A fresh NPR investigation into the water-sector cyberattacks that hit more than 30 Minnesota communities during the Iran war — including Plymouth’s water tower, documented in ONYX’s August 2 coverage — confirms that the operational technology vulnerabilities exploited during those attacks remain unresolved weeks later. The underlying security weaknesses in the industrial control systems that manage water treatment, distribution, and storage are still present. The attack was managed; the vulnerability that made the attack possible was not.

THE SPECIFIC VULNERABILITY — WHY IT PERSISTS
Water utility operational technology (OT) systems — the industrial control systems (SCADA systems) that manage pumps, valves, chemical dosing, and distribution pressure — were not designed with cybersecurity as a primary consideration. Many of these systems were installed 20-30 years ago, when they were isolated from external networks and therefore considered inherently secure. The expansion of internet connectivity and remote access capabilities has connected them to the broader internet without commensurate security upgrades.
The specific challenge: patching and upgrading these systems is not like patching a computer. Water systems run 24/7; they cannot simply be taken offline for updates. The control systems often run on legacy software that is no longer supported by its original manufacturer. And the smaller communities that operate these systems — the 30+ Minnesota communities affected — do not have cybersecurity staff, budgets, or expertise comparable to the scale of the threat they face.
The attack was managed. The vulnerability that made the attack possible was not fixed. The next attack can use the same door.
WHY THE MINNEAPOLIS GEOGRAPHIC CLUSTER IS SIGNIFICANT
ONYX covered the Minneapolis ARTCC failure on August 8 and its connection to the broader infrastructure vulnerability story. The same Minneapolis/Upper Midwest geographic corridor that produced the ATC failure also produced the concentration of water-system attacks. Whether these represent a coordinated targeting of Minnesota infrastructure or coincidental convergence of vulnerabilities in a specific region is a question that federal investigators have not publicly answered.
The geographic concentration suggests either: targeted reconnaissance that identified Minnesota’s specific vulnerability profile; or a broader campaign that happened to find a cluster of exploitable systems in this region. Either explanation has significant implications for how the national infrastructure security community should respond.
WHAT WOULD ACTUALLY FIX IT
▸ Mandatory OT cybersecurity standards for water utilities — EPA and CISA have proposed rules; implementation has been legally challenged by water utility associations
▸ Federal funding for small utilities — communities of under 10,000 people (the majority of US water utilities) lack the budgets to independently upgrade aging control systems
▸ Network segmentation — isolating OT systems from internet-accessible networks is the most effective near-term mitigation; it requires physical and software changes
▸ Incident response capacity — most small water utilities have no cybersecurity incident response plan; the Minnesota attacks revealed response gaps alongside the technical vulnerabilities
WHAT HAPPENS NEXT
▸ EPA and CISA are expected to respond to the NPR investigation with updated guidance
▸ Congressional infrastructure committees will use the NPR findings in ongoing cybersecurity legislation debates
▸ The legal challenge to mandatory OT cybersecurity rules for water utilities is pending; the NPR investigation strengthens the regulatory case
| CONFIDENCE: HIGH | NPR investigation confirming vulnerability persistence is documented. Plymouth water tower attack and 30+ Minnesota communities affected are from prior ONYX August 2 coverage and NPR reporting. OT/SCADA vulnerability context is from established cybersecurity documentation. |
| ⚖️ BIAS CHECK — WHO IS SAYING WHAT | |
| NPR | Accountability journalism confirming that the vulnerability was not fixed; directly serving the public interest |
| EPA / CISA | Will respond defensively; are aware of the vulnerability but facing legal and resource obstacles to mandating fixes |
| Water Utility Associations | Have legally challenged mandatory cybersecurity rules; will push back on any framing that implies negligence |
| Congressional Cybersecurity Advocates | Will use the NPR report to advance mandatory standards legislation |
| Minnesota Communities | 30+ communities whose systems were compromised; the residents of those communities have an interest in knowing the vulnerability persists |
SOURCES
▸ NPR — Minnesota water system cyberattack vulnerability investigation, August 2026
▸ Prior ONYX August 2 coverage — Plymouth water tower, 7-state water system attacks
Q: Are Minnesota’s water supplies safe to drink?
A: The NPR investigation addresses the technical vulnerability in control systems, not current water safety. The attacks documented during the Iran war were managed before causing changes to water treatment that would affect safety. The ongoing vulnerability is to future attacks, not current water quality.
Q: Why can’t the federal government just require fixes?
A: EPA and CISA have proposed mandatory cybersecurity rules for water utilities. The American Water Works Association and other utility associations legally challenged those rules. The regulatory process is ongoing, meaning mandatory standards are not yet in effect.

