July 26-27, 2026 · Coordinated OT Attack

More Than 30 Minnesota Water Systems Were Hit at Once. The Water Stayed Safe. The Controls Did Not.

Over a single weekend, attackers went after the operational technology at more than 30 Minnesota community water systems. One city's treatment plant dropped offline. Another lost telemetry to its water towers and sewer lift stations. Operators kept the water safe by running their plants by hand. State officials say the goal looked like disruption, not money.

Attack window July 26-27, 2026  ·  30-plus systems targeted  ·  4 cities publicly confirmed impact  ·  No attribution released  ·  MNIT · MDH · FBI

What Happened

A coordinated push against control systems at small municipal utilities, inside a 48-hour window.

Scale

30-plus systems, one weekend

Minnesota IT Services says more than 30 community water systems were targeted across July 26 and 27. The state has not said how many of those were actually compromised, as opposed to probed or attempted.

Target

Operational technology, not email

This was not a business-network phishing wave. The activity hit the automated control layer: plant operating controls, tower telemetry, and lift-station communications. That is the layer that moves water.

Motive

Disruption, not extortion

MNIT assistant commissioner and state CISO John Israel: "All signs are pointing to disruption, not trying to get a financial gain or get an actual public impact." No ransom demand has been reported.

Attribution

Nobody has been named

No actor, nation, or access vector has been made public. MNIT is working with state and federal agencies including the FBI. Anyone telling you who did this is ahead of the evidence.

What Actually Broke, City by City

Four Minnesota cities have publicly described impact. Every one of them kept drinking water safe.

Braham

The water plant went offline Monday morning after what the city described as a malicious cyberattack on its computerized operating systems by unknown actors. Operating controls for the well and the treatment plant were disabled. No physical damage and no water-quality problem. Braham is a town of roughly 1,800 people in Isanti County.

Plymouth

Lost cellular communications to two water towers and multiple wastewater lift stations starting late Sunday. Staff ran the system manually. The city stated water levels and quality were unaffected, the water was safe, and residents did not need to change how much they used.

South St. Paul

A cybersecurity incident affected the water utility's technology and its automated controls. Public Works staff maintained normal water and wastewater operations by hand.

Maple Plain

Certain automated control functions were affected. The city maintained normal operations and confirmed the water remained safe to drink.

No boil-water advisory was issued in any affected community. The Minnesota Department of Health was involved in the response, and the state noted that any public-health advisory would come from local officials or state health authorities directly.

Why This One Should Change How You Think About Your Plant

Read the four city summaries again and notice what they have in common. In every case, the water was fine and the controls were not. Operators saved these systems by dropping to manual operation. That is real operational competence, and it is also the entire problem: the automation layer failed and the humans absorbed it.

Three things make this incident more useful than the examples most vendors still quote at you.

It is days old, not years old. Aliquippa was November 2023. Muleshoe was 2024. When a water board hears a 2023 example, the honest reaction is "that was a while ago, and nothing happened to us." July 2026 does not allow that answer.

The motive was disruption, which removes the usual excuse. The most common objection from a small utility is "we are too small to be worth a ransom." That reasoning only protects you from criminals who want money. It offers nothing against an actor whose goal is to make a town's water plant stop working, and by the state's own read, that is what this was.

These were small systems. Braham serves roughly 1,800 people. If your defense is that you are too obscure to target, Braham was more obscure, and it was hit as part of a coordinated set of 30-plus.

One more thing worth saying plainly, because the internet got this wrong within a day: no one has attributed this attack. The pattern of going after internet-reachable control systems at small water utilities is the same pattern federal advisory AA26-097A describes, and that advisory does name Iranian-affiliated actors. Those are two separate facts. Treating the resemblance as an identification is exactly the kind of shortcut that stops people believing a security vendor.

Read the reporting

What To Do This Week

If you run a water or wastewater system, these are the questions this incident should make you ask.

How RedEye Helps You Answer This

The assessment is built to answer the two questions this incident raises: what is exposed, and would you see it.

1

Discovery

We map what of yours is reachable from the internet, including the remote sites and vendor links that never made it onto a drawing.

2

Monitoring

We put visibility on the control network so a change to a setpoint or a controller looks different from a technician doing their job.

3

Threat Hunt

We look for the indicators from current federal advisories, including historical activity that predates the engagement.

4

Report

A prioritized roadmap aligned to EPA priority controls and AWWA guidance, in language your board and your operators can both use.

Would You Have Found Out Before the Plant Stopped?

Free scoping call. We check what of yours is exposed, hunt for current advisory indicators, and show you what an assessment covers. Federal grants may cover the cost.

Schedule Free Scoping Call