A ransomware attack compromised a server tied to the Minot Water Treatment Plant in North Dakota, affecting the plant’s SCADA environment and forcing operators to switch to manual procedures for about 16 hours. City officials said the plant and related water system facilities remained operational and the water supply stayed safe throughout the incident. The facility serves Minot and surrounding communities through the Northwest Area Water Supply, reaching roughly 80,000 people.
Officials said they unplugged the affected server after discovering the intrusion on March 14 and found only a ransom letter displayed on the screen, with no direct contact from the attackers and no specified payment demand. The city did not pay a ransom, recovery is nearly complete, and the plant is temporarily relying on an older server while a replacement is prepared. The letter has been turned over to the FBI, and the incident adds to mounting concern over cyber threats to U.S. water utilities from both ransomware actors and state-linked campaigns associated with Iran and China.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By the time the incident was publicly reported, recovery was nearly complete. The plant was temporarily operating on an older server while preparing a new replacement system.
The ransom letter recovered from the incident was turned over to the FBI as part of a potential investigation into the attack on the water treatment plant.
City officials said they found a ransom note or letter displayed on the affected server, but it did not include a dollar amount and there was no direct interaction with the attackers. The city did not pay a ransom.
A ransomware attack affected the Minot, North Dakota water treatment plant in March, compromising a server tied to the plant's SCADA environment. Operators disconnected the affected server and shifted to manual procedures and gauge readings for about 16 hours while keeping water service operational and safe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.