More Than 30 Minnesota Water Utilities Hit in Coordinated Cyberattack
Attackers knocked out automated controls at water and wastewater plants across the state on July 26 and 27. Drinking water stayed safe, but one city briefly shut its plant down entirely.

Key points
- Criminals attacked more than 30 community water systems across Minnesota on July 26 and 27, 2025.
- The City of Braham temporarily shut its water treatment plant after attackers cut off the controls that run its well and pumping equipment.
- Plymouth officials said the damage was limited to equipment that communicates over cellular, meaning wireless phone-network, connections.
- No group has formally been named as responsible, though federal warnings issued shortly before the attack flagged Iran-linked hackers targeting industrial water and power equipment.
- All affected cities say drinking water remains safe.
Criminals broke into the computer systems that run water treatment plants at more than 30 Minnesota communities during a coordinated two-day attack, state officials confirmed. Minnesota IT Services (MNIT) said the incidents occurred on July 26 and 27. State and federal investigators are now looking into what happened.
The targeted systems are known as operational technology, or OT, meaning the hardware and software that physically runs a plant: opening valves, running pumps, monitoring water quality. Unlike a standard office network, a hit on OT can stop water flowing or, more dangerously, change how it is treated without operators realising.
What actually happened to the water plants?
In most affected cities, backup procedures kicked in and services kept running. Braham was the hardest-hit community publicly named. Its city administrator said attackers "shut down the operating controls, which shut down the well and water treatment plant," forcing officials to take the facility offline briefly and ask residents to cut back on water use.
Maple Plain, South St. Paul, and Plymouth also confirmed that some "automated control functions" were affected. Plymouth's statement noted the problem was "limited to equipment connected via cellular communications within the system," pointing to the wireless modems that link remote assets, such as water towers and pump stations, back to the plant's central control software.
Denis Calderone, CTO of Suzu Labs, said those cellular links are a known weak point. "Secondary and/or alternative comm links are often overlooked when doing risk and vulnerability analysis," he told SecurityWeek, adding that the integrators who build out these networks often leave those connections out of formal security reviews entirely.
Who carried out the attack?
No group has been formally named. The attack came shortly after the US government warned water and energy operators about hackers linked to the Iranian government targeting industrial control systems made by Siemens, Rockwell Automation, and Schneider Electric. Groups including CyberAv3ngers and Handala have been tied to similar attacks on water infrastructure in the past, including a 2020 campaign against water facilities in Israel that also used vulnerable cellular routers as a way in. Investigators have not confirmed any connection to the Minnesota incidents.
Should people worry about their tap water?
All affected cities say drinking water is safe. No contamination has been reported. The attack appears to have focused on disrupting controls rather than altering treatment processes.
Harry Thomas, CTO of industrial security firm Frenos, offered a useful distinction. A loss of control can be temporary and recovered through manual operation. What is harder to catch is manipulation, where a plant's screens show normal readings while something different is actually happening in the pipes. Investigators will want to rule that out before closing any of these cases.
For residents in the affected cities, no action is required. If your local utility issues a boil-water notice or other advisory, follow it. Otherwise, watch for official updates from your city's water department.
| City | Impact reported | Operations status |
|---|---|---|
| Braham | Plant shut down, well offline | Restored after incident |
| Plymouth | Cellular-connected equipment affected | Operational |
| South St. Paul | Automated control functions affected | Operational |
| Maple Plain | Automated control functions affected | Operational |
Researcher Seemant Sehgal, CEO of BreachLock, made a point worth noting: whatever vulnerability let attackers in almost certainly exists in water infrastructure well beyond Minnesota.



