The Minnesota Water System Cyberattack: What Happened, and What It Teaches Every Business
Over one weekend in late July, somebody reached into the automated controls of more than 30 Minnesota community water systems. In Braham, the attackers shut down the well and the treatment plant. In Plymouth, two water towers and multiple lift stations lost their communications links. This was not an email scam or a stolen customer list. Somebody touched the machines.
We work IT and cybersecurity for Minnesota businesses every day, including in Plymouth, one of the four cities that has publicly confirmed it was hit. So we have been following this one closely. Here is what is actually known, what is not known yet, and what a business owner anywhere in the state should take from it.
What Actually Happened
Between Sunday, July 26 and Monday, July 27, attackers targeted the operational technology of more than 30 community water systems across Minnesota. Minnesota IT Services confirmed the scope on July 28. Four cities have been named publicly so far: Plymouth, South St. Paul, Maple Plain, and Braham. The rest have not been identified.
The most concrete public account comes from Braham, a town of about 1,800 north of the metro. At roughly 9:34 on Monday morning, the attackers shut down the operating controls for the city well and water treatment plant. City crews took the system to manual operation and had water flowing again in about two hours. Residents were briefly asked to go easy on water use. That was the extent of it.
In Plymouth, the city reported cellular communications problems at two water towers and multiple wastewater lift stations, and kept operating manually while systems were checked.
No drinking water was ever unsafe. Every affected city has said water quality was not touched, no boil advisories were issued, and the Minnesota Department of Health confirmed that no municipality asked residents to change how they use water. There is no indication customer data was accessed. The state activated a coordinated incident response and is working with the FBI.
One more detail worth sitting with. The state's chief information security officer said the signs point to disruption as the goal. Not money. Nobody has reported a ransom demand. Somebody apparently wanted to prove they could turn off pieces of Minnesota's water infrastructure, and for a couple of hours in Braham, they did.
What Is Not Known Yet
Plenty of coverage this week has raced ahead of the facts, so let us be careful here. As of this writing, the following has not been confirmed by investigators:
- Who did it. No group has claimed responsibility and no official attribution has been made. Security researchers have pointed out that the pattern fits a CISA advisory, updated just four days before the attack, about Iranian-affiliated actors compromising internet-connected industrial controllers across US water and energy systems. That is an analyst's observation about timing and technique. It is not a finding.
- How they got in. The state has not identified the equipment involved or the access method. Reporting points at cellular-modem connections on remote assets like water towers and lift stations as a likely path, which lines up with Plymouth's symptoms, but that remains unconfirmed.
- The full victim list, whether any malware was left behind, and whether the attackers still have access anywhere.
When the investigation publishes real findings, some of the guesses above will be wrong. Treat anyone who tells you otherwise this week as selling something.
How This Class of Attack Works
Water systems run on PLCs, programmable logic controllers. Small industrial computers that open valves, start pumps, and report tank levels. They were designed decades ago for reliability, not for a hostile internet. A lot of them ended up connected anyway, because remote access is convenient when your water tower is twenty minutes from the public works garage and it is January.
That convenience is the attack surface. The CISA advisory that researchers keep citing describes actors finding internet-exposed controllers, using known weaknesses to get in, changing controller logic, and in some cases manipulating the operator displays so everything looks normal while it is not. One of the key flaws involved is a 2021 authentication bypass that the vendor says cannot be fully patched. The fix is architectural: get the controller off the internet and put real access controls in front of it.
This is not new. An intruder tried to spike the lye levels at a Florida treatment plant in 2021 through a shared remote-access tool. An Iranian-linked group defaced controllers at a Pennsylvania water authority in 2023, walking in through an internet-exposed device still wearing its default password. Russian-linked actors overflowed a tank in a Texas panhandle town in 2024. The pattern repeats because the conditions repeat: old equipment, direct internet exposure, weak or absent authentication, and nobody watching.
The Braham Lesson: Two Hours, Not Two Weeks
Here is the part of this story that did not get enough attention. Braham was back up in about two hours.
That did not happen because their technology saved them. It happened because their people could run the plant by hand. The operators knew the manual procedures, took control, and kept water moving while the automation was down. Plymouth did the same thing at its towers and lift stations.
Resilience is a plan, not a product. The cities that came through this cleanly were the ones that could answer a simple question: if the computers stop, what do we do for the next four hours? Every business should be able to answer that question about its own operations, and most cannot.
You Are Not a Water Utility. This Is Still About You.
Most of our clients are professional firms, manufacturers, and service companies with 25 to 300 employees. No PLCs, no lift stations. It would be easy to read this story as somebody else's problem. It is not, for two reasons.
First, the same doors exist in your building under different names. The water sector's exposed controllers are your exposed remote desktop, the VPN without MFA, the vendor account nobody audits, the firewall rule from 2019 that nobody remembers. Attackers scan for all of it the same way. Manufacturers especially: if you run CNC machines, environmental controls, or any shop-floor equipment a vendor can reach remotely, you have operational technology, and this story is directly about you.
Second, the motive here should change your math. There was no ransom. Disruption itself was the point. You cannot buy your way out of an attacker who does not want money. You can only be harder to reach and faster to recover than the next target down the list.
What We Would Check This Week
If we ran your IT, this is the review this news would trigger. It is the same checklist whether you move water or invoices:
- Find everything of yours that answers from the internet. Remote desktop, VPN portals, firewalls with management pages exposed, cameras, HVAC controllers, anything a vendor installed. If you have never scanned for this, you will find surprises. Utilities can get this scan free from CISA. Businesses can ask us.
- Put MFA in front of every remote path. Every one. Including the vendor accounts and the cellular or dial-home links on equipment. The suspected vector in this attack was exactly that kind of quiet side door.
- Kill default passwords and retired accounts. The Pennsylvania water authority was breached through a device still set to its factory password. We find the equivalent in businesses constantly.
- Separate the machines that run your operation from the computers that browse email. Network segmentation is what keeps a phished laptop from becoming a stopped production line.
- Keep offline, immutable backups of the configurations that run your business, not just your files. Braham recovered fast partly because operators could restore control quickly. Ask yourself what your two-hour recovery would look like.
- Rehearse the manual fallback. If your systems went dark at 9:34 on a Monday morning, what would your team physically do? If the answer lives in one person's head, it is not a plan.
None of this is exotic. It is the unglamorous work of knowing what you have, closing the doors you do not need, and practicing for the bad morning. The cities that did that work had a two-hour story last week. The ones that did not are still doing impact assessments.
Sources & Citations
Facts in this article are drawn from public reporting and government advisories. Where reporting is unconfirmed, the article says so.
- Star Tribune: Cyberattack hits more than 30 water utilities across Minnesota
- MPR News: Braham cyberattack knocked water system offline and 30 Minnesota municipal water systems targeted
- CBS Minnesota: State CISO on the Braham outage and attacker motive
- SecurityWeek: Dozens of Minnesota water utilities targeted in coordinated OT attacks
- CISA: Advisory AA26-097A, Iranian-affiliated actors targeting PLCs (updated July 22, 2026), and WaterISAC's advisory note
- StateScoop: Coordinated cyberattack disrupts water utilities in 30 Minnesota communities
- Tenable: Analysis of the Minnesota attacks and AA26-097A
Could your business run through a morning like Braham's?
We will find what you have exposed to the internet, check every remote path for MFA, and walk your recovery plan with you. No sales pitch attached. Minnesota businesses with 25 to 300 employees.
Request a Security Review