---
title: "The Minnesota Water Attacks: Why Connectivity I… | Firevault"
description: "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#webpage",
      "url": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk",
      "name": "The Minnesota Water Attacks: Why Connectivity I…",
      "description": "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk",
          "item": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk",
      "description": "More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.",
      "url": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/hero-images/minnesota-water-attacks-2026-vibrant.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-31T07:08:56.803563+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk"
      },
      "inLanguage": "en-GB",
      "articleSection": "Industry Insight",
      "wordCount": 822,
      "keywords": "Industry Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Original reporting Reuters — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani. Syndicated by Yahoo News Canada, 28 July 2026. View the original Reuters article When Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened in the Minnesota water utility cyber attacks?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "More than 30 US water and wastewater utilities were targeted in a coordinated campaign against internet-exposed operational technology. Affected utilities switched to manual operations and no unsafe drinking water was reported."
          }
        },
        {
          "@type": "Question",
          "name": "Why are attackers targeting operational technology rather than data?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Disrupting operational technology creates immediate pressure to restore essential services, which gives attackers greater leverage than data theft alone."
          }
        },
        {
          "@type": "Question",
          "name": "How does offline storage help critical infrastructure operators?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A physically disconnected copy of critical data and system configuration cannot be encrypted or deleted by an attacker who controls the production network, so recovery remains possible during an active incident."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What HappenedWhy Operational Technology Is th…Connectivity as the Risk SurfaceContinuity Depends on Being Able…Firevault InsightKey TakeawaysMore Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · Industry Insight · 31 July 2026 

# The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk&text=The%20Minnesota%20Water%20Attacks%3A%20Why%20Connectivity%20Is%20Becoming%20Critical%20Infrastructure's%20Biggest%20Risk%0A%0AMore%20than%2030%20US%20water%20and%20wastewater%20utilities%20were%20targeted%20in%20a%20coordinated%20cyber%20attack%20on%20operational%20technology.%20The%20lesson%20for%20critical%20infrastructure%20is%20that%20unnecessary%20connectivity%20is%20now%20the%20risk%20itself.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk)[](mailto:?subject=The%20Minnesota%20Water%20Attacks%3A%20Why%20Connectivity%20Is%20Becoming%20Critical%20Infrastructure's%20Biggest%20Risk&body=More%20than%2030%20US%20water%20and%20wastewater%20utilities%20were%20targeted%20in%20a%20coordinated%20cyber%20attack%20on%20operational%20technology.%20The%20lesson%20for%20critical%20infrastructure%20is%20that%20unnecessary%20connectivity%20is%20now%20the%20risk%20itself.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fminnesota-water-attacks-connectivity-critical-infrastructure-risk)

![Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window](/hero-images/minnesota-water-attacks-2026-vibrant.jpg)

Water treatment plant control room at night with an ageing SCADA terminal, a manual valve handwheel and settling tanks visible through the window

Why it matters

## What this means for organisations holding critical data

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

In this analysis

1.  01 [What Happened](#section-0)
2.  02 [Why Operational Technology Is th…](#section-1)
3.  03 [Connectivity as the Risk Surface](#section-2)
4.  04 [Continuity Depends on Being Able…](#section-3)
5.  05 [Firevault Insight](#section-4)

**On this page**[What Happened](#section-0)[Why Operational Technology Is th…](#section-1)[Connectivity as the Risk Surface](#section-2)[Continuity Depends on Being Able…](#section-3)[Firevault Insight](#section-4)

Original reporting

**Reuters** — AJ Vicens in Detroit, with additional reporting by Raphael Satter in Washington. Edited by Sanjeev Miglani.

Syndicated by Yahoo News Canada, 28 July 2026.

[View the original Reuters article](https://ca.news.yahoo.com/minnesota-officials-disclose-coordinated-cyberattack-223502118.html)

When Reuters first reported that more than 30 US water and wastewater utilities had been targeted in a coordinated cyber attack, the immediate focus was on the scale of the incident and the suspected threat actors. As further details emerged from the FBI and CISA, it became clear that this was not simply another cyber attack. It was a coordinated attempt to disrupt operational technology that controls essential services.

The significance of this incident goes beyond the water sector. It reinforces a growing trend in which attackers are targeting the systems that keep organisations operating, rather than concentrating solely on the information those systems contain. While the affected utilities maintained safe drinking water by switching to manual operations, the attacks demonstrate how exposed internet-connected operational technology can become when connectivity is not carefully managed.

## What Happened

Reporting indicates a coordinated campaign against more than 30 water and wastewater utilities, with human machine interfaces and programmable logic controllers reachable from the public internet among the exposed assets. Minnesota IT Services worked alongside federal partners as the picture developed, and the FBI and CISA issued guidance to operators.

Critically, no unsafe drinking water was reported. Utilities fell back to manual operation, which is the clearest illustration of the point that follows. Continuity was preserved not by the digital control layer, but by the ability to operate without it.

## Why Operational Technology Is the Target

Data theft creates a negotiation. Disruption of operational technology creates a crisis. Attackers understand that a water utility, an energy operator or a manufacturer under pressure to restore service has a very different risk calculus to an organisation managing a data exposure.

Much of the operational technology in service today was designed for isolated networks and long service lives. Remote access, telemetry and vendor support brought that equipment onto routable networks over time, often without the authentication, patching cadence or monitoring that modern IT assumes as standard. The result is a large population of long-lived devices that were never designed to face the internet.

## Connectivity as the Risk Surface

CISA has been consistent on this point. Removing unnecessary internet connectivity from operational technology should be a priority wherever it is possible. That guidance is not a rejection of digital transformation. It is a recognition that every connection is a standing decision that has to be justified, reviewed and, where the justification is weak, reversed.

The same logic applies in the United Kingdom. The NCSC Cyber Assessment Framework asks operators to demonstrate that they understand their assets, control access to them and can maintain essential functions during a cyber incident. Reducing exposure is a legitimate control, not an admission that defence has failed.

## Continuity Depends on Being Able to Operate Offline

The Minnesota utilities kept water flowing because staff could run the plant manually. Most organisations do not have an equivalent fallback for their data. If the primary systems are encrypted, tampered with or taken offline, recovery depends entirely on whether a clean, verifiable copy exists somewhere the attacker could not reach.

A copy held on a connected network shares the fate of that network. A copy held on a physically disconnected system does not. That distinction is the whole argument for [Offline Secure Storage](/offline-secure-storage)®: the recovery data sits at Layer 1, physically separated, so an attacker with full control of the production estate still cannot alter or delete it.

## Firevault Insight

This incident highlights a broader shift in cyber security. Protecting connected systems remains essential, but resilience increasingly depends on deciding which systems need to be connected in the first place. Reducing unnecessary connectivity, maintaining physical control over operational technology and designing for continuity are becoming just as important as firewalls, monitoring and endpoint protection.

Mark Fermor, Founder of Firevault, puts it plainly. The organisations that recovered fastest in 2026 were not the ones with the most tooling. They were the ones that had already decided which systems and which data did not need to be reachable at all.

## Key Takeaways

-   **Exposure is a decision.** Every internet-facing operational technology asset should have a documented reason to be reachable, reviewed on a schedule.
-   **Manual fallback is a control.** The utilities kept services running because people could operate the plant without the digital layer. Test the equivalent for your own critical processes.
-   **Recovery data must be out of reach.** Immutability policies enforced by connected software can be reconfigured by an attacker with sufficient privilege. Physical disconnection cannot.
-   **Regulators are already asking.** CAF outcomes and NIS-derived duties expect evidence of asset understanding, access control and continuity, not just perimeter defence.
-   **Start with the crown jewels.** Identify the small set of data and configuration needed to rebuild, and hold a gold copy offline.

_Sources: Reuters, Minnesota IT Services, FBI and CISA._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://ca.news.yahoo.com/minnesota-officials-disclose-coordinated-cyberattack-223502118.html)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![When Access Fails: Continuity Needs Offline Secure Storage](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

Industry Insight 

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min 







](/news/when-the-grid-fails-offline-secure-storage-business-continuity)[

![Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation](/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg)

Industry Insight 

### Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

6 Aug 2026 4 min 







](/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough)[

![Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident](/hero-images/rogue-ai-agents-2026-vibrant.jpg)

Industry Insight 

### Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident

Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy's BBC reporting.

29 Jul 2026 4 min 







](/news/rogue-ai-agents-hugging-face-opinion-2026)[

![CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery](/__l5e/assets-v1/a89fcfee-ebb3-4b8f-be73-99ddac829a76/cisa-ci-fortify-isolation-recovery-1778147922771-2x.jpg)

Industry Insight 

### CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery

Insights from Mark Fermor on OT, ICS, and the underlying storage layer.

7 May 2026 7 min 







](/news/cisa-ci-fortify-isolation-recovery-firevault)[

![Data Integrity Attacks and Air Gap Defence](/__l5e/assets-v1/2afceeb3-5499-4aa5-9b5c-e555af9b8ab8/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence-1771693250462-2x.jpg)

Industry Insight 

### Data Integrity Attacks and Air Gap Defence

Data integrity attacks, a stealthier cousin to traditional ransomware, are on the rise, posing a significant threat to organisational trust and operational continuity. This article explores the growing danger of data manipulation and highlights how physically air-gapped storage offers an uncompromised defence.

21 Feb 2026 5 min 







](/news/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence)[

![Firmware Attacks and the Air Gap Defence](/__l5e/assets-v1/05135422-b1ae-4dcf-8de5-66b7067ec7ae/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative-1771434041117-2x.jpg)

Industry Insight 

### Firmware Attacks and the Air Gap Defence

Firmware attacks are a sophisticated and increasingly prevalent threat, capable of bypassing traditional security measures. This article explores the growing danger of these low-level compromises and highlights the critical role of physical air-gapped storage in providing an unbreachable last line of defence.

18 Feb 2026 5 min 







](/news/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)