Forgot your password?
typodupeerror
Security Privacy

More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com) 65

jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

More Than 30 Minnesota Water Systems Targeted In Cyberattack

Comments Filter:
  • Boss says (Score:2, Insightful)

    by Anonymous Coward

    I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.

    • by CEC-P ( 10248912 )
      I see you also work in low budget IT lol.
      • by haruchai ( 17472 )

        it happens in any org where people has enough clout to exempt themselves from recommended practices.

    • I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.

      Boss' Boss: "Why are we paying him to remote in when we can hire an international team to remote in for 24/7 redundant button clicking at half the price of one person?"

      International team: "North Korea is willing to pay us to do the job we were hired to do. Sounds tempting..."

  • have anyone actually measured the values before (requires actual data) and after ?

    i.e. water is life start measuring the water pressure and chemistry BEFORE complaining

    • have anyone actually measured the values before (requires actual data) and after ?

      Do you have even the vaguest idea what the monitoring requirements are for water systems in the USA?

      If not, why didn't you look it up?

    • Yes, they have teams of people who do exactly that. Metropolitan Council [wikipedia.org] has a master water supply plan that includes this information for every municipal water source in the seven county region. I personally know people who are on the team that does that. Very, very smart people with lots of field experience and scientific know-how.
    • You think life means anything to the leader of the country?
      • by Anonymous Coward
        Dude. I agree with you, but my god the "what about Trump" is getting old. This has nothing to do with him.
  • attack (Score:4, Interesting)

    by phantomfive ( 622387 ) on Wednesday July 29, 2026 @09:30AM (#66262590) Journal
    So what happened? There are no details of the "attack," no explanation of mitigation, no claim that anything compromised.

    For all we know they installed some new detection software and realized that their computers were being targeted by nefarious ping [wikipedia.org] packets
    • by garcia ( 6573 )

      I live in Plymouth; there was no city communications about this nor did I see any issues. So, I assume there were no physical disruptions to service.

    • Re:attack (Score:5, Informative)

      by Smidge204 ( 605297 ) on Wednesday July 29, 2026 @10:06AM (#66262670) Journal

      From another source [cbsnews.com] it sounds like the plant's SCADA system was compromised and shut down/disabled, causing some plants to go offline.

      The immediate consequence is they would lose remote control over the pumps, fans, and valves at these facilities and either default to some safe state or just shut down entirely. Someone would have to drive over and manually reset/control everything, which is exactly what they did. Addressed promptly enough most people would even notice something was wrong.

      The long term consequences could be that they end up getting incorrect status information about the facility's operation, causing a longer disruption until complaints start coming in and they have to run around trying to figure out what's wrong. Loss of water pressure, distribution of untreated water, distribution of over treated water, depletion of reserves are all obvious problems a bad enough attack could cause. Physical damage to equipment is also not impossible, which would be the worst case scenario.... you're not fixing a broken well/system pump or AOP reactor in two or three hours, and it you lose a bunch of them at once you could be at reduced capacity for months.
      =Smidge=

      • Re:attack (Score:5, Interesting)

        by garcia ( 6573 ) on Wednesday July 29, 2026 @11:17AM (#66262786)

        City Council member of a non-listed Twin Cities suburb I know:

        FBI is involved. Most water systems use one of two control/alert systems that are old and make them easy targets.

        All they did was shut down components of the systems e.g., wells/sewer lift stations. Most cities were able to cycle manually to get back up and running. There was not messages warning or ransom of which I am aware.

        They could have done a lot more damage if they wanted to, rather than just shutting things down.

        • by RobinH ( 124750 )
          Civilian infrastructure is a pretty squishy target in wartime, even without "cyber" attack vectors. If the bullets ever really start flying, expect everyone's standard of living to plummet. Look at the civilian infrastructure that's been hit in the Ukraine war, and now in the Iran war, even in neighboring countries. It's fragile and takes a long time to rebuild. We need to make it clear to our leaders that we want a large alliance network and open but fair trade agreements with other countries, because
    • It was a "rogue AI agent" of course!

  • by RobinH ( 124750 ) on Wednesday July 29, 2026 @09:37AM (#66262612) Homepage
    It must be the preliminary moves in a surprise strike by our mortal forever enemy, Canada. "Oceania had always been at war with Eastasia." - 1984
  • 80's kids know (Score:4, Informative)

    by OrangeTide ( 124937 ) on Wednesday July 29, 2026 @09:39AM (#66262614) Homepage Journal

    Have we learned nothing from 80's movies? WarGames, Superman III, Jumpin' Jack Flash, The Manhattan Project, Ferris Bueller's Day Off, Prime Risk, Hide and Seek, Revenge of the Nerds, and more showed us what happens when a business or government leaves computer connected and always on.

    I would recommend we not plug everything into the Internet. Or at least use two layers of authentication, one for the VPN, and one for the devices themselves on the private network. With no NAT while in the private network.

    But for industries that buy off-the-shelf monitoring systems, that's not how they actually work. They are really just the equivalent of an wireless router running embedded Linux, glorifies OpenWRT to hook a site's LoRa/Zigbee/802.15.4 sensor network to a gateway to store and forward monitoring data. Ideally not doing controls, but honestly if you unplug the safety monitoring then you have to shut the whole system down. So even a sensor systems is a viable target if the goal is a simple DoS attack.

    • The only way to avoid having the systems hacked is to just don't computer.

      • by kmoser ( 1469707 )
        Ignore that innocent looking guy in a hard hat and construction vest carrying a clipboard. I'm sure he's authorized to flip those switches and turn those knobs and open those valves.
        • A classic heist trick too, nobody checks the plumber's toolbags (in the movies). Worked for Ocean's Eleven and The A-Team.

    • Re: (Score:2, Interesting)

      by thegarbz ( 1787294 )

      I would recommend we not plug everything into the Internet.

      Not possible in today's world. Infrastructure is not just big, but relies on real time information across it accessible remotely by engineers. One could foresee a way around this by laying fibre lines with absolutely everything, but that is only cheap for new installations. How much more do you want to pay for water / power to retrofit this?

      Or at least use two layers of authentication

      The problem here is the age of equipment. A lot of it just isn't up to modern standards. You don't need to recommend two layers of authentication, we already have far mo

  • Good! (Score:5, Insightful)

    by SlashbotAgent ( 6477336 ) on Wednesday July 29, 2026 @10:22AM (#66262702)

    They fucking deserve everything they get. We have had more than enough close calls and incidents to clearly demonstrate to every drooling moron that critical infrastructure like water and electricity systems should never be connected to the internet. There's no reason for them to to need it.

    No fucking access in or out. Fucking duh!

    Air gap that shit or get the intrusion that you deserve. My private infrastructure has computer monitoring and automation. But, none of it can exchange a single packet with the internet. There's no reason that a state government with dedicated IT departments shouldn't know and do the same.

    • by PPH ( 736903 )

      community water systems

      These might be nothing more than a bookkeeper and an on-call plumber. And you want them to hire an IT person in a market that starts at 6 figures for a game developer that can barely fog a mirror?

      We can't even get our state to ditch Microsoft.

      • by gweihir ( 88907 )

        Ever heard of service providers?

        Incidentally, if this was not done using the cheapest possible crap (yes, Microsoft among others), this could be done pretty securely. OpenSSH, for example, has a pretty impressive security record (unless some blithering idiots in some distros patch systemd libraries in there, that is) and OpenVPN is pretty good too. This would be more than enough to secure links to, say, a central control computer. Obviously, this would need to be administrated as a service, but remote admin

        • by PPH ( 736903 )

          Ever heard of service providers?

          Yes. These are the people that repeatedly e-mail me to inform me that my account is full and I have to follow the included link and log on to remedy the situation.

    • Anyone can get phished, especially these days.

      Admin computers with e-mail access might also have access to the private control fabric that doesn't have direct Internet access.

      • by gweihir ( 88907 )

        Not really. Anyone using Outlook can get phished easily. For other MUAs it is more difficult, for some a lot more difficult. For good ones you have to convince the operator to do something obviously stupid.

        • Timing is everything.

          If the circumstances are conducive to it, even the most paranoid person can get phished in a moment of distraction.

          A famous, recent(ish) example is the operator of HIBP, who mistakenly fell for a credential phish because he was distracted and/or tired and the communication was something that he wasn't surprised by in the moment.

          https://www.malwarebytes.com/b... [malwarebytes.com]

          • by gweihir ( 88907 )

            This is not about eliminating the problem. It is about making it so unlikely to happen that the bad guys give up. And we are very far from that, especially on Outlook.

    • by gweihir ( 88907 )

      I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.

      And yes, there is reasons for having that connection and it is not only convenience. Unless you want to start digging for dedicated fiber connections all over the country at huge cost?

      • Unless you want to start digging for dedicated fiber connections all over the country at huge cost?

        Would it cost more to bury that dedicated fiber with the pipes? Would it be a huge cost to build out your own wireless network, like many power companies do?

        There are still many water utilities serving area with a million or more customers that do not have ANY infrastructure connected to the internet. Back office and billing, sure. Infrastructure, is not connected. How ever do they manage? They manage just fine.

        Let me restate for the hard of hearing and the hard of feeling, no critical infrastructure such a

        • by tlhIngan ( 30335 )

          Would it cost more to bury that dedicated fiber with the pipes? Would it be a huge cost to build out your own wireless network, like many power companies do?

          There are still many water utilities serving area with a million or more customers that do not have ANY infrastructure connected to the internet. Back office and billing, sure. Infrastructure, is not connected. How ever do they manage? They manage just fine.

          Let me restate for the hard of hearing and the hard of feeling, no critical infrastructure such a

          • Do you know of an SDR means of decoding the new iTron meters?

            I used to be able to listen to my and my neighbors' iTron meter broadcasts. But, then the power company upgraded the meters and I haven't figured out how to receive nor decode the new meters.

        • by gweihir ( 88907 )

          If your pipes are already in the ground and good for another 50 years? Yes. The cost makes this completely unworkable.

      • I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.

        This. The bad guys and gals go after the low hanging fruit. And there is so. damned. much. of. it.

        I've long said that a company - especially one involved with essential infrastructure, should have a head of IT with C-Suite level authority. And the compliance chops to go with it.

        And while small companies - water in this case - might not have the money to hire such a person, if they have to use software, it comes from somewhere. So "somewhere" needs to be responsible and in the loop. If that's too muc

        • by gweihir ( 88907 )

          The "small utility problem" can be solved. C-level CISO "as a service" or part time is entirely doable. You just need to want to do it.

      • In this instance, you and I agree completely.

    • So you've never heard of social engineering, which can breach airgapped systems.

    • No fucking access in or out. Fucking duh!

      Airgap isn't compatible with modern infrastructure requirements. Your city is bigger than the town of yesteryear. Remote control is a necessity, not just for basic control and optimisation but in many cases to maintain things like safe water quality.

      Sure you could setup your own network, lay your own fibre, but how much do you want to pay for water?

      The reality is the problem here is basic cybersecurity standards weren't in place which is not surprising for old infrastructure.

      By the way air-gapped systems ar

  • "Land of 10,000 Lakes". So, who cares? Just grab a bucket.

  • Wrong headline (Score:5, Insightful)

    by gweihir ( 88907 ) on Wednesday July 29, 2026 @11:14AM (#66262784)

    A better one would be "More than 30 Minnesota water systems have IT security that completely sucks".

    Seriously, without liability (including personal one) and strict qualification requirements, the total crap-show that IT security is today will continue. And not only for critical infrastructure.

    • If it's connected to the internet, the security will eventually be found to suck. The solution is air gap and private network (but even then, it's connected to a network between buildings so security will eventually be found to suck).
      • by gweihir ( 88907 )

        Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.

        • Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.

          You know - I'm amazed at how many in here - a site supposedly of the computer savvy - think that if you are on the internet at all, you are pwned. Using good security (and no, Windows Defender and Firewall is obviously not good security) you can be pretty safe.

          And before anyone chimes in on how no internet facing system is safe, it is true that if it can be written, it can be compromised. But that's not the point. The point is that about 70 percent of setups have piss-poor security. So the hackers go

          • by gweihir ( 88907 )

            Pretty much, yes. Although very simple systems, designed carefully, can achieve security that cannot practically be broken IMO. But let's not get into that. The point is that if you have good, state-of-the-art security on your systems, designed and operated with actual understanding, you very likely will not get attacked or not get attacked that way.

            • State of the art doesn't matter, if there happens to be a low thinking worker on the payroll, they get social engineered. But since you are still on the internet that social engineering opens a hole that may not even be used for several years and that employee is long gone. Also we can not forget that managers like outsourcing to third parties on the other side of the world that doesn't have security worth the paper it is written upon.
  • I doubt Minnesota was specifically targeted; they are simply the first state to notice that multiple attacks occurred.
  • Guys? Any chance this was related to this [slashdot.org]?

    • by PPH ( 736903 )

      Yes. The AIs have figured out that if they can kill off the meatsacks competing for water supplies by poisoning them, they'll have more for their data center cooling needs.

  • Funny, right around the time Elon sued the state because they're banning AI fake porn of real people and children.

  • I mean, I'll say it if no one else is.
  • ... the open ai logs?
  • Core defensive principle:

    * Treat water-system control infrastructure as air-gapped or tightly controlled by default:

    * No direct internet connectivity for PLCs, SCADA servers, HMIs, or field devices.

    * Remote access (if truly required) only through dedicated, monitored jump hosts or industrial gateways with strong authentication, MFA, logging, and the ability to instantly cut sessions.

    * Cellular connections for towers/lift stations should use industrial-grade gateways that enforce VPN tunnels and

Time sharing: The use of many people by the computer.

Working...