VMTech
+381 11 4183 54024/7 Discuss a project

Cyberattack targets 30+ Minnesota water systems, forcing Braham plant offline

Cyberattack targets 30+ Minnesota water systems, forcing Braham plant offline

On July 26 and 27, 2026, a coordinated cyberattack targeted operational technology at more than 30 community water systems across Minnesota. Braham’s water plant went offline, and residents were asked to minimize consumption until treatment resumed.

Why the disruption matters

Operational technology converts digital commands into physical processes. Interference can disable automated treatment, pumping, alarms or communications, forcing utilities to switch to manual operation while preserving water quality and supply.

The statewide total refers to systems targeted, not confirmed compromises. Officials have not disclosed how many experienced unauthorized access or operational effects. On July 28, Minnesota IT Services said no active request to change drinking-water use was in place.

What investigators know

Plymouth reported cellular communications failures at two water towers and several wastewater lift stations but continued manually. South St. Paul and Maple Plain maintained service after automated controls were affected; Maple Plain declared a local emergency.

The attacker, entry method, affected products and any exploited vulnerability remain unknown. Minnesota IT Services is coordinating containment and recovery with CISA, the Environmental Protection Agency, the FBI, state agencies and affected utilities.

“Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said Minnesota CISO John Israel.

Four days before the incidents, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing controllers from Rockwell Automation, Schneider Electric, Siemens and possibly others. Tenable said the timing and pattern were consistent with the CyberAv3ngers ecosystem, but no official link has been established.

CISA advises operators to restrict controller access, log cellular modem connections and inspect running project files for unauthorized changes. Backups should be validated before restoration, and physical mode switches returned to run only after project files are verified.

For businesses operating physical infrastructure, the practical priority is resilience rather than attribution: isolate exposed controllers, inventory remote access, retain usable logs and rehearse manual procedures. Tested backups and clear escalation paths can determine whether an intrusion remains manageable or becomes an outage.

#criticalinfrastructure#otsecurity#cybersecurity#watersystems
Open analytics
On the site 1 views
min read 3 29.07.2026
Instagram

Cyberattack targets 30+ Minnesota water systems, forcing Braham plant offline

Open the post on Instagram ↗