Jonathan Wrolstad, who teaches cyber threat intelligence at the University of Minnesota's Technological Leadership Institute, joined WCCO Radio this week to unpack what happened when hackers hit the operational technology behind more than 30 Minnesota community water systems on July 26 and 27.
Wrolstad has nearly two decades in threat intelligence and risk management, with stints at Mandiant, Accenture, ExtraHop and Symantec before landing at TLI, where he holds CISM and CISSP certifications and teaches the course ST 8513: Cyber Threat Intelligence. He pointed to a recent federal warning that Iranian-affiliated hackers were targeting critical infrastructure, saying the Minnesota incident matches that exact scenario and predicting more attacks like it over the next year or two.
The attack disabled automated controls at water plants and towers across the state. In Braham, a city of roughly 1,700 people, the disruption knocked the town's well and treatment plant offline entirely; public works crews got the system running again within about two hours. Plymouth lost cellular communications at two water towers and several wastewater lift stations but kept running manually, while South St. Paul and Maple Plain saw automated controls affected — Maple Plain declared a local state of emergency to help manage its response. Officials in every affected city said drinking water quality was never compromised and no customer data was accessed.

Minnesota IT Services activated its statewide cybersecurity incident response, pulling in the Department of Public Safety's Bureau of Criminal Apprehension, the Minnesota Fusion Center, the Department of Health, the Pollution Control Agency, and federal partners including the FBI, CISA and the EPA. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT's assistant commissioner and chief information security officer.
Attribution is still pending a federal investigation, but the timing lines up with a broader campaign researchers have tied to the Iran-linked group CyberAv3ngers, which security researchers say has been exploiting an unpatchable authentication-bypass flaw in widely used Rockwell Automation industrial controllers. The bug, tracked as CVE-2021-22681 and rated 9.8 out of 10 in severity, has no fix coming from Rockwell. The Minnesota attack came just days after federal agencies updated an advisory warning that the same actors had expanded their targeting beyond Rockwell equipment to controllers made by Siemens and Schneider Electric.