- What: More than 30 Minnesota community water systems were targeted in a coordinated attack on operational technology across July 26 and 27, 2026. This hit the control layer, not the business network.
- Impact: Braham's well and treatment-plant controls were disabled and the plant went offline. Plymouth lost cellular communications to two water towers and multiple wastewater lift stations. South St. Paul and Maple Plain lost automated control functions. All four ran manually, drinking water stayed safe, and no boil advisories were issued.
- Fix / mitigation: Find what of yours answers the internet, including vendor-installed links at towers and lift stations. Get visibility on the control network so a controller change looks different from a technician. Practice manual operation on purpose.
- Who's at risk: Small and mid-size water and wastewater utilities. Braham serves roughly 1,800 people. State CISO John Israel said the signs point to disruption, not financial gain, which means being too small for a ransom is not protection. No actor has been named.
Over a single weekend, someone went after the machinery that moves Minnesota's drinking water. Minnesota IT Services says more than 30 community water systems were targeted on July 26 and 27, 2026, and the targeting was aimed at operational technology rather than email and file servers. Four cities have since described what broke.
What Actually Happened
In Braham, a town of roughly 1,800 in Isanti County, the water plant went offline on Monday morning. The city described a malicious cyberattack on its computerized operating systems by unknown actors, which disabled the operating controls for the well and the treatment plant. There was no physical damage and no water-quality problem.
In Plymouth, cellular communications to two water towers and multiple wastewater lift stations dropped late Sunday. Staff ran the system manually. The city told residents that water levels and quality were unaffected, the water was safe, and nobody needed to change how much they used.
South St. Paul reported a cybersecurity incident affecting its water utility technology and automated controls, with Public Works staff maintaining normal water and wastewater operations by hand. Maple Plain reported that certain automated control functions were affected while normal operations continued, and confirmed its water remained safe to drink.
In every one of those four cities, the water was fine and the controls were not. Operators saved these systems by dropping to manual operation. That is genuine operational competence, and it is also the whole problem: the automation layer failed and humans absorbed it. Nobody got an alert saying "your control system is under attack." Braham found out when the plant stopped.
Disruption, Not Extortion
John Israel, MNIT assistant commissioner and Minnesota's chief information security officer, put the motive plainly: "All signs are pointing to disruption, not trying to get a financial gain or get an actual public impact." No ransom demand has been reported. MNIT worked with state and federal partners including the FBI, and the Minnesota Department of Health was part of the response.
That single sentence dismantles the most common objection small utilities raise. "We are too small to be worth a ransom" is a reasonable read of criminal economics, and it is useless against an actor who simply wants a town's water plant to stop working. Ransomware crews need you to be worth money. A disruption actor only needs you to be reachable.
What Is Not Known, and Why That Matters
No actor, nation, or access vector has been made public. Within a day of the story breaking, widely-shared social posts were already asserting a specific agency lineup and an attacker. Some of that is not supported by the reporting.
It is fair to observe that the pattern here, internet-reachable control systems at small water utilities, is the same pattern federal advisory AA26-097A describes, and that advisory does name Iranian-affiliated actors targeting exposed PLCs across Rockwell, Schneider Electric, and Siemens. Those are two separate facts, and stitching them into an identification is how a security vendor stops being worth listening to. When attribution comes, it will come from the FBI, not from a thread.
What To Do This Week
- Find out what of yours answers the internet. Not what should, what does. Remote sites, towers, and lift stations are the usual surprises, because a vendor connected them for convenience years ago.
- Ask honestly whether you would have noticed. If your only alarm for a compromised control system is the process failing, you do not have detection, you have consequences.
- Practice manual operation deliberately. Every city that came through this did it by hand. Confirm your staff can, and that it does not depend on one person who might be on vacation.
- Inventory the cellular and radio links. Plymouth's failure was communications, not the plant. Those links often sit outside whatever anyone considers "the network."
- Check that the separation between the control network and the business network is real, not just drawn.
- Write down who you call before you need them at 6am.
Strategic Implications
Water is the sector where the gap between consequence and budget is widest. A utility serving 1,800 people has the same exposed protocols as one serving 500,000 and a fraction of the staff to watch them. This incident is the clearest recent evidence that the targeting does not scale down with the customer count, and that when the automation fails the only thing standing between an attack and the public is an operator who happened to be paying attention.
For the full incident brief, the city-by-city breakdown, and the primary reporting, see the RedEye incident brief on the Minnesota attack. For the wider picture of who is targeting water and what exposure looks like across US critical infrastructure, start at the RedEye ICS threat intelligence page.
Would you have found out before the plant stopped?
RedEye Security assesses what of your control network is exposed and whether you would see an attack on it. Federal grants may cover the cost.
Talk to us about your exposure