Back to news
Cybersecurity Alert
July 30, 2026 by EmailMeNow IT Consulting

Coordinated Cyberattack Hit 30+ Minnesota Water Systems — OT Controls Offline

MNIT says a coordinated OT cyberattack hit more than 30 Minnesota community water systems July 26–27. Braham briefly took its plant offline; Plymouth, Maple Plain, and South St. Paul went to manual ops. Domain audits (ideal 100%): none reached 100% — health.state.mn.us 38%, peopleservice.com 46%.

Source: Minnesota IT Services (MNIT)

NewsCritical InfrastructureWater UtilitiesOTSCADAMunicipalMinnesotaCISACybersecurity
Minnesota community water treatment plant with industrial control screens showing offline OT alerts

A coordinated cyberattack hit operational technology (OT) at more than 30 Minnesota community water systems on July 26–27, 2026, according to Minnesota IT Services (MNIT). Automated controls and remote communications failed at multiple utilities. At least one plant — Braham — went offline for several hours and asked residents to minimize water use while crews restored treatment. Other named cities switched to manual contingency operations. Officials report no drinking-water quality compromise and, after the initial outages, no statewide ask for residents to change water use.

MNIT activated statewide incident response and is coordinating with the Minnesota Department of Health, Fusion Center partners, CISA, the EPA, the FBI, and local utilities. Attribution remains under investigation — treat timing overlap with CISA Advisory AA26-097A (Iranian-affiliated PLC activity, updated July 22) as context, not a confirmed link to this incident.

Minnesota community water treatment plant with industrial control screens showing offline OT alerts

Snapshot

FieldDetail
WhatCoordinated OT cyberattack on community water systems
WhenJuly 26–27, 2026
Scope30+ Minnesota community water systems (most names not public)
Named citiesBraham, Maple Plain, Plymouth, South St. Paul
Hardest public hitBraham water plant briefly offline; conserve-water notice while tower held limited supply
Other impactsAutomated controls / cellular tower–lift-station links disrupted; manual ops
Water safetyOfficials: quality and safety not compromised; no customer-data breach reported
Lead respondersMNIT, MDH, Fusion Center, CISA, EPA, FBI, local utilities
ActorUnknown (investigation active)

Stylized Minnesota map with amber alerts marking more than thirty community water systems

Named communities — what went wrong

Only four systems have been named publicly; MNIT has said the rest are treated as nonpublic. Local reporting aligns on the following:

CommunityDomainWhat operators reported
Braham (~1,700)brahammn.govComputerized well / treatment controls disabled → plant offline ~morning of July 27; restored within hours; residents asked to minimize use during outage
Plymouthplymouthmn.govCellular-linked gear at two water towers and multiple lift stations lost remote communications; city moved to manual procedures
Maple Plainmapleplainmn.govAutomated control functions affected; mayor declared a local emergency to speed response; contingency ops kept water/wastewater running
South St. Paulsouthstpaulmn.govCybersecurity incident on water-utility technology; automated controls impaired; manual ops maintained service

Braham contracts water/wastewater operations with PeopleService (peopleservice.com) — a reminder that vendor OT access sits next to city IT when something breaks.

Municipal operators switching from dark SCADA screens to manual contingency procedures

Timeline

WhenWhat happened
July 22, 2026CISA and partners update advisory AA26-097A on internet-exposed PLC targeting (broader vendor scope) — not an attribution of this Minnesota event
July 26–27Coordinated OT disruptions across 30+ Minnesota community water systems
July 27 morningBraham posts plant offline / conserve-water notice; later confirms malicious cyberattack on computerized operating systems; plant returns online
July 27Plymouth, Maple Plain, South St. Paul disclose water-utility tech incidents and contingency ops
July 28MNIT public statement: statewide response activated; MDH not aware of active statewide water-use change requests
July 28+CISA publishes CI Fortify isolation guidance for vital OT systems (international partners)

Water towers with interrupted cellular links suggesting lost remote communications

Why OT isolation matters here

Public details describe control-plane pain — computerized operating systems, automated valves/pumps, and cellular remote links — not a mass customer-PII dump. That is the water-sector failure mode CISA’s isolation guidance targets: keep treatment and pressure available through manual or alternate SCADA paths when the IT/OT edge is hostile.

For small systems, the practical lesson is blunt:

ControlWhy it showed up in this incident
OT network isolationLimits blast radius when internet-facing or cellular-managed assets are hit
Documented manual runbooksBraham / Plymouth / Maple Plain / South St. Paul kept service via contingency procedures
Vendor access reviewContract operators and remote support paths are part of the attack surface
Crisis email authenticitySpoofed “boil water / conserve / plant status” mail spikes during outages — domain auth still matters

Independent cybersecurity audits

EmailMeNow domain audits on July 30, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture on the municipal and response domains, not whether a PLC was internet-exposed.

Organization / roleDomainOverallIdentityTransportWebsiteRisk
U.S. EPAepa.gov76%65%45%92%Good
City of South St. Paulsouthstpaulmn.gov70%75%15%65%Good
City of Brahambrahammn.gov68%90%15%37%Above Average
CISAcisa.gov67%90%45%45%Above Average
Minnesota state portal (MNIT)mn.gov63%75%45%37%Above Average
City of Maple Plainmapleplainmn.gov57%25%15%89%Average
City of Plymouthplymouthmn.gov50%45%15%37%Average
PeopleService (ops contractor)peopleservice.com46%35%15%37%Below Average
Minnesota Department of Healthhealth.state.mn.us38%10%45%40%Weak

Audit links: epa.gov · southstpaulmn.gov · brahammn.gov · cisa.gov · mn.gov · mapleplainmn.gov · plymouthmn.gov · peopleservice.com · health.state.mn.us

Pattern: Every named city domain and the PeopleService contractor sit at 15% transport — the recurring gap that makes spoofed “plant status / conserve water / vendor invoice” mail easier to deliver next to a real outage. MDH (health.state.mn.us) is the weakest overall at 38%, with 10% identity. EPA leads this set at 76%, still 24 points under the 100% ideal.

Website stack note

Passive website-tech probes on July 30, 2026 covered all nine domains (9 probed, 4 notable):

DomainPublic stack signal
mapleplainmn.govDrupal 11 reported behind current (11.4.4 at probe time); TLS ~57 days remaining
health.state.mn.usDrupal 11 behind current (11.4.4)
cisa.govDrupal 11 behind current (11.4.4)
peopleservice.comWordPress with outdated-core freshness signal vs wordpress.org 7.0.2; visible page-builder plugins

Other probed hosts (brahammn.gov, plymouthmn.gov, southstpaulmn.gov ASP.NET, mn.gov PHP, epa.gov Drupal) did not surface the same notable freshness bullets. Marketing/CMS age does not explain the OT outage — but soft public stacks on contractor and health hosts are a poor look beside a water-sector IR.

Cybersquat / lookalike scan

DoH lookalike scans on July 30, 2026 (registered-only):

Brand domainCheckedTo reviewNotes
brahammn.gov1240No threatening registered variants in generated set
mapleplainmn.gov1650Clean in generated set
southstpaulmn.gov1820Clean in generated set
plymouthmn.gov1451plymouthmn.com registered with MX (tld-swap); city also appears to hold .info / .net / .org / .us redirects
peopleservice.com1825peopleservices.com, people-service.com, peopleservice.net, peopleservice.xyz, peoplesservice.com
mn.gov5410Short-label TLD swaps (mn.com, mn.org, mn.ai, …) — high noise; monitor crisis-impersonation mail, don’t treat all as water-sector staging

During an outage, a live-MX lookalike like plymouthmn.com is exactly the kind of domain that can host spoofed “Public Works update” threads. Same playbook as Surfside Beach — just aimed at utility status instead of ACH.

Priority actions

  1. Water / wastewater operators: Inventory internet-facing and cellular-managed OT; apply CISA isolation / CI Fortify guidance; verify manual runbooks with a tabletop this quarter.
  2. City IT / MSPs: Treat spoofed plant-status and “MDH / EPA advisory” mail as high risk while headlines circulate; enforce DMARC and callback procedures for vendor and contractor mail.
  3. Contract operators: Review remote access into customer plants; harden the public domain that residents and cities will Google first (peopleservice.com scored 46%).
  4. Residents: Follow city and MDH notices only from verified channels; ignore unexpected links claiming boil-water or payment changes during the news cycle.

Sources: MNIT — statewide response (Jul 28, 2026) · BleepingComputer · CBS Minnesota · Star Tribune · MinnPost · CISA AA26-097A (context only). Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans July 30, 2026. Domain scores: audit.emailmenow.com only — not a penetration test of plant OT.