
More than 30 community water utilities across Minnesota were struck by a coordinated cyberattack on July 26 and 27 that disabled operational technology systems, prompting one of the largest responses to an attack on local water infrastructure in the state’s history. Minnesota IT Services (MNIT), the state’s central technology organization, activated its cybersecurity incident response capabilities as soon as it learned of the intrusion, and the response remained active this week.
Four municipalities have been identified publicly: Braham, Maple Plain, Plymouth and South St. Paul. Braham, a town of roughly 1,700 residents, was hit hardest. Attackers disabled the computerized controls operating the town’s well and treatment systems, knocking the water plant offline entirely. The plant’s mayor described the effect on operations, saying, "There was power – but there was no controls, you know, telling the water where to go." Crews restored filtering and treatment at the Braham plant within about two hours.
In Plymouth, the city’s information technology staff disconnected cellular-connected equipment at two water towers as a precautionary measure, and the disruption stayed confined to that equipment. Other affected communities reported that the attack interrupted communications and automated operations, requiring staff to shift to manual workarounds while systems were brought back online. Residents in at least one location were advised to limit water use before service resumed roughly an hour and a half later. Across most of the affected utilities statewide, backup procedures kept operations running without a full shutdown.
MNIT spokesperson Emily Zimmer told Reuters that the intrusion’s timing, methods of access and targeted equipment shared characteristics with earlier coordinated attacks on U.S. critical infrastructure, including attacks involving programmable logic controllers, devices used to automate industrial control systems. Zimmer said MNIT applied the term "attack" to the incident because investigators found unauthorized access carried out with malicious intent against the affected systems.
State officials have not formally attributed the intrusion to any specific group, but a hacktivist collective known as CyberAv3ngers, which has ties to Iran’s Islamic Revolutionary Guard Corps, is being blamed for the campaign. The group, also known as Shahid Kaveh, has previously breached U.S. water and wastewater facilities, though never at this scale. In November 2023, CyberAv3ngers compromised Unitronics programmable logic controller equipment at a Pennsylvania municipal water authority by exploiting an internet-exposed device that still used default credentials, and the group said at the time it targeted the equipment because the underlying software was made in Israel, defacing the system with a statement of its agenda. The U.S. State Department’s Rewards for Justice program has offered a $10 million reward since 2024 for information leading to the arrest of Iranian military officials connected to the group’s activities.
MNIT is now coordinating with the Minnesota Department of Public Safety, the FBI and other state and federal authorities to support the affected communities and reinforce the security of the state’s critical infrastructure. Officials say the drinking water in the targeted municipalities remains safe and that no city has asked residents to change how they use tap water.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543