Cyber Incident Victim: Maple Plain Water Utility
Timeline
Summary
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack targeting operational technology, with no ransom detected and water service maintained. Facilities in several cities, including Maple Plain, experienced technology malfunctions that prompted manual operation; Braham’s plant was offline for under two hours before restoration. State officials said the attacks prompted a statewide response involving MNIT, the FBI and the Bureau of Criminal Apprehension to investigate and strengthen defenses.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Sunday and Monday, a coordinated cyberattack targeted the operational technology of more than thirty community water systems across Minnesota, prompting a statewide response. Minnesota IT Services reported that the attacks focused on operational technology, caused temporary equipment malfunctions, and did not involve ransomware, allowing water service to continue uninterrupted. The attacks were first identified after several cities reported unusual technology behavior to state officials on Monday morning. Officials in Plymouth noted technology malfunctions at some facilities Sunday night and switched to manual backup to maintain service, while officials in Braham said their system was offline for under two hours after crews isolated it. In addition, officials in Maple Plain, along with those in other communities from Maple Plain to South St. Paul, described similar problems over the past two days, indicating that the utility was among those affected. The agency did not release a list of impacted communities, citing state law that treats cyberattack reports as nonpublic information.

Despite the technical disruptions, public water service remained uninterrupted in the affected areas, with officials emphasizing that checks and controls allowed manual operation to preserve water quality and quantity. State authorities, working with local, tribal, and federal partners, launched an investigation involving the Minnesota Bureau of Criminal Apprehension and the FBI to determine the nature and source of the attack. Minnesota’s chief information security officer stressed the need for a whole‑of‑government response, highlighting ongoing efforts to share intelligence, support affected utilities, and strengthen defenses against future incidents. The incident underscored the vulnerability of critical infrastructure, coming after a year in which only nine cyberattacks on such systems had been recorded, and followed an executive order issued by Governor Tim Walz in 2022 that mandated annual assessments, certified reporting, and response plans for water and other essential services.
