More Than 30 Minnesota Water Utilities Hit in Coordinated Cyberattack
Attackers knocked out automated controls at water and wastewater plants across the state on July 26 and 27. Drinking water stayed safe, but one city briefly shut its plant down entirely.

Key points
- Criminals attacked more than 30 community water systems across Minnesota on July 26 and 27, 2025.
- Braham temporarily shut its water treatment plant after attackers cut off the controls running its well and pumping equipment.
- Plymouth said the damage was limited to equipment on cellular connections, meaning wireless modems linking remote assets back to the plant.
- No group has been formally named, though federal warnings issued days before the attack flagged Iran-linked hackers targeting industrial water and power equipment.
- All affected cities say drinking water remains safe.
Criminals broke into the computer systems running water treatment plants at more than 30 Minnesota communities during a coordinated two-day attack, state officials confirmed. Minnesota IT Services (MNIT) said the incidents occurred on July 26 and 27. State and federal investigators are now looking into what happened.
The targeted systems are known as operational technology, or OT: the hardware and software that physically runs a plant, opening valves, running pumps, monitoring water quality. Unlike a standard office network, a hit on OT can stop water flowing or change how it's treated without operators realising.
What actually happened to the water plants?
In most affected cities, backup procedures kicked in and services kept running. Braham was the hardest-hit community publicly named. Its city administrator said attackers "shut down the operating controls, which shut down the well and water treatment plant," forcing officials to take the facility offline briefly and ask residents to cut back on water use.
Maple Plain, South St. Paul, and Plymouth confirmed that some "automated control functions" were affected. Plymouth's statement noted the problem was "limited to equipment connected via cellular communications within the system," pointing to the wireless modems that link remote assets back to the plant's central control software.
Denis Calderone, CTO of Suzu Labs, said those cellular links are a known weak point. "Secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis," he told SecurityWeek, adding that the integrators who build these networks often leave those connections out of formal security reviews entirely. Braham's administrator has already asked for the city's vulnerability study to be re-evaluated; Calderone said he wouldn't be surprised if that study never included the cellular paths at all.
Who carried out the attack?
No group has been formally named. The attack came days after we reported a US government warning about hackers linked to the Iranian government targeting industrial control systems made by Siemens and Rockwell Automation. Groups including CyberAv3ngers and Handala have been tied to similar attacks before. Investigators have not confirmed any connection to the Minnesota incidents.
Should people worry about their tap water?
All affected cities say drinking water is safe. No contamination has been reported. The attack appears to have focused on disrupting controls rather than altering treatment.
Harry Thomas, CTO of industrial security firm Frenos, offered a useful distinction. A loss of control can be temporary, recovered through manual operation. Manipulation is harder to catch: a plant's screens can show normal readings while something different is actually happening in the pipes. Investigators will want to rule that out before closing any of these cases.
For residents in affected cities, no action is required right now. Watch for official updates from your city's water department, and follow any boil-water notice if one is issued.
| City | Impact reported | Operations status |
|---|---|---|
| Braham | Plant shut down, well offline | Restored after incident |
| Plymouth | Cellular-connected equipment affected | Operational |
| South St. Paul | Automated control functions affected | Operational |
| Maple Plain | Automated control functions affected | Operational |
Seemant Sehgal, CEO of BreachLock, put the broader problem plainly: whatever vulnerability let attackers into Minnesota's systems almost certainly exists in water infrastructure well beyond this state. That's the detail investigators and utility managers everywhere should be sitting with.



