News: 0184745098

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com)

(Wednesday July 29, 2026 @05:00PM (BeauHD) from the coordinated-attacks dept.)


[1]jrnvk shares a report from KMSP:

> Minnesota IT Services reports that a "coordinated cyberattack" [2]targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.

>

> On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.

>

> State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.



[1] https://slashdot.org/~jrnvk

[2] https://www.fox9.com/news/30-minnesota-water-systems-targeted-cyber-attack



Boss says (Score:1)

by Anonymous Coward

I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.

Re: (Score:2)

by CEC-P ( 10248912 )

I see you also work in low budget IT lol.

Re: (Score:2)

by haruchai ( 17472 )

it happens in any org where people has enough clout to exempt themselves from recommended practices.

Boss' Boss says (Score:2)

by Culture20 ( 968837 )

> I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.

Boss' Boss: "Why are we paying him to remote in when we can hire an international team to remote in for 24/7 redundant button clicking at half the price of one person?"

International team: "North Korea is willing to pay us to do the job we were hired to do. Sounds tempting..."

more like team viewer on older windows version so (Score:2)

by Joe_Dragon ( 2206452 )

more like team viewer on older windows version so we don't need pay $4/gal + for people to drive to each site.

measurement ? (Score:1)

by johnjones ( 14274 )

have anyone actually measured the values before (requires actual data) and after ?

i.e. water is life start measuring the water pressure and chemistry BEFORE complaining

Re: (Score:2)

by drinkypoo ( 153816 )

> have anyone actually measured the values before (requires actual data) and after ?

Do you have even the vaguest idea what the monitoring requirements are for water systems in the USA?

If not, why didn't you look it up?

Re: (Score:2)

by Green Mountain Bot ( 4981769 )

Yes, they have teams of people who do exactly that. [1]Metropolitan Council [wikipedia.org] has a master water supply plan that includes this information for every municipal water source in the seven county region. I personally know people who are on the team that does that. Very, very smart people with lots of field experience and scientific know-how.

[1] https://en.wikipedia.org/wiki/Metropolitan_Council_(Minnesota)

Re: measurement ? (Score:1, Flamebait)

by fluffernutter ( 1411889 )

You think life means anything to the leader of the country?

attack (Score:4, Interesting)

by phantomfive ( 622387 )

So what happened? There are no details of the "attack," no explanation of mitigation, no claim that anything compromised.

For all we know they installed some new detection software and realized that their computers were being targeted by nefarious [1]ping [wikipedia.org] packets

[1] https://en.wikipedia.org/wiki/Ping_(networking_utility)

Re: (Score:3)

by garcia ( 6573 )

I live in Plymouth; there was no city communications about this nor did I see any issues. So, I assume there were no physical disruptions to service.

Re:attack (Score:5, Informative)

by Smidge204 ( 605297 )

From [1]another source [cbsnews.com] it sounds like the plant's SCADA system was compromised and shut down/disabled, causing some plants to go offline.

The immediate consequence is they would lose remote control over the pumps, fans, and valves at these facilities and either default to some safe state or just shut down entirely. Someone would have to drive over and manually reset/control everything, which is exactly what they did. Addressed promptly enough most people would even notice something was wrong.

The long term consequences could be that they end up getting incorrect status information about the facility's operation, causing a longer disruption until complaints start coming in and they have to run around trying to figure out what's wrong. Loss of water pressure, distribution of untreated water, distribution of over treated water, depletion of reserves are all obvious problems a bad enough attack could cause. Physical damage to equipment is also not impossible, which would be the worst case scenario.... you're not fixing a broken well/system pump or AOP reactor in two or three hours, and it you lose a bunch of them at once you could be at reduced capacity for months.

=Smidge=

[1] https://www.cbsnews.com/minnesota/news/cyberattack-malware-braham-water-plant-outage/

Re:attack (Score:5, Interesting)

by garcia ( 6573 )

City Council member of a non-listed Twin Cities suburb I know:

FBI is involved. Most water systems use one of two control/alert systems that are old and make them easy targets.

All they did was shut down components of the systems e.g., wells/sewer lift stations. Most cities were able to cycle manually to get back up and running. There was not messages warning or ransom of which I am aware.

They could have done a lot more damage if they wanted to, rather than just shutting things down.

Re: (Score:3)

by RobinH ( 124750 )

Civilian infrastructure is a pretty squishy target in wartime, even without "cyber" attack vectors. If the bullets ever really start flying, expect everyone's standard of living to plummet. Look at the civilian infrastructure that's been hit in the Ukraine war, and now in the Iran war, even in neighboring countries. It's fragile and takes a long time to rebuild. We need to make it clear to our leaders that we want a large alliance network and open but fair trade agreements with other countries, because

Blame Canada (Score:5, Funny)

by RobinH ( 124750 )

It must be the preliminary moves in a surprise strike by our mortal forever enemy, Canada. "Oceania had always been at war with Eastasia." - 1984

80's kids know (Score:4, Informative)

by OrangeTide ( 124937 )

Have we learned nothing from 80's movies? WarGames, Superman III, Jumpin' Jack Flash, The Manhattan Project, Ferris Bueller's Day Off, Prime Risk, Hide and Seek, Revenge of the Nerds, and more showed us what happens when a business or government leaves computer connected and always on.

I would recommend we not plug everything into the Internet. Or at least use two layers of authentication, one for the VPN, and one for the devices themselves on the private network. With no NAT while in the private network.

But for industries that buy off-the-shelf monitoring systems, that's not how they actually work. They are really just the equivalent of an wireless router running embedded Linux, glorifies OpenWRT to hook a site's LoRa/Zigbee/802.15.4 sensor network to a gateway to store and forward monitoring data. Ideally not doing controls, but honestly if you unplug the safety monitoring then you have to shut the whole system down. So even a sensor systems is a viable target if the goal is a simple DoS attack.

Yeah, don't computer (Score:2)

by ebunga ( 95613 )

The only way to avoid having the systems hacked is to just don't computer.

Re: (Score:2)

by kmoser ( 1469707 )

Ignore that innocent looking guy in a hard hat and construction vest carrying a clipboard. I'm sure he's authorized to flip those switches and turn those knobs and open those valves.

Good! (Score:4, Insightful)

by SlashbotAgent ( 6477336 )

They fucking deserve everything they get. We have had more than enough close calls and incidents to clearly demonstrate to every drooling moron that critical infrastructure like water and electricity systems should never be connected to the internet. There's no reason for them to to need it.

No fucking access in or out. Fucking duh!

Air gap that shit or get the intrusion that you deserve. My private infrastructure has computer monitoring and automation. But, none of it can exchange a single packet with the internet. There's no reason that a state government with dedicated IT departments shouldn't know and do the same.

Re: (Score:2)

by PPH ( 736903 )

> community water systems

These might be nothing more than a bookkeeper and an on-call plumber. And you want them to hire an IT person in a market that starts at 6 figures for a game developer that can barely fog a mirror?

We can't even get our state to ditch Microsoft.

Re: (Score:2)

by gweihir ( 88907 )

Ever heard of service providers?

Incidentally, if this was not done using the cheapest possible crap (yes, Microsoft among others), this could be done pretty securely. OpenSSH, for example, has a pretty impressive security record (unless some blithering idiots in some distros patch systemd libraries in there, that is) and OpenVPN is pretty good too. This would be more than enough to secure links to, say, a central control computer. Obviously, this would need to be administrated as a service, but remote admin

Re: (Score:2)

by PPH ( 736903 )

> Ever heard of service providers?

Yes. These are the people that repeatedly e-mail me to inform me that my account is full and I have to follow the included link and log on to remedy the situation.

Re: (Score:2)

by gweihir ( 88907 )

Careful, your mental immaturity is showing.

Re: (Score:2)

by PPH ( 736903 )

Thank you. The wisdom and experience of a boomer, but the IT savvy of a millennial.

Re: (Score:2)

by The-Ixian ( 168184 )

Anyone can get phished, especially these days.

Admin computers with e-mail access might also have access to the private control fabric that doesn't have direct Internet access.

Re: (Score:2)

by gweihir ( 88907 )

Not really. Anyone using Outlook can get phished easily. For other MUAs it is more difficult, for some a lot more difficult. For good ones you have to convince the operator to do something obviously stupid.

Re: (Score:2)

by The-Ixian ( 168184 )

Timing is everything.

If the circumstances are conducive to it, even the most paranoid person can get phished in a moment of distraction.

A famous, recent(ish) example is the operator of HIBP, who mistakenly fell for a credential phish because he was distracted and/or tired and the communication was something that he wasn't surprised by in the moment.

[1]https://www.malwarebytes.com/b... [malwarebytes.com]

[1] https://www.malwarebytes.com/blog/news/2025/03/security-expert-troy-hunt-hit-by-phishing-attack

Re: (Score:2)

by gweihir ( 88907 )

This is not about eliminating the problem. It is about making it so unlikely to happen that the bad guys give up. And we are very far from that, especially on Outlook.

Re: (Score:2)

by gweihir ( 88907 )

I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.

And yes, there is reasons for having that connection and it is not only convenience. Unless you want to start digging for dedicated fiber connections all over the country at huge cost?

Re: (Score:2)

by SlashbotAgent ( 6477336 )

> Unless you want to start digging for dedicated fiber connections all over the country at huge cost?

Would it cost more to bury that dedicated fiber with the pipes? Would it be a huge cost to build out your own wireless network, like many power companies do?

There are still many water utilities serving area with a million or more customers that do not have ANY infrastructure connected to the internet. Back office and billing, sure. Infrastructure, is not connected. How ever do they manage? They manage just fine.

Let me restate for the hard of hearing and the hard of feeling, no critical infrastructure such a

Re: (Score:2)

by tlhIngan ( 30335 )

> Would it cost more to bury that dedicated fiber with the pipes? Would it be a huge cost to build out your own wireless network, like many power companies do?

> There are still many water utilities serving area with a million or more customers that do not have ANY infrastructure connected to the internet. Back office and billing, sure. Infrastructure, is not connected. How ever do they manage? They manage just fine.

> Let me restate for the hard of hearing and the hard of feeling, no critical infrastructure such a

Re: (Score:2)

by SlashbotAgent ( 6477336 )

Do you know of an SDR means of decoding the new iTron meters?

I used to be able to listen to my and my neighbors' iTron meter broadcasts. But, then the power company upgraded the meters and I haven't figured out how to receive nor decode the new meters.

Re: (Score:2)

by gweihir ( 88907 )

If your pipes are already in the ground and good for another 50 years? Yes. The cost makes this completely unworkable.

Re: (Score:2)

by Ol Olsoc ( 1175323 )

> I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.

This. The bad guys and gals go after the low hanging fruit. And there is so. damned. much. of. it.

I've long said that a company - especially one involved with essential infrastructure, should have a head of IT with C-Suite level authority. And the compliance chops to go with it.

And while small companies - water in this case - might not have the money to hire such a person, if they have to use software, it comes from somewhere. So "somewhere" needs to be responsible and in the loop. If that's too muc

Re: (Score:2)

by gweihir ( 88907 )

The "small utility problem" can be solved. C-level CISO "as a service" or part time is entirely doable. You just need to want to do it.

Re: (Score:2)

by MachineShedFred ( 621896 )

So you've never heard of social engineering, which can breach airgapped systems.

Minnesota (Score:2)

by PPH ( 736903 )

"Land of 10,000 Lakes". So, who cares? Just grab a bucket.

Wrong headline (Score:4, Insightful)

by gweihir ( 88907 )

A better one would be "More than 30 Minnesota water systems have IT security that completely sucks".

Seriously, without liability (including personal one) and strict qualification requirements, the total crap-show that IT security is today will continue. And not only for critical infrastructure.

Re: (Score:3)

by Fly Swatter ( 30498 )

If it's connected to the internet, the security will eventually be found to suck. The solution is air gap and private network (but even then, it's connected to a network between buildings so security will eventually be found to suck).

Re: (Score:2)

by gweihir ( 88907 )

Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.

Re: (Score:2)

by Ol Olsoc ( 1175323 )

> Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.

You know - I'm amazed at how many in here - a site supposedly of the computer savvy - think that if you are on the internet at all, you are pwned. Using good security (and no, Windows Defender and Firewall is obviously not good security) you can be pretty safe.

And before anyone chimes in on how no internet facing system is safe, it is true that if it can be written, it can be compromised. But that's not the point. The point is that about 70 percent of setups have piss-poor security. So the hackers go

Re: (Score:2)

by gweihir ( 88907 )

Pretty much, yes. Although very simple systems, designed carefully, can achieve security that cannot practically be broken IMO. But let's not get into that. The point is that if you have good, state-of-the-art security on your systems, designed and operated with actual understanding, you very likely will not get attacked or not get attacked that way.

Re: (Score:2)

by Fly Swatter ( 30498 )

State of the art doesn't matter, if there happens to be a low thinking worker on the payroll, they get social engineered. But since you are still on the internet that social engineering opens a hole that may not even be used for several years and that employee is long gone. Also we can not forget that managers like outsourcing to third parties on the other side of the world that doesn't have security worth the paper it is written upon.

So no other state noticed? (Score:2)

by laughingskeptic ( 1004414 )

I doubt Minnesota was specifically targeted; they are simply the first state to notice that multiple attacks occurred.

Uh... (Score:1)

by Narcocide ( 102829 )

Guys? Any chance this was related to [1]this [slashdot.org]?

[1] https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face

Re: (Score:2)

by PPH ( 736903 )

Yes. The AIs have figured out that if they can kill off the meatsacks competing for water supplies by poisoning them, they'll have more for their data center cooling needs.

Coincidence? (Score:2)

by WankerWeasel ( 875277 )

Funny, right around the time Elon sued the state because they're banning AI fake porn of real people and children.

OpenAI again? (Score:1)

by JoshZK ( 9527547 )

I mean, I'll say it if no one else is.

did anyone check... (Score:2)

by friesofdoom ( 3817155 )

... the open ai logs?

"What if" is a trademark of Hewlett Packard, so stop using it in your
sentences without permission, or risk being sued.