---
title: "The Minnesota Water Attacks: Why Connectivity I… | Firevault"
url: https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk
description: "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure…"
lang: en-GB
---

Insight · Industry Insight · 31 July 2026

# The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

5 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk&text=The%20Minnesota%20Water%20Attacks%3A%20Why%20Connectivity%20Is%20Becoming%20Critical%20Infrastructure%27s%20Biggest%20Risk%0A%0AMore%20than%2030%20US%20water%20and%20wastewater%20utilities%20were%20targeted%20in%20a%20coordinated%20cyber%20attack%20on%20operational%20technology.%20The%20lesson%20for%20critical%20infrastructure%20is%20that%20unnecessary%20connectivity%20is%20now%20the%20risk%20itself.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk

Image: Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window (https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg)

Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window

Why it matters

## What this means for organisations holding critical data

Original reporting

**Reuters** — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani.

Syndicated by Yahoo News Canada, 28 July 2026.

View the original Reuters article (https://ca.news.yahoo.com/minnesota-officials-disclose-coordinated-cyberattack-223502118.html)

When Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident and the suspected threat actors. As further details emerged from the FBI and CISA, it became clear that this was not simply another cyber attack. It was a coordinated attempt to disrupt operational technology that controls essential services.

The significance of this incident goes beyond the water sector. It reinforces a growing trend in which attackers are targeting the systems that keep organisations operating, rather than concentrating solely on the information those systems contain. While the affected utilities maintained safe drinking water by switching to manual operations, the attacks demonstrate how exposed internet-connected operational technology can become when connectivity is not carefully managed.

## What Happened

Reporting indicates a coordinated campaign against more than 30 water and wastewater utilities, with human machine interfaces and programmable logic controllers reachable from the public internet among the exposed assets. Minnesota IT Services worked alongside federal partners as the picture developed, and the FBI and CISA issued guidance to operators.

Critically, no unsafe drinking water was reported. Utilities fell back to manual operation, which is the clearest illustration of the point that follows. Continuity was preserved not by the digital control layer, but by the ability to operate without it.

## Why Operational Technology Is the Target

Data theft creates a negotiation. Disruption of operational technology creates a crisis. Attackers understand that a water utility, an energy operator or a manufacturer under pressure to restore service has a very different risk calculus to an organisation managing a data exposure.

Much of the operational technology in service today was designed for isolated networks and long service lives. Remote access, telemetry and vendor support brought that equipment onto routable networks over time, often without the authentication, patching cadence or monitoring that modern IT assumes as standard. The result is a large population of long-lived devices that were never designed to face the internet.

## Connectivity as the Risk Surface

CISA has been consistent on this point. Removing unnecessary internet connectivity from operational technology should be a priority wherever it is possible. That guidance is not a rejection of digital transformation. It is a recognition that every connection is a standing decision that has to be justified, reviewed and, where the justification is weak, reversed.

The same logic applies in the United Kingdom. The NCSC Cyber Assessment Framework asks operators to demonstrate that they understand their assets, control access to them and can maintain essential functions during a cyber incident. Reducing exposure is a legitimate control, not an admission that defence has failed.

## Continuity Depends on Being Able to Operate Offline

The Minnesota utilities kept water flowing because staff could run the plant manually. Most organisations do not have an equivalent fallback for their data. If the primary systems are encrypted, tampered with or taken offline, recovery depends entirely on whether a clean, verifiable copy exists somewhere the attacker could not reach.

A copy held on a connected network shares the fate of that network. A copy held on a physically disconnected system does not. That distinction is the whole argument for Offline Secure Storage (https://fire-vault.com/offline-secure-storage)®: the recovery data sits at Layer 1, physically separated, so an attacker with full control of the production estate still cannot alter or delete it.

## Firevault Insight

This incident highlights a broader shift in cyber security. Protecting connected systems remains essential, but resilience increasingly depends on deciding which systems need to be connected in the first place. Reducing unnecessary connectivity, maintaining physical control over operational technology and designing for continuity are becoming just as important as firewalls, monitoring and endpoint protection.

Mark Fermor, Founder of Firevault, puts it plainly. The organisations that recovered fastest in 2026 were not the ones with the most tooling. They were the ones that had already decided which systems and which data did not need to be reachable at all.

## Key Takeaways

- **Exposure is a decision.** Every internet-facing operational technology asset should have a documented reason to be reachable, reviewed on a schedule.
- **Manual fallback is a control.** The utilities kept services running because people could operate the plant without the digital layer. Test the equivalent for your own critical processes.
- **Recovery data must be out of reach.** Immutability policies enforced by connected software can be reconfigured by an attacker with sufficient privilege. Physical disconnection cannot.
- **Regulators are already asking.** CAF outcomes and NIS-derived duties expect evidence of asset understanding, access control and continuity, not just perimeter defence.
- **Start with the crown jewels.** Identify the small set of data and configuration needed to rebuild, and hold a gold copy offline.

_Sources: Reuters, Minnesota IT Services, FBI and CISA._

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://ca.news.yahoo.com/minnesota-officials-disclose-coordinated-cyberattack-223502118.html)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Industry Insight

### Morgan Stanley email error exposed an internal list of more than 100 potential deals

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

25 Sept 2026 6 min
https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026

Industry Insight

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min
https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity

Industry Insight

### Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

6 Aug 2026 4 min
https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough

Industry Insight

### Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident

Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy's BBC reporting.

29 Jul 2026 4 min
https://fire-vault.com/news/rogue-ai-agents-hugging-face-opinion-2026

Industry Insight

### CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery

Insights from Mark Fermor on OT, ICS, and the underlying storage layer.

7 May 2026 7 min
https://fire-vault.com/news/cisa-ci-fortify-isolation-recovery-firevault

Industry Insight

### Data Integrity Attacks and Air Gap Defence

Data integrity attacks, a stealthier cousin to traditional ransomware, are on the rise, posing a significant threat to organisational trust and operational continuity. This article explores the growing danger of data manipulation and highlights how physically air-gapped storage offers an uncompromised defence.

21 Feb 2026 5 min
https://fire-vault.com/news/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#webpage",
    "url": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk",
    "name": "The Minnesota Water Attacks: Why Connectivity I…",
    "description": "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk",
        "item": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk",
    "description": "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.",
    "url": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-31T07:08:56.803563+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk"
    },
    "inLanguage": "en-GB",
    "articleSection": "Industry Insight",
    "wordCount": 822,
    "keywords": "Industry Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Original reporting Reuters — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani. Syndicated by Yahoo News Canada, 28 July 2026. View the original Reuters article When Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident ",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "What happened in the Minnesota water utility cyber attacks?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "More than 30 US water and wastewater utilities were targeted in a coordinated campaign against internet-exposed operational technology. Affected utilities switched to manual operations and no unsafe drinking water was reported."
        }
      },
      {
        "@type": "Question",
        "name": "Why are attackers targeting operational technology rather than data?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Disrupting operational technology creates immediate pressure to restore essential services, which gives attackers greater leverage than data theft alone."
        }
      },
      {
        "@type": "Question",
        "name": "How does offline storage help critical infrastructure operators?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "A physically disconnected copy of critical data and system configuration cannot be encrypted or deleted by an attacker who controls the production network, so recovery remains possible during an active incident."
        }
      }
    ]
  }
]
```