Skip to content

South St. Paul, Minnesota, keeps water flowing after cyber incident

Automated utility controls were affected, but officials said drinking water remained safe and water and wastewater operations continued normally.

Aerial view of a white South St. Paul water tower with the city logo, surrounded by trees, homes and a baseball field.
A South St. Paul water tower rises above a residential area and park in the Minnesota city. (City of South St. Paul)
Published:

South St. Paul officials said a cybersecurity incident affected automated controls supporting parts of the Minnesota city’s water utility Monday, but drinking water remained safe and water and wastewater services continued normally.

Public works employees implemented established contingency procedures after the incident was identified early Monday, allowing the city to maintain operations. “Drinking water remains safe,” the city said. Residents did not need to take action.

The disruption affected technology supporting portions of the utility, not the safety of the water supply or the city’s ability to provide water and wastewater services. South St. Paul, a Dakota County community of about 20,500 people immediately south of St. Paul, operates municipal water and wastewater services.

Screenshot of a South St. Paul Facebook post saying a cybersecurity incident affected some automated water utility controls while drinking water and wastewater services remained safe and operational.
South St. Paul said a cybersecurity incident affected automated controls supporting parts of its water utility, but drinking water remained safe and water and wastewater services continued normally. (City of South St. Paul/Facebook)

The city said it was working with technology partners and coordinating with state and federal agencies. Staff continued monitoring the system and working to restore normal automated operations.

The incident occurred the same morning Plymouth and Braham reported cyberattacks affecting water infrastructure. Plymouth said two water towers and several lift stations were affected beginning overnight Sunday, while Braham’s well and water treatment plant briefly went offline.

Plymouth said water remained safe and service continued. Braham’s plant returned to service in less than two hours, and officials there said water quality and safety were not affected. Braham officials said they had been told at least four other communities experienced similar attacks, but they did not identify them or publicly link the incidents to one actor.

Five days before the Minnesota incidents, federal agencies updated an advisory warning that Iran-affiliated actors were targeting internet-connected programmable logic controllers used by U.S. critical infrastructure operators. The agencies said the activity had caused operational disruptions, including erased configurations, manipulated sensor readings and interference with control system interfaces. No agency or affected city has publicly linked the South St. Paul, Plymouth or Braham incidents to that activity.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

The South St. Paul incident also follows a March ransomware attack that disrupted automated controls at the water treatment plant in Minot, North Dakota. Operators took manual readings for about 16 hours while water service remained safe.

South St. Paul is also the third Twin Cities municipality with St. Paul in its name to disclose a cyber incident within a year, after broader incidents in St. Paul and North St. Paul. Officials have not linked the cases.

South St. Paul said water and wastewater service remained reliable while the investigation continued and employees worked to restore normal automated operations.

Officials had not disclosed how the systems were accessed, what equipment or software was affected, whether malware or ransomware was involved, or whether the incident was related to the Plymouth and Braham incidents or the activity described in the federal advisory.

No threat actor or specific attack method had been confirmed. DysruptionHub found no public ransomware claim at the time of publication.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all