About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>OT Attacks >Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage

Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage

What has been suspected to be a coordinated cyberattack impacted operational technology (OT) systems at dozens of water utilities across Minnesota on July 26 and 27, prompting a joint state and federal response. According to Minnesota IT Services (MNIT), more than 30 community water systems were hit.

Several affected cities including, Maple Plain, Braham, South St. Paul, and Plymouth, disclosed that some automated control functions were disrupted. In most cases, utilities activated contingency procedures and kept water and wastewater operations running. Every city that issued a statement stressed that drinking water remained safe.

The most disruptive case was in Braham, which briefly took its water plant offline and asked residents to limit water use. The city reported that the intruders shut down its operating controls, which in turn took the well and water treatment plant offline until staff could intervene.

Cellular/Wireless Connection?

One detail is drawing particular attention from OT security practitioners: Plymouth stated that the impact was “limited to equipment connected via cellular communications within the system.”

That points to a class of assets many utilities underestimate. Remote sites like water towers, lift stations, and pump stations frequently reach back to the SCADA system over cellular modems, and those secondary or alternative communication links are routinely left out of risk and vulnerability assessments. Denis Calderone, CTO of Suzu Labs, noted that because industrial networks are often built out by integrators, these cellular paths are especially easy to overlook. He pointed out that one affected city has now asked for its vulnerability study to be reevaluated — and suggested that study may never have accounted for those cellular connections in the first place.

The concern extends well beyond Minnesota. Seemant Sehgal, founder and CEO of BreachLock, argued that investigators need to identify the common thread across the incidents, because the same weakness almost certainly exists in water infrastructure elsewhere in the country.

The consequences that matter to operators

Harry Thomas, CTO and co-founder of OT security firm Frenos, framed the incidents less around attribution and more around operational impact. Drawing on the MITRE ATT&CK for ICS framework, he described how attacks like these can produce denial or loss of view, denial or loss of control, and manipulation of view or control — a physical process may keep running even when operators can no longer see it, influence it, or trust what their screens are reporting. From there, he warned, an incident can escalate toward loss of availability, safety, or physical damage. Manipulation is especially dangerous, because the process may be in a very different state than what operators are being shown.

An open question about the timing

Attribution remains unresolved. The incidents landed shortly after the U.S. government warned critical infrastructure operators about Iran-linked activity targeting ICS devices from Siemens, Rockwell Automation, and Schneider Electric. Iranian threat groups such as CyberAv3ngers and Handala would fit the profile, and in the 2020 attacks on Israeli water facilities, Iran-linked actors gained entry through vulnerable cellular routers. Still, investigators have made no formal attribution.

That uncertainty is fueling a pointed question from the OT community. Joe Langill, a veteran industrial control systems security expert, raised the possibility that the attack was deliberately timed to coincide with the same-day T-Mobile outage. He asked whether analysts had considered that the Minnesota attack was “coordinated with the T-Mobile outage for 5G services during the same time frame,” pointing to a structural reason it belongs on their radar: “a LOT of water districts have moved to cellular networks for ICS endpoints across large geo areas,” he wrote, often at “entities with limited budgets for advanced security controls.”

The timing is interesting. On July 27, T-Mobile suffered one of the year’s largest single-carrier disruptions, with peak outage reports topping 140,000 and phones across multiple states (Minnesota among them) dropping into SOS mode before service was restored the following day.

Langill also suggested the damage could have been far greater in more experienced hands and warned how little stands in an attacker’s way once they reach these endpoints: “Get me on the network and I will own just about any system that does not have endpoint security appliances,” he wrote. Langill’s question underscores how tangled timing, connectivity, and intent become when large fleets of lightly secured cellular assets are in play.

Whatever the final attribution, the Minnesota incidents are a reminder that the communication paths into remote OT assets, especially cellular links added by integrators and forgotten by everyone else, deserve the same scrutiny as the control systems themselves.