Image
Cyber incidents affecting water infrastructure in Braham, Plymouth and South St. Paul did not contaminate drinking water or cause prolonged service failures. The successful use of stored water, manual procedures and contingency plans prevented a more serious emergency. Minnesota should use that narrow escape to strengthen cybersecurity across municipal water and wastewater systems, particularly in smaller communities that cannot carry the financial and technical burden alone.
MINNEAPOLIS, MN (July 28, 2026). The most important fact about Monday’s cyberattacks against municipal water infrastructure in Minnesota is that the water remained safe. Residents continued turning on their faucets. Wastewater services continued operating. No boil-water advisories were issued. No city reported that an attacker had changed chemical levels, contaminated the water supply or caused a prolonged interruption of service.
That outcome deserves recognition. Public works employees responded quickly. Water stored in a municipal tower helped sustain service in Braham. Plymouth employees continued operating affected facilities through manual procedures. South St. Paul activated established contingency measures after technology supporting portions of its water utility was disrupted. Systems designed to provide reserve capacity and employees trained to work around automated equipment did what they were supposed to do.
Minnesota should be grateful that Monday’s incidents ended without a public health emergency. It should not mistake that outcome for proof that the state’s water infrastructure is adequately protected.
The attacks were a warning about the growing dependence of essential public services on computers, cellular connections, remote monitoring systems and industrial controls. They also exposed the limits of leaving local governments to manage a national cybersecurity problem with sharply unequal budgets, staffing levels and technical resources. A larger city may employ information technology specialists, security professionals and outside consultants. A small community may depend on a limited public works staff and one contracted technology provider to protect the machinery responsible for supplying drinking water.
The public record remains incomplete, and Minnesota officials should resist the pressure to fill those gaps with speculation. Braham, Plymouth and South St. Paul publicly confirmed incidents affecting water or wastewater technology on Monday, July 27. Braham officials said they were informed that at least four other communities experienced attacks with a similar result, leading news organizations to report that at least five Minnesota communities had been targeted. As of Tuesday morning, however, only three affected cities had publicly identified themselves.
That distinction matters. It is not yet known whether all the incidents came from the same attacker. Investigators have not publicly identified a criminal organization, foreign government, political group or individual responsible. No agency has announced that the incidents were part of a coordinated campaign. Officials have not disclosed whether a common vendor, software product, cellular provider or type of industrial controller connected the affected systems.
What is known is serious enough.
In Braham, an east-central Minnesota community in Isanti County, the city initially reported that its water plant was offline for an unknown reason. Public works employees began troubleshooting while residents were asked to minimize water use. The city depended on the limited volume already stored in its water tower because its well and treatment plant were not operating.
Less than two hours later, Braham announced that the facility had returned to service. City officials attributed the shutdown to a malicious cyberattack against computerized operating systems by unknown actors. According to the city, the attackers shut down operating controls serving the well and water-treatment plant. The physical facility was not reported damaged, and officials said the water continued to be filtered and treated properly after operations resumed.
Braham’s water tower helped prevent a temporary control-system failure from becoming an immediate loss of water service. Water towers maintain pressure and store a reserve supply that can support a community when pumping or treatment operations are interrupted. That reserve gave employees time to restore the facility. The city’s conservation request also showed why the tower could not serve as an indefinite substitute for an operating well and treatment plant. Stored water is a buffer, not a complete replacement for production.
In Plymouth, the incident affected communications equipment serving two water towers and multiple wastewater lift stations. The city said the outage began overnight Sunday and that a cyberattack was suspected. Officials described the problem as limited to equipment connected through cellular communications. Water levels and water quality remained unaffected, and residents were told they did not need to reduce consumption.
Plymouth employees continued operating through manual procedures. That statement is reassuring, but it should not be exaggerated into claims that every pump or valve was physically operated by hand. The city has not released detailed information about the procedures used, the equipment affected or the method by which the communications were disrupted. That restraint is understandable during an active cybersecurity investigation. Publishing unnecessary technical details could expose vulnerabilities before they are corrected.
The confirmed facts are sufficient. Technology used to communicate with water towers and wastewater lift stations stopped functioning as intended. City employees worked around the outage and maintained service. The public did not lose water, experience a wastewater emergency or face a water-quality threat.
South St. Paul also reported that a cybersecurity incident affected technology supporting parts of its water utility. Some automated controls were disrupted, but public works employees implemented established contingency procedures. Drinking water remained safe, and water and wastewater services continued operating. The city said it was working with technology partners and coordinating with state and federal agencies while employees monitored the system and worked to restore normal automated operations.
These accounts show that Monday’s incidents were not confined to public websites, email accounts or administrative files. Technology connected to physical water and wastewater operations was affected. In Braham, computerized operating controls were disabled and the plant temporarily stopped. In Plymouth, cellular communications serving towers and lift stations were disrupted. In South St. Paul, automated utility controls were affected.
That does not mean attackers gained the ability to manipulate every physical process within those systems. It does mean that digital security and physical infrastructure can no longer be treated as separate municipal responsibilities. A compromised computer, communications link or remote control system can change how pumps, wells, towers and wastewater facilities operate. Cybersecurity is therefore part of maintaining safe drinking water in the same way that testing, filtration, pipe maintenance and equipment inspection are part of that responsibility.
The timing of the Minnesota attacks adds urgency without settling the question of responsibility. On July 22, five days before the incidents, the federal Cybersecurity and Infrastructure Security Agency, the FBI, the Environmental Protection Agency and other government partners updated a warning about Iranian-affiliated cyber actors targeting internet-connected operational technology devices across American critical infrastructure.
The federal advisory focused on programmable logic controllers, commonly called PLCs. These industrial computers can monitor or control machinery and processes involving pumps, valves, pressure, flow and treatment operations. Federal agencies reported that malicious activity involving exposed controllers had caused operational disruptions, including erased configurations, manipulated sensor readings and interference with control-system interfaces.
The advisory urged infrastructure operators to identify equipment exposed to the internet, restrict remote access, change default credentials, segment operational technology from other networks and monitor systems for unauthorized changes. Those recommendations reflect a broader problem within the water sector. Equipment installed to improve efficiency and allow remote monitoring can also create an entry point if it remains publicly accessible, uses weak passwords, runs outdated software or depends on poorly secured communications.
The federal warning does not prove that Iranian-affiliated actors attacked Braham, Plymouth or South St. Paul. No Minnesota city, state agency or federal investigator has made that connection publicly. There is no confirmed finding that the same PLCs discussed in the federal advisory were involved in Minnesota. There is no publicly confirmed attribution to Iran, another government or any named cybercriminal group.
Professional reporting requires maintaining that boundary. The public should be told about the federal warning because it establishes the seriousness of the national threat environment. It should also be told that responsibility for the Minnesota incidents remains unknown.
Officials should exercise similar care before describing Monday’s events as a coordinated assault. Several cities experienced related problems within the same period. That pattern raises legitimate questions about a common attacker, shared equipment, a compromised vendor, a cellular communications failure or an automated campaign searching the internet for vulnerable systems. It does not by itself establish that one person or organization directed every incident.
Cyberattacks do not always begin with an attacker selecting a particular community. Some campaigns use automated tools to scan large numbers of internet addresses for exposed equipment, common passwords and known vulnerabilities. A small utility can become a victim because its technology is reachable, not because an attacker has a particular interest in the town or its residents. That makes basic security practices especially important. Attackers looking for the easiest available entry point do not care whether a municipality has the tax base to employ a sophisticated security team.
The national-security implications remain substantial even without an identified foreign actor. Water and wastewater systems support nearly every other part of a community. Hospitals require clean water and reliable sanitation. Fire departments depend on adequate pressure and supply. Schools, child care centers, restaurants, nursing homes, apartment buildings and manufacturing facilities cannot function normally without dependable water service. A wastewater failure can create environmental and public health consequences extending beyond the municipality where the disruption begins.
An attacker does not have to poison drinking water to cause damage. Disabling remote monitoring can force employees to travel between facilities and inspect equipment locally. Interrupting communications with a lift station can make it harder to detect changing conditions. Shutting down a well or treatment plant can reduce the amount of water available. Manipulating system information could delay an accurate response. A prolonged outage during extreme heat, a major fire or another emergency could create consequences far more serious than those experienced Monday.
Minnesota should therefore treat water-system cybersecurity as a statewide public-safety responsibility, not merely a collection of local technology problems.
Municipal governments own and operate many of these systems, but the threat does not respect municipal boundaries. Neither should the response. A vulnerability in a small city can require assistance from state agencies, federal investigators, private contractors and neighboring jurisdictions. If an incident affects a shared water source, interconnected wastewater infrastructure or a common technology provider, the consequences can move beyond the city where the intrusion was first detected.
The financial burden is particularly important. Public discussion often assumes that cities can respond by purchasing newer equipment, hiring cybersecurity employees and installing additional monitoring. Those recommendations may be technically sound, but they are not financially simple.
Water utilities already face expensive obligations. They must replace aging pipes, maintain wells, treatment plants and towers, comply with health and environmental standards, manage staffing shortages, prepare for severe weather and respond to population growth. Smaller communities spread those costs across fewer households and businesses. Adding cybersecurity assessments, equipment replacement, network segmentation, secure remote access, staff training, emergency exercises and continuous monitoring can strain budgets that were never designed to address sophisticated international cyber threats.
The precise cost of Monday’s incidents has not been disclosed. It would be irresponsible to claim that each affected city faces a particular repair bill without municipal estimates, contracts or budget records. Some vulnerabilities may be corrected through password changes, revised configurations or restricted remote access. Others may require replacement of obsolete controllers, communications equipment or software. Investigations, forensic services and long-term monitoring can add further expense.
Minnesota should not wait for final invoices before recognizing the basic funding problem. A city should not have to postpone street repairs, park maintenance, public safety equipment or replacement of aging water mains to correct a vulnerability in technology controlling the water supply. Cybersecurity is now part of the cost of providing water, but that does not mean every municipality can absorb the cost without state and federal support.
Federal resources are available. The Environmental Protection Agency offers free cybersecurity evaluations for drinking water and wastewater utilities. Those evaluations can identify vulnerabilities and provide a risk-mitigation plan. Cybersecurity projects may also qualify for assistance through the Drinking Water State Revolving Fund and the Clean Water State Revolving Fund. Federal programs provide training, planning tools, technical assistance and grants for eligible resilience projects.
Availability, however, is not the same as access. A small city must still learn about the programs, determine eligibility, complete applications, manage awards and find qualified vendors. Some grants are aimed at midsized or large systems and may not match the needs of the smallest communities. Competitive funding also leaves open the possibility that cities with the greatest administrative capacity will secure assistance while those with the fewest employees struggle to apply.
Minnesota should establish a coordinated program that does more than distribute links to federal guidance. The state should help every municipal water and wastewater utility identify internet-connected operational equipment, evaluate remote access, review passwords and user accounts, document critical technology assets and test incident-response procedures. Smaller systems should receive direct technical assistance rather than being expected to build an independent cybersecurity department.
The Legislature should consider dedicated grants for replacing obsolete or unnecessarily exposed equipment. State agencies could create regional purchasing agreements that allow communities to obtain security services at negotiated rates. Shared cybersecurity specialists could serve groups of smaller utilities. Regular exercises could test whether employees can maintain safe operations when automated communications or controls become unavailable.
Any state program should include clear minimum expectations. Utilities should know which equipment is connected to the internet, who can access it remotely, whether default passwords remain active and how operational systems are separated from ordinary administrative networks. They should maintain current contact information for state and federal response agencies. They should know how long stored water can support residents if a well or treatment plant goes offline. They should also practice manual and contingency procedures before an emergency requires them.
Standards must be paired with resources. Imposing requirements without funding would transfer a statewide security responsibility back onto local ratepayers. It could also encourage superficial compliance in communities that lack the money and staff to make meaningful improvements. Minnesota needs enforceable expectations, technical assistance and adequate financing working together.
The successful use of manual and contingency procedures on Monday offers an important lesson. Automation makes water systems more efficient, but employees remain essential. When cellular communications failed in Plymouth, people continued operating the affected facilities. When automated controls were disrupted in South St. Paul, employees used established contingency procedures. When Braham’s plant went offline, its water tower provided time for public works personnel to restore operations.
Those results justify continued investment in training, staffing and backup capacity. A water utility cannot depend on a written emergency plan that employees have never practiced. It cannot assume that a retired operator’s knowledge will automatically transfer to the next employee. It cannot wait until automated systems fail to determine which readings must be collected locally, which equipment can be operated manually and how often facilities must be inspected.
Manual procedures also have limits. They can demand additional travel, repeated inspections and around-the-clock staffing. They may provide less immediate information than functioning automated systems. A small crew can sustain an emergency response for a limited period, but fatigue and competing responsibilities become more serious as an outage continues. Manual operation is an essential safeguard. It is not an acceptable long-term substitute for secure and reliable automation.
Minnesota’s response must also include responsible public communication. Each affected city appropriately told residents whether the water was safe and whether consumption needed to change. Braham asked people to conserve when the plant was offline. Plymouth told residents that water levels and quality were unaffected and that no conservation was necessary. South St. Paul said drinking water remained safe and service continued.
That practical information should remain the first priority during any water-system incident. Residents need to know whether they can drink the water, whether they should boil it, whether they should conserve and where they can receive verified updates. Officials should explain what services are affected without releasing technical information that could help an attacker. They should correct rumors quickly, particularly when the words “cyberattack” and “water system” create understandable fear about contamination.
State officials must also provide a public accounting when the immediate danger has passed. Minnesotans deserve to know how many communities were affected, whether the incidents were connected, which state and federal agencies responded and what broad corrective measures are being taken. Security concerns may prevent disclosure of exact configurations or vulnerabilities, but they should not become a reason for permanent silence.
The Legislature should request a statewide after-action report. That review should examine detection, communication, staffing, reserve capacity, manual procedures, vendor relationships and coordination among local, state and federal agencies. It should identify gaps without turning the report into a blueprint for future attackers. It should also recommend how Minnesota will measure improvement rather than allowing attention to fade once the systems return to normal.
Monday’s events should be considered alongside Minnesota’s recent experience with municipal cybercrime. St. Paul spent months recovering from the major 2025 attack that forced the city to shut down broad portions of its computer network. That incident affected internal systems and public services, required outside cybersecurity assistance and eventually involved notification to residents and employees whose information may have been exposed. The water incidents are not known to be connected to the St. Paul attack, but together they demonstrate that cyber threats to local government are persistent, expensive and capable of affecting both information and physical operations.
Minnesota cannot prevent every intrusion. No responsible official can promise that. The proper goal is to reduce unnecessary exposure, detect attacks quickly, prevent movement between systems, maintain safe service during a disruption and restore operations without placing residents at risk.
The state should begin with the facts established on Monday. At least three publicly identified communities experienced incidents affecting water or wastewater technology. Braham temporarily lost operation of its well and treatment plant. Plymouth lost cellular communications serving two towers and multiple lift stations. South St. Paul experienced disruptions to automated utility controls. Employees responded, stored water and contingency procedures worked, and drinking water remained safe.
Those facts support neither panic nor complacency. They support action.
Minnesota was fortunate that Monday’s attacks did not become a water-quality emergency. It was fortunate that Braham’s plant returned to operation before the tower’s stored supply became a more serious concern. It was fortunate that Plymouth and South St. Paul could continue operating through manual or contingency procedures. The state should respect that outcome by learning from it.
The next incident may last longer. It may occur during a heat emergency, a major fire, a flood or a period of reduced staffing. It may affect a utility whose backup procedures have not been tested. It may target obsolete equipment that cannot be restored quickly. It may disrupt several interconnected services at once.
Waiting for those consequences would be an avoidable failure.
Minnesota should identify the vulnerabilities now, help cities correct them, fund improvements according to need and require every water and wastewater utility to demonstrate that it can operate safely when digital systems fail. The public employees who protected service on Monday did their part. State leaders must now do theirs.
MinneapoliMedia | Community. Culture. Civic Life.