines force the issue. 

Know what’s connected wirelessly, if equipment talks to your OT or SCADA systems over a cellular connection, it needs to be in your inventory. Have a backup plan and actually test it, before you need it, not during an emergency. Act on warnings when they come out. 

Key takeaway

Cellular and other wireless links can be blind spots. Get them into your inventory today. All utilities, and all industrial operators, are in the sights of cyber attackers. Small operations are not too small to be a target. 

Read the original article highlighting the water utilities attack. Article

Connect with our cyber advisor today to learn how your company can protect against this type of incident.