Industry Insight·31 July 2026

The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
5 min read
Share
Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window
Industry Insight

Article record

Industry InsightCategory
31 July 2026Published
5 min readReading time
Mark FermorWritten by
Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window

Why it matters

What this means for organisations holding critical data

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

Original reporting

Reuters — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani.

Syndicated by Yahoo News Canada, 28 July 2026.

View the original Reuters article

When Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident and the suspected threat actors. As further details emerged from the FBI and CISA, it became clear that this was not simply another cyber attack. It was a coordinated attempt to disrupt operational technology that controls essential services.

The significance of this incident goes beyond the water sector. It reinforces a growing trend in which attackers are targeting the systems that keep organisations operating, rather than concentrating solely on the information those systems contain. While the affected utilities maintained safe drinking water by switching to manual operations, the attacks demonstrate how exposed internet-connected operational technology can become when connectivity is not carefully managed.

What Happened

Reporting indicates a coordinated campaign against more than 30 water and wastewater utilities, with human machine interfaces and programmable logic controllers reachable from the public internet among the exposed assets. Minnesota IT Services worked alongside federal partners as the picture developed, and the FBI and CISA issued guidance to operators.

Critically, no unsafe drinking water was reported. Utilities fell back to manual operation, which is the clearest illustration of the point that follows. Continuity was preserved not by the digital control layer, but by the ability to operate without it.

Why Operational Technology Is the Target

Data theft creates a negotiation. Disruption of operational technology creates a crisis. Attackers understand that a water utility, an energy operator or a manufacturer under pressure to restore service has a very different risk calculus to an organisation managing a data exposure.

Much of the operational technology in service today was designed for isolated networks and long service lives. Remote access, telemetry and vendor support brought that equipment onto routable networks over time, often without the authentication, patching cadence or monitoring that modern IT assumes as standard. The result is a large population of long-lived devices that were never designed to face the internet.

Connectivity as the Risk Surface

CISA has been consistent on this point. Removing unnecessary internet connectivity from operational technology should be a priority wherever it is possible. That guidance is not a rejection of digital transformation. It is a recognition that every connection is a standing decision that has to be justified, reviewed and, where the justification is weak, reversed.

The same logic applies in the United Kingdom. The NCSC Cyber Assessment Framework asks operators to demonstrate that they understand their assets, control access to them and can maintain essential functions during a cyber incident. Reducing exposure is a legitimate control, not an admission that defence has failed.

Continuity Depends on Being Able to Operate Offline

The Minnesota utilities kept water flowing because staff could run the plant manually. Most organisations do not have an equivalent fallback for their data. If the primary systems are encrypted, tampered with or taken offline, recovery depends entirely on whether a clean, verifiable copy exists somewhere the attacker could not reach.

A copy held on a connected network shares the fate of that network. A copy held on a physically disconnected system does not. That distinction is the whole argument for Offline Secure Storage®: the recovery data sits at Layer 1, physically separated, so an attacker with full control of the production estate still cannot alter or delete it.

Firevault Insight

This incident highlights a broader shift in cyber security. Protecting connected systems remains essential, but resilience increasingly depends on deciding which systems need to be connected in the first place. Reducing unnecessary connectivity, maintaining physical control over operational technology and designing for continuity are becoming just as important as firewalls, monitoring and endpoint protection.

Mark Fermor, Founder of Firevault, puts it plainly. The organisations that recovered fastest in 2026 were not the ones with the most tooling. They were the ones that had already decided which systems and which data did not need to be reachable at all.

Key Takeaways

  • Exposure is a decision. Every internet-facing operational technology asset should have a documented reason to be reachable, reviewed on a schedule.
  • Manual fallback is a control. The utilities kept services running because people could operate the plant without the digital layer. Test the equivalent for your own critical processes.
  • Recovery data must be out of reach. Immutability policies enforced by connected software can be reconfigured by an attacker with sufficient privilege. Physical disconnection cannot.
  • Regulators are already asking. CAF outcomes and NIS-derived duties expect evidence of asset understanding, access control and continuity, not just perimeter defence.
  • Start with the crown jewels. Identify the small set of data and configuration needed to rebuild, and hold a gold copy offline.

Sources: Reuters, Minnesota IT Services, FBI and CISA.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Industry Insight31 July 20265 min read

The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy