Keeper protects over 95,000 organizations, which includes many Fortune 500 enterprises and public sector agencies. The company is quickly emerging as the market standard for AI-native
In late July 2026, over 30 municipal water systems across Minnesota were targeted in coordinated cyber attacks that disrupted the Operational Technology (OT) used to remotely monitor and control water equipment. The attacks initially unfolded on July 26 and 27, striking multiple automated control systems across the state, including those in Plymouth, Braham and South St. Paul. While officials confirmed that the drinking water supply was not compromised, Minnesota IT Services (MNIT) activated the state’s cybersecurity incident response in collaboration with municipal, state and federal partners to investigate the breaches and enhance protections for Critical Infrastructure (CI).
Continue reading to learn the key takeaways from these water-sector cyber attacks, their broader impact on the industry and how Keeper® can help protect CI across industries from cyber threats.
What you should know about the US water cyber attacks
- The attacks targeted internet-connected Programmable Logic Controllers (PLCs), which are remote devices used to monitor and manage water infrastructure, linked to automated control systems in several Minnesota cities.
- Attackers accessed the exposed PLCs and changed their passwords and IP addresses, locking operators out of their systems and causing a loss of monitoring that forced some utilities to switch to manual operations.
- No water supply was reported to have been compromised as a result of these attacks, and officials confirmed that water quality was not impacted.
- This security incident reached beyond Minnesota, with water and wastewater utilities in at least six additional states reporting cyber incidents to the FBI.
The impact of the US water cyber attacks
The national water cyber attacks stand apart from the data breaches that dominate news headlines because, rather than stealing sensitive information, the attackers targeted OT in a clear effort to disrupt CI. The incident was less about theft and more a demonstration of how vulnerable the industrial control systems that keep essential services running can be. By changing passwords and IP addresses on exposed PLCs, the attackers locked operators out of the systems they relied on to monitor and control water equipment, cutting off visibility into how those systems were performing. Several utilities were forced to fall back on manual operations to keep water flowing safely while they worked to regain control.
The bigger picture of this incident is what makes it so concerning. Across the multi-state campaign, federal officials reported more serious consequences in some areas, including boil-water notices and drops in water pressure. Water systems have become attractive targets for cyber attacks because many rely on internet-exposed, remotely managed OT — often connected through devices and modems that are outdated and were never designed with security as a priority. Many utilities, especially smaller municipal systems, are also severely under-resourced when it comes to cybersecurity, lacking the funding and staff needed to secure every connection. As a result, a critical industry that millions of people and businesses depend on every day is being protected by systems that attackers have learned can be relatively easy to reach.
What the water industry can learn from the US water cyber attacks
Although the investigation is ongoing at the time of this writing, these water cyber attacks have already exposed security weaknesses that water and wastewater utilities of all sizes can learn from. This incident demonstrated what can happen when exposed systems, weak credentials and gaps in basic access controls are exploited. For water and wastewater operators, the lessons below are both urgent and achievable.
The risk of internet-exposed OT
The main vulnerability in these attacks was that OT was directly accessible from the public internet. Attackers identified and exploited exposed PLCs and cellular modems, including undocumented devices installed by vendors or operators that were not captured in routine security scans. These forgotten or unmanaged connections gave attackers a direct path into critical systems.
Water utilities should inventory every external connection and assume that unmanaged remote access paths already exist elsewhere in their environment. OT should never be exposed directly to the internet. Instead, operators need secure remote access that creates a protected layer between the public internet and the systems responsible for running CI.
The danger of default and weak credentials
Many PLCs in this attack were protected only by default manufacturer passwords or weak credentials, allowing attackers to log in, change those passwords and lock operators out of their own systems. The main lesson for the water sector is to eliminate all default passwords and enforce strong, unique credentials on every device and account. Default and insecurely shared credentials are among the most common ways attackers get in, yet they are also among the easiest security vulnerabilities to fix.
The importance of network segmentation and offline backups
How Braham, Minnesota, responded to this incident proved the value of thorough preparation, as staff recovered in under 90 minutes. After detecting the compromise, they isolated the impacted system, restored it from a backup and restarted the plant — all while keeping the city’s residents supplied with uninterrupted water service. This demonstrates how effective recovery practices can reduce the impact of an intrusion and turn a potential crisis into a brief disruption.
The key takeaway is to build resilience before an attack happens by segmenting OT from IT systems and the public internet so a breach in one area doesn’t spread to others. With tested, offline backups, operators can restore systems quickly when something goes wrong.
Why smaller utilities are especially vulnerable
CISA has emphasized that attackers are targeting water entities of all sizes, not just large metropolitan areas. This is a major concern since smaller municipal utilities often operate with limited budgets and minimal IT staff, leaving them less prepared to defend against this kind of attack. Smaller utilities should recognize that even the leanest utilities need baseline access controls in place, and they increasingly don’t have to fund it alone. At the federal level, CISA’s State and Local Cybersecurity Grant Program (SLCGP) helps state, local and territorial governments enhance their cybersecurity resilience, and municipal water systems operated by local governments can pursue this funding through their state’s administering agency. Multiple states are starting to step in as well; for example, New York recently announced more than $9 million in cybersecurity grants to help protect water systems statewide. Smaller utilities should actively pursue this kind of funding and assistance to close security gaps before they’re exploited.
How Keeper Security helps protect critical infrastructure against cyber attacks
The recommendations issued by officials in response to these attacks all point to the same underlying need: granular control over access and identity. This is exactly what Keeper’s unified identity security platform is built to provide. With a zero-trust, zero-knowledge architecture, Keeper ensures that access to CI is verified, encrypted and controlled at every step so that even the connections attackers relied on in Minnesota are closed off before they can be exploited.
Secure remote access
The key failure in these attacks was that OT was reachable directly from the public internet. Keeper’s secure remote access for infrastructure removes the need for that risky exposure, giving operators controlled access to PLCs and control systems without leaving them directly exposed to the internet. Instead of relying on insecure modems and exposed devices, remote connections run through a secure, monitored channel with Keeper.
Credential and secrets management
Default or weak credentials can make internet-facing devices easier for attackers to compromise. Keeper’s credential manager helps enforce strong, unique credentials across accounts and replace default passwords that can give attackers an easy way in. By generating and securely storing credentials, Keeper helps close one of the easiest entry points and aligns with official recommendations to replace default passwords with strong, unique ones.
For the machine identities and secrets that run behind the scenes, Keeper Secrets Manager supports automated rotation of API tokens, service accounts and other infrastructure credentials. This is important because even if an attacker does gain unauthorized access, unique and regularly rotated credentials can reduce the risk that a compromised credential can be reused to move across systems.
Privileged Access Management (PAM)
Beyond securing individual credentials, protecting CI means controlling exactly who can reach the systems that run it. KeeperPAM® enforces least-privilege access, so users and vendors only have the access they genuinely need, with session monitoring and control over privileged connections managed through KeeperPAM. Keeper’s capabilities align with official guidance to ensure remote access is mediated, monitored and controlled, and to strictly limit network access to critical control systems, giving operators greater ability to detect and respond to suspicious activity before it escalates.
Secure remote access with Keeper
The national water cyber attacks should remind organizations that no industry is immune to cyber attacks – not even the CI that communities depend on daily. As cyber attacks on water systems spread across state lines, these incidents make it clear that protecting essential services should start with controlling access to the systems that run them. Keeper secures both privileged and remote access with a zero-trust, zero-knowledge architecture that closes off the exposed connections and weak credentials that attackers rely on.
Request a demo of KeeperPAM to see how your organization can protect its most critical infrastructure.