A coordinated cyberattack hit operational technology (OT) at more than 30 Minnesota community water systems on July 26–27, 2026, according to Minnesota IT Services (MNIT). Automated controls and remote communications failed at multiple utilities. At least one plant — Braham — went offline for several hours and asked residents to minimize water use while crews restored treatment. Other named cities switched to manual contingency operations. Officials report no drinking-water quality compromise and, after the initial outages, no statewide ask for residents to change water use.
MNIT activated statewide incident response and is coordinating with the Minnesota Department of Health, Fusion Center partners, CISA, the EPA, the FBI, and local utilities. Attribution remains under investigation — treat timing overlap with CISA Advisory AA26-097A (Iranian-affiliated PLC activity, updated July 22) as context, not a confirmed link to this incident.

Snapshot
| Field | Detail |
|---|---|
| What | Coordinated OT cyberattack on community water systems |
| When | July 26–27, 2026 |
| Scope | 30+ Minnesota community water systems (most names not public) |
| Named cities | Braham, Maple Plain, Plymouth, South St. Paul |
| Hardest public hit | Braham water plant briefly offline; conserve-water notice while tower held limited supply |
| Other impacts | Automated controls / cellular tower–lift-station links disrupted; manual ops |
| Water safety | Officials: quality and safety not compromised; no customer-data breach reported |
| Lead responders | MNIT, MDH, Fusion Center, CISA, EPA, FBI, local utilities |
| Actor | Unknown (investigation active) |

Named communities — what went wrong
Only four systems have been named publicly; MNIT has said the rest are treated as nonpublic. Local reporting aligns on the following:
| Community | Domain | What operators reported |
|---|---|---|
| Braham (~1,700) | brahammn.gov | Computerized well / treatment controls disabled → plant offline ~morning of July 27; restored within hours; residents asked to minimize use during outage |
| Plymouth | plymouthmn.gov | Cellular-linked gear at two water towers and multiple lift stations lost remote communications; city moved to manual procedures |
| Maple Plain | mapleplainmn.gov | Automated control functions affected; mayor declared a local emergency to speed response; contingency ops kept water/wastewater running |
| South St. Paul | southstpaulmn.gov | Cybersecurity incident on water-utility technology; automated controls impaired; manual ops maintained service |
Braham contracts water/wastewater operations with PeopleService (peopleservice.com) — a reminder that vendor OT access sits next to city IT when something breaks.

Timeline
| When | What happened |
|---|---|
| July 22, 2026 | CISA and partners update advisory AA26-097A on internet-exposed PLC targeting (broader vendor scope) — not an attribution of this Minnesota event |
| July 26–27 | Coordinated OT disruptions across 30+ Minnesota community water systems |
| July 27 morning | Braham posts plant offline / conserve-water notice; later confirms malicious cyberattack on computerized operating systems; plant returns online |
| July 27 | Plymouth, Maple Plain, South St. Paul disclose water-utility tech incidents and contingency ops |
| July 28 | MNIT public statement: statewide response activated; MDH not aware of active statewide water-use change requests |
| July 28+ | CISA publishes CI Fortify isolation guidance for vital OT systems (international partners) |

Why OT isolation matters here
Public details describe control-plane pain — computerized operating systems, automated valves/pumps, and cellular remote links — not a mass customer-PII dump. That is the water-sector failure mode CISA’s isolation guidance targets: keep treatment and pressure available through manual or alternate SCADA paths when the IT/OT edge is hostile.
For small systems, the practical lesson is blunt:
| Control | Why it showed up in this incident |
|---|---|
| OT network isolation | Limits blast radius when internet-facing or cellular-managed assets are hit |
| Documented manual runbooks | Braham / Plymouth / Maple Plain / South St. Paul kept service via contingency procedures |
| Vendor access review | Contract operators and remote support paths are part of the attack surface |
| Crisis email authenticity | Spoofed “boil water / conserve / plant status” mail spikes during outages — domain auth still matters |
Independent cybersecurity audits
EmailMeNow domain audits on July 30, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture on the municipal and response domains, not whether a PLC was internet-exposed.
| Organization / role | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| U.S. EPA | epa.gov | 76% | 65% | 45% | 92% | Good |
| City of South St. Paul | southstpaulmn.gov | 70% | 75% | 15% | 65% | Good |
| City of Braham | brahammn.gov | 68% | 90% | 15% | 37% | Above Average |
| CISA | cisa.gov | 67% | 90% | 45% | 45% | Above Average |
| Minnesota state portal (MNIT) | mn.gov | 63% | 75% | 45% | 37% | Above Average |
| City of Maple Plain | mapleplainmn.gov | 57% | 25% | 15% | 89% | Average |
| City of Plymouth | plymouthmn.gov | 50% | 45% | 15% | 37% | Average |
| PeopleService (ops contractor) | peopleservice.com | 46% | 35% | 15% | 37% | Below Average |
| Minnesota Department of Health | health.state.mn.us | 38% | 10% | 45% | 40% | Weak |
Audit links: epa.gov · southstpaulmn.gov · brahammn.gov · cisa.gov · mn.gov · mapleplainmn.gov · plymouthmn.gov · peopleservice.com · health.state.mn.us
Pattern: Every named city domain and the PeopleService contractor sit at 15% transport — the recurring gap that makes spoofed “plant status / conserve water / vendor invoice” mail easier to deliver next to a real outage. MDH (health.state.mn.us) is the weakest overall at 38%, with 10% identity. EPA leads this set at 76%, still 24 points under the 100% ideal.
Website stack note
Passive website-tech probes on July 30, 2026 covered all nine domains (9 probed, 4 notable):
| Domain | Public stack signal |
|---|---|
mapleplainmn.gov | Drupal 11 reported behind current (11.4.4 at probe time); TLS ~57 days remaining |
health.state.mn.us | Drupal 11 behind current (11.4.4) |
cisa.gov | Drupal 11 behind current (11.4.4) |
peopleservice.com | WordPress with outdated-core freshness signal vs wordpress.org 7.0.2; visible page-builder plugins |
Other probed hosts (brahammn.gov, plymouthmn.gov, southstpaulmn.gov ASP.NET, mn.gov PHP, epa.gov Drupal) did not surface the same notable freshness bullets. Marketing/CMS age does not explain the OT outage — but soft public stacks on contractor and health hosts are a poor look beside a water-sector IR.
Cybersquat / lookalike scan
DoH lookalike scans on July 30, 2026 (registered-only):
| Brand domain | Checked | To review | Notes |
|---|---|---|---|
brahammn.gov | 124 | 0 | No threatening registered variants in generated set |
mapleplainmn.gov | 165 | 0 | Clean in generated set |
southstpaulmn.gov | 182 | 0 | Clean in generated set |
plymouthmn.gov | 145 | 1 | plymouthmn.com registered with MX (tld-swap); city also appears to hold .info / .net / .org / .us redirects |
peopleservice.com | 182 | 5 | peopleservices.com, people-service.com, peopleservice.net, peopleservice.xyz, peoplesservice.com |
mn.gov | 54 | 10 | Short-label TLD swaps (mn.com, mn.org, mn.ai, …) — high noise; monitor crisis-impersonation mail, don’t treat all as water-sector staging |
During an outage, a live-MX lookalike like plymouthmn.com is exactly the kind of domain that can host spoofed “Public Works update” threads. Same playbook as Surfside Beach — just aimed at utility status instead of ACH.
Priority actions
- Water / wastewater operators: Inventory internet-facing and cellular-managed OT; apply CISA isolation / CI Fortify guidance; verify manual runbooks with a tabletop this quarter.
- City IT / MSPs: Treat spoofed plant-status and “MDH / EPA advisory” mail as high risk while headlines circulate; enforce DMARC and callback procedures for vendor and contractor mail.
- Contract operators: Review remote access into customer plants; harden the public domain that residents and cities will Google first (
peopleservice.comscored 46%). - Residents: Follow city and MDH notices only from verified channels; ignore unexpected links claiming boil-water or payment changes during the news cycle.
Related trackers
- Surfside Beach municipal BEC + lookalike domains
- Fairlife ransomware halted U.S. production
- Fortune 500 utilities email security
- Cyber insurance controls vs claim denials
- Local government industry hub
Sources: MNIT — statewide response (Jul 28, 2026) · BleepingComputer · CBS Minnesota · Star Tribune · MinnPost · CISA AA26-097A (context only). Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans July 30, 2026. Domain scores: audit.emailmenow.com only — not a penetration test of plant OT.