"offline for an unknown reason," Braham officials wrote on the city website — a blunt notification that prefaced a wider disruption that affected more than 30 Minnesota communities over Sunday and Monday, the state’s technology bureau said on Tuesday.
Minnesota Information Technology Services and the state response
Minnesota Information Technology Services (MN IT Services) said it has led a coordinated response that included "sharing threat intelligence, providing guidance on response efforts and best practices, and helping affected utilities contain, investigate, and remediate damages from the attack." The agency said it is working with state public safety and health departments, a state fusion center, and federal partners including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA) and the FBI.
John Israel, the state's chief information security officer, is quoted as saying the "whole-of-government response" worked as intended and helped "prevent more serious impacts to critical services." The statement casts the effort as damage limitation while investigations continue.
Local impacts: Braham and Plymouth
In Braham — a community of roughly 1,700 people — city officials posted that the water plant was "offline for an unknown reason" and asked residents to minimize water use because the water tower held only a "limited quantity." That same day the city later said the plant was back online and described the outage as "a malicious cyber-attack of computerized operating systems by unknown actors."
In Plymouth, a suburban city of about 80,000, a spokesperson said the city's IT division "disconnected the affected equipment from the network to stop the cyberattack and avoid any potential retargeting while the equipment is reconfigured." Plymouth reported the incident was limited to "equipment connected via cellular communications" at two city water towers and "multiple" lift stations, and emphasized that water quality was unaffected and "the water is safe and there is no need for the public to adjust consumption."
Threat advisories, suspected actors, and recent related activity
The Minnesota state government and several local governments contacted for this story declined to name who attacked the state's water utilities; the article notes that "Iran is a reasonable guess," citing a recent, urgent CISA advisory warning of ongoing attempts by Iranian hacking groups — including CyberAv3ngers — to target internet-connected operational technology devices such as programmable logic controllers (PLCs).
The story also cites recent regional events: U.S. strikes this month along Iran's southern coast that destroyed a water facility and cut off water access to more than 20,000 people, and a claim by the hacker group Hanzala that it had breached water utility systems in several California cities while (the group said) restraining itself from disrupting supplies. Joshua Corman of the Institute for Security and Technology warned that recent advisories "should give everyone nightmare fuel" and argued that some adversaries are motivated to "disrupt and destroy at a time and place of their choosing."
Technical uncertainty and the evolving cyber threat
TJ Sayers, senior director of threat intelligence at the Center for Internet Security, noted in an emailed statement that the Minnesota attacks have not yet been attributed to any particular party and that "it is unclear" whether programmable logic controllers were involved. Sayers also wrote that offensive cyber activity of this nature is expected to "greatly accelerate in the short-term with the continued release of frontier AI models," with a possible plateau in the mid- to long-term as the same models are applied defensively.
The article reiterates longer-term vulnerability assessments: the EPA warned in 2024 that more than 70% of water systems were failing to comply with a provision of a 2018 law requiring updated risk assessments and emergency response plans, and an audit of 1,000 water systems serving 193 million people found 97 systems with critical- or high-risk vulnerabilities. Those gaps intersect with Corman’s concern that many utilities lack the capacity to operate without their Supervisory Control and Data Acquisition (SCADA) systems; Corman said the recent national cyber drill "saw 'a really tiny participation rate'" when participants were asked if they could run a facility for one day without SCADA.
What this means for technologists, policymakers, and the general public
- Technologists and security teams: Expect investigators to continue sharing threat intelligence and guidance — MN IT Services already is coordinating with federal partners — while defenders must validate whether internet-connected devices and cellular-linked equipment were vectors.
- Policymakers and regulators: The EPA’s 2024 compliance findings and the audit of 1,000 systems provide concrete policy levers; regulators will face pressure to enforce risk-assessment and incident-response requirements now that multiple utilities have been disrupted.
- The general public and critical-care operators: Local officials emphasized that, in these incidents, water quality remained unaffected, but small utilities with limited storage could see rapid operational strain — Corman warned hospitals relying on local water reserves might exhaust usable supplies within "two to four hours" in a worst-case outage.
The immediate record is one of coordinated disruption, defensive containment, and unanswered questions: more than 30 communities experienced interruptions, MN IT Services and federal partners are engaged, and officials have not yet attributed the attacks or confirmed whether PLCs were used. The state’s leader in cybersecurity framed the response as successful at limiting damage, while outside observers point to an intensifying threat environment that includes novel tools and recent regional provocations. The next steps hinge on forensic findings and whether investigators can tie the intrusions to known threat actors or techniques — and on whether under-resourced utilities can close the gaps the EPA and auditors have already documented.




