The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk
More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.
Article record
Why it matters
What this means for organisations holding critical data
More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.
Original reporting
Reuters — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani.
Syndicated by Yahoo News Canada, 28 July 2026.
View the original Reuters articleWhen Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident and the suspected threat actors. As further details emerged from the FBI and CISA, it became clear that this was not simply another cyber attack. It was a coordinated attempt to disrupt operational technology that controls essential services.
The significance of this incident goes beyond the water sector. It reinforces a growing trend in which attackers are targeting the systems that keep organisations operating, rather than concentrating solely on the information those systems contain. While the affected utilities maintained safe drinking water by switching to manual operations, the attacks demonstrate how exposed internet-connected operational technology can become when connectivity is not carefully managed.
What Happened
Reporting indicates a coordinated campaign against more than 30 water and wastewater utilities, with human machine interfaces and programmable logic controllers reachable from the public internet among the exposed assets. Minnesota IT Services worked alongside federal partners as the picture developed, and the FBI and CISA issued guidance to operators.
Critically, no unsafe drinking water was reported. Utilities fell back to manual operation, which is the clearest illustration of the point that follows. Continuity was preserved not by the digital control layer, but by the ability to operate without it.
Why Operational Technology Is the Target
Data theft creates a negotiation. Disruption of operational technology creates a crisis. Attackers understand that a water utility, an energy operator or a manufacturer under pressure to restore service has a very different risk calculus to an organisation managing a data exposure.
Much of the operational technology in service today was designed for isolated networks and long service lives. Remote access, telemetry and vendor support brought that equipment onto routable networks over time, often without the authentication, patching cadence or monitoring that modern IT assumes as standard. The result is a large population of long-lived devices that were never designed to face the internet.
Connectivity as the Risk Surface
CISA has been consistent on this point. Removing unnecessary internet connectivity from operational technology should be a priority wherever it is possible. That guidance is not a rejection of digital transformation. It is a recognition that every connection is a standing decision that has to be justified, reviewed and, where the justification is weak, reversed.
The same logic applies in the United Kingdom. The NCSC Cyber Assessment Framework asks operators to demonstrate that they understand their assets, control access to them and can maintain essential functions during a cyber incident. Reducing exposure is a legitimate control, not an admission that defence has failed.
Continuity Depends on Being Able to Operate Offline
The Minnesota utilities kept water flowing because staff could run the plant manually. Most organisations do not have an equivalent fallback for their data. If the primary systems are encrypted, tampered with or taken offline, recovery depends entirely on whether a clean, verifiable copy exists somewhere the attacker could not reach.
A copy held on a connected network shares the fate of that network. A copy held on a physically disconnected system does not. That distinction is the whole argument for Offline Secure Storage®: the recovery data sits at Layer 1, physically separated, so an attacker with full control of the production estate still cannot alter or delete it.
Firevault Insight
This incident highlights a broader shift in cyber security. Protecting connected systems remains essential, but resilience increasingly depends on deciding which systems need to be connected in the first place. Reducing unnecessary connectivity, maintaining physical control over operational technology and designing for continuity are becoming just as important as firewalls, monitoring and endpoint protection.
Mark Fermor, Founder of Firevault, puts it plainly. The organisations that recovered fastest in 2026 were not the ones with the most tooling. They were the ones that had already decided which systems and which data did not need to be reachable at all.
Key Takeaways
- Exposure is a decision. Every internet-facing operational technology asset should have a documented reason to be reachable, reviewed on a schedule.
- Manual fallback is a control. The utilities kept services running because people could operate the plant without the digital layer. Test the equivalent for your own critical processes.
- Recovery data must be out of reach. Immutability policies enforced by connected software can be reconfigured by an attacker with sufficient privilege. Physical disconnection cannot.
- Regulators are already asking. CAF outcomes and NIS-derived duties expect evidence of asset understanding, access control and continuity, not just perimeter defence.
- Start with the crown jewels. Identify the small set of data and configuration needed to rebuild, and hold a gold copy offline.
Sources: Reuters, Minnesota IT Services, FBI and CISA.
Sources
Where this reporting comes from
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






