CSIDB logo
Incident

Braham

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-06 17:35

Linked entities

Victim
Braham
Threat actors
1 actor
Sources
7 sources

Timeline

Occurred
Jul 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Jul 2026

Summary

Braham’s water plant was taken offline after a cyberattack compromised its operational controls, prompting officials to ask residents to conserve water while they switched to a backup supply and restored service within a few hours. The attack was part of a broader coordinated effort that targeted more than thirty water systems across Minnesota and later spread to facilities in several other states, disrupting remote monitoring and control equipment but leaving water quality unaffected. Investigators have not identified a perpetrator, though officials have noted similarities to known Iran‑linked hacking activity and continue to examine the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late July 2026 the city of Braham, Minnesota, with approximately 1,700 residents, experienced a cyberattack that took its water treatment plant offline, prompting officials to ask residents to conserve water while they relied on the backup supply stored in the local water tower. Plant operators discovered that the well was not operating despite the water tower calling for water, leading them to isolate the computerized control system and switch to manual control. Within a couple of hours crews restored flow by taking manual control of the pump, and the city reported that water quality was not affected. Braham’s annual Pie Day celebration proceeded as scheduled just days later. The outage led to a temporary request for residents to avoid using water for lawns or recreational purposes, which was lifted once normal service resumed.

Soon after Braham’s incident, Minnesota state officials reported that more than 30 community water systems across the state had been targeted in a coordinated cyberattack, with similar disruptions reported in communities such as Plymouth, Maple Plain, and others. The attacks extended beyond Minnesota, with local authorities in New Jersey, South Dakota, and Georgia acknowledging they had been affected, and Michigan joining the list after receiving a federal cyber alert about attempts to tamper with operational technology at water systems. In several locations officials issued brief boil‑water advisories or asked residents to minimize use, though no known impacts to public health were reported and the Minnesota Department of Health said it was unaware of any active requests for residents to modify drinking water usage. Response actions included local operators shifting affected facilities to manual control, state IT teams assisting with investigations, and the FBI confirming awareness of recent public reporting around the water and wastewater sectors. The Cybersecurity and Infrastructure Security Agency issued advisories urging water systems to be removed from the internet and to reset passwords, while WaterISAC convened a call for its members to share intelligence from federal authorities.

U.S. and state officials briefed on the investigation told The New York Times that Iranian hackers were likely behind the cyberattack, citing the tradecraft used and the absence of a ransom demand, although Minnesota IT Services noted the investigation remained active and no specific actor had been formally attributed. President Donald Trump publicly blamed Minnesota officials for the attacks, asserting that Iran had bigger problems than worrying about the state, while Governor Tim Walz responded that Trump knew exactly who was responsible and that other states had been hit too. The FBI, CISA, and other agencies continued to monitor the situation, and officials emphasized that the quick restoration of service demonstrated the effectiveness of manual controls and backup supplies, with ongoing efforts to gather data on how the attackers gained access. The incident concluded with water systems returning to normal operation and authorities maintaining vigilance for any further malicious activity.

Sources

Sources available to members: 7 sources.

CSIDB