MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure

A press release from MNIT

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27. Minnesota IT Services (MNIT) immediately activated the state’s cybersecurity incident response capabilities. MNIT continues to collaborate with federal, state, local, Tribal, and private-sector partners to investigate the attack, support affected communities, and strengthen the security of Minnesota’s critical infrastructure.

As MNIT cybersecurity teams assess the cyber impacts, they are sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack. MNIT is working closely with Minnesota Department of Public Safety, Bureau of Criminal Apprehension’s Minnesota Fusion Center, Minnesota Department of Health, Minnesota Pollution Control Agency, Cybersecurity and Infrastructure Security Agency, U.S. Environmental Protection Agency, Federal Bureau of Investigation, and local water utilities throughout the response.

The investigation remains active, and responders continue to assess affected systems. The Minnesota Department of Health continues to work directly with affected water systems to help ensure public health remains protected. At this time, they are not aware of any active requests from Minnesota cities to have their residents modify their drinking water usage.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said John Israel, MNIT Assistant Commissioner and Minnesota Chief Information Security Officer. “MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks. This incident demonstrates why Minnesota has invested in strong cybersecurity capabilities and partnerships. Our response worked as intended, enabling agencies at every level of government to rapidly coordinate, contain the incident, and help prevent more serious impacts to critical services.”

  • MNIT activated its incident response capabilities immediately after learning of the attack and continues to:
  • Coordinate technical response activities across government partners.
  • Share threat intelligence and indicators of compromise with affected organizations.
  • Support incident investigation, containment, recovery, and remediation efforts.
  • Monitor for related malicious cyber activity and coordinate with state and federal cybersecurity partners.
  • Provide cybersecurity expertise and technical assistance to affected communities.

Minnesota’s Whole-of-State Cybersecurity Program brings together federal, state, local, Tribal, and critical infrastructure partners to prepare for, respond to, and recover from cyber incidents. By sharing threat intelligence, coordinating technical expertise, and strengthening cyber resilience, MNIT helps protect the essential services Minnesotans rely on every day.

MNIT will continue working with its partners to investigate the incident, support recovery efforts, strengthen cybersecurity protections, and help ensure Minnesota’s critical infrastructure remains secure and resilient. Additional information will be shared as it becomes available.

 

 

This entry was posted in Government, MN, Policy, Security by Ann Treacy. Bookmark the permalink.

About Ann Treacy

Librarian who follows rural broadband in MN and good uses of new technology (blandinonbroadband.org), hosts a radio show on MN music (mostlyminnesota.com), supports people experiencing homelessness in Minnesota (elimstrongtowershelters.org) and helps with social justice issues through Women’s March MN.

Leave a Reply