Cyber Incident Victim: City of South St. Paul
Date:
Jul 2026
Location:
United States of America
Summary
A cyberattack targeted municipal water systems in several Minnesota communities, including South St. Paul, disrupting automated controls but not affecting water quality or safety. Officials in the city reported that the incident impacted certain automated functions, yet contingency procedures allowed public works staff to maintain normal water and wastewater operations. The city coordinated with state and federal agencies to monitor the system, restore normal automated operations, and ensure continued service delivery.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Monday morning, officials in Braham, Minnesota, reported that its water treatment plant was offline for an unknown reason, and within two hours they identified the outage as resulting from a malicious cyber‑attack of computerized operating systems by unknown actors. The attack shut down the plant’s operating controls, which halted the well and water treatment processes, though officials emphasized that no physical damage occurred and water quality and safety remained unaffected. Braham’s public works crews quickly determined the issue and mediated the cause, restoring the plant to online status later that morning. The city’s statement also indicated that at least four other Minnesota communities had experienced the same type of cyber‑attack, though it did not name them. Later that afternoon, South St. Paul officials confirmed that their water utility system had been targeted as part of this broader incident, noting that the attack affected certain automated controls within the technology used for parts of the city’s water and wastewater infrastructure.

In response to the detected anomaly, South St. Paul’s public works staff immediately implemented established contingency procedures, which allowed them to maintain normal water and wastewater operations despite the disruption to automated functions. Officials assured residents that drinking water remained safe, that water and wastewater services continued fully operational, and that no action was required from the public. The city reported that staff were actively monitoring the system and taking the necessary steps to restore normal automated operations while preserving reliable service through manual processes where needed. South St. Paul officials also said they were collaborating with state and federal agencies, including Minnesota IT Services, which was providing cybersecurity and technical support to assess potential impacts, share threat information, and assist with response and remediation efforts.
Parallel disclosures from Plymouth and Maple Plain described similar patterns: Plymouth noted an issue affecting communications at two water towers and multiple lift stations that began late Sunday and was believed to stem from a cyberattack, while water levels and quality were unaffected and crews continued operating via manual procedures; Maple Plain reported an incident affecting certain automated control functions but confirmed that workers maintained normal operations. Across all affected communities, the consistent message was that essential water services remained uninterrupted, water quality was not compromised, and response efforts were focused on restoring automated controls and strengthening coordination with state and federal cybersecurity resources. The ongoing investigation seeks to identify the source of the attacks and address any vulnerabilities exposed by the incident.
