Are Minnesota’s Water Systems Safe From Cyberattacks?

Are Minnesota’s Water Systems Safe From Cyberattacks?

Malik Haidar is a veteran of the cybersecurity trenches, having spent decades defending the digital infrastructure of some of the world’s largest multinational corporations. His career has been defined by a unique ability to bridge the gap between complex technical analytics and the high-stakes reality of business operations, ensuring that security is never just an afterthought. Today, we sit down with Malik to dissect the recent coordinated assault on Minnesota’s water infrastructure—an event that saw over 30 systems compromised in a single weekend. We explore the vulnerabilities inherent in our aging operational technology, the signature tactics of state-sponsored actors, and the massive logistical effort required to secure a state’s most vital resource when the taps are at risk of running dry.

The following discussion centers on the tactical nuances of the July attacks, the specific vulnerabilities found in programmable logic controllers and cellular modems, and the massive multi-agency response triggered by these events. We delve into the intersection of physical utility operations and digital defense, looking at how cities from Braham to Plymouth managed to keep the water flowing during a crisis, while analyzing the broader implications of synchronized threats against critical infrastructure.

When a water plant suddenly goes offline or cellular communications fail at critical sites like water towers, what is the immediate psychological and operational reality for the teams on the ground?

The atmosphere in a control room during a sudden outage is one of controlled urgency shadowed by a deep sense of vulnerability. In Braham, when the water plant went offline entirely on July 26, the silence of the machinery was likely more deafening than the usual hum of treatment. You have operators who are suddenly forced to ask residents to minimize water use, which is a stressful public-facing admission that the system is failing. In Plymouth, they dealt with cellular communications failing at two water towers and multiple wastewater lift stations, forcing teams to scramble into manual operation mode. It’s a visceral, hands-on battle where you are physically checking valves and gauges while knowing that an invisible adversary has reached into your system from across the globe.

How do you interpret the fact that over 30 different systems were hit across July 26 and 27, and what does this “coordinated” timing tell us about the adversary?

The sheer scale—targeting more than 30 water systems in a 48-hour window—screams of a scripted, highly organized campaign rather than a series of opportunistic breaches. When MNIT Assistant Commissioner John Israel speaks of a “whole-of-government” response, he is reacting to the fact that these incidents shared common characteristics in their timing, methods of access, and the specific infrastructure targeted. This suggests the attackers had a pre-compiled list of targets and a playbook designed to overwhelm local response capabilities simultaneously. By hitting so many locations at once, they force state agencies like MNIT and federal partners like the FBI and CISA to spread their resources thin, making containment and forensic investigation much more complex.

The reports mention vulnerabilities in automated utility controls and programmable logic controllers from manufacturers like Rockwell or Siemens. Why are these specific components such attractive targets for groups like CyberAv3ngers?

These programmable logic controllers, or PLCs, are the literal brains of our physical world; they control the flow, the chemicals, and the pressure that keep our water safe and moving. Groups like the CyberAv3ngers, often linked to the IRGC-CEC, target these devices because they frequently sit on the edge of the network with internet-facing interfaces that lack robust authentication. Just four days before the Minnesota hits, federal agencies warned that actors were exfiltrating project files and manipulating human-machine interfaces to disable shutdown and alarm logic. When an attacker can change the logic of a pump or hide a failure from the HMI, they aren’t just stealing data; they are potentially creating physical catastrophes that can take weeks to remediate.

In the case of Maple Plain and South St. Paul, services were maintained despite the attacks. What does this reveal about the resilience of manual overrides versus automated systems?

Resilience in critical infrastructure often comes down to the “human in the loop” who can pivot when the automation fails. Maple Plain had to declare a local state of emergency to support their response, but they kept the water flowing because they didn’t rely solely on the compromised automated utility controls. This highlights a critical lesson: while automation provides efficiency, the ability to operate manually is the ultimate safety net. We saw this in Plymouth as well, where despite the cellular communication failures at their towers, they continued operating manually to ensure no service disruption. It’s a grueling way to run a city, requiring constant physical monitoring, but it’s what prevents a cyberattack from becoming a public health crisis.

Given the active investigation by CISA and the FBI, what are the most critical steps utilities must take right now to harden their cellular modems and project files against future exfiltration?

The defensive blueprint provided by CISA is quite specific: you must start by logging all cellular modem connections and strictly restricting controller access to only authorized systems. Operators need to treat their running project files as sacred; they should be regularly inspected for any unauthorized changes that might have been slipped in by an adversary. A very practical, physical step is the use of the physical mode switch on the controller—placing it in “run” mode only after the project files have been thoroughly validated. Furthermore, before any restoration happens after an incident, backups must be validated to ensure you aren’t just re-installing the attacker’s backdoor back into your system.

What is your forecast for the security of municipal infrastructure?

My forecast for municipal infrastructure security is one of increasing friction between aging hardware and sophisticated, state-sponsored cyber-warfare tactics. We are likely to see more “coordinated” campaigns where attackers leverage known vulnerabilities in widely used components from vendors like Schneider Electric or Siemens to hit dozens of targets at once. The “CyberAv3ngers” model of targeting water and wastewater systems is not an anomaly; it is a proof-of-concept that will be refined and repeated. Consequently, I expect to see a mandatory shift toward air-gapping critical controls and a massive federal push for standardized security logging across even the smallest community water systems. The era of “security through obscurity” for small-town utilities is officially over, and the next three years will be a race to harden these systems before the next coordinated window opens.

subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address
subscription-bg
Subscribe to Our Weekly News Digest

Stay up-to-date with the latest security news delivered weekly to your inbox.

Invalid Email Address