Braham
Incident posture
Timeline
Summary
Braham’s water plant was taken offline after a cyberattack compromised its operational controls, prompting officials to ask residents to conserve water while they switched to a backup supply and restored service within a few hours. The attack was part of a broader coordinated effort that targeted more than thirty water systems across Minnesota and later spread to facilities in several other states, disrupting remote monitoring and control equipment but leaving water quality unaffected. Investigators have not identified a perpetrator, though officials have noted similarities to known Iran‑linked hacking activity and continue to examine the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In late July 2026 the city of Braham, Minnesota, with approximately 1,700 residents, experienced a cyberattack that took its water treatment plant offline, prompting officials to ask residents to conserve water while they relied on the backup supply stored in the local water tower. Plant operators discovered that the well was not operating despite the water tower calling for water, leading them to isolate the computerized control system and switch to manual control. Within a couple of hours crews restored flow by taking manual control of the pump, and the city reported that water quality was not affected. Braham’s annual Pie Day celebration proceeded as scheduled just days later. The outage led to a temporary request for residents to avoid using water for lawns or recreational purposes, which was lifted once normal service resumed.
Soon after Braham’s incident, Minnesota state officials reported that more than 30 community water systems across the state had been targeted in a coordinated cyberattack, with similar disruptions reported in communities such as Plymouth, Maple Plain, and others. The attacks extended beyond Minnesota, with local authorities in New Jersey, South Dakota, and Georgia acknowledging they had been affected, and Michigan joining the list after receiving a federal cyber alert about attempts to tamper with operational technology at water systems. In several locations officials issued brief boil‑water advisories or asked residents to minimize use, though no known impacts to public health were reported and the Minnesota Department of Health said it was unaware of any active requests for residents to modify drinking water usage. Response actions included local operators shifting affected facilities to manual control, state IT teams assisting with investigations, and the FBI confirming awareness of recent public reporting around the water and wastewater sectors. The Cybersecurity and Infrastructure Security Agency issued advisories urging water systems to be removed from the internet and to reset passwords, while WaterISAC convened a call for its members to share intelligence from federal authorities.
U.S. and state officials briefed on the investigation told The New York Times that Iranian hackers were likely behind the cyberattack, citing the tradecraft used and the absence of a ransom demand, although Minnesota IT Services noted the investigation remained active and no specific actor had been formally attributed. President Donald Trump publicly blamed Minnesota officials for the attacks, asserting that Iran had bigger problems than worrying about the state, while Governor Tim Walz responded that Trump knew exactly who was responsible and that other states had been hit too. The FBI, CISA, and other agencies continued to monitor the situation, and officials emphasized that the quick restoration of service demonstrated the effectiveness of manual controls and backup supplies, with ongoing efforts to gather data on how the attackers gained access. The incident concluded with water systems returning to normal operation and authorities maintaining vigilance for any further malicious activity.
Sources
Sources available to members: 7 sources.