Monday morning in Braham, Minnesota, population 1,900, the water plant went dark. Automated controls — dead. Public works crews scrambled to isolate the system, load a backup, and restart everything manually. It took about 90 minutes, according to CBS Minnesota. Across the state, 35 other municipal water systems were experiencing the same thing simultaneously. No ransom demands arrived. No data was stolen. This wasn’t a shakedown. Investigators believe it was a message — and they believe it came from Iran.
A Coordinated Strike, Not a Random Hack
More than 36 community water systems were hit over 48 hours, targeting the physical hardware that moves municipal drinking water.
Minnesota IT Services disclosed the coordinated attack on July 28, according to Reuters, confirming that hackers targeted operational technology — the digital controls running pumps, wells, water towers, and wastewater lift stations. OT isn’t office email servers; it’s the physical muscle that opens valves and moves water through pipes. In Plymouth, attackers compromised equipment connected via cellular communications at two water towers and multiple lift stations. The city’s IT team disconnected everything and ran systems by hand. South St. Paul activated contingency procedures. Maple Plain declared a local state of emergency.
Water remained safe across all affected communities — no boil-water advisories issued. But “safe” and “secure” aren’t the same thing.
Former senior FBI official Cynthia Kaiser told the New York Times that “almost every initial assumption of attribution turns out to be true,” noting the attack’s hallmarks — disruption without profit motive — align with Tehran’s documented interest in U.S. water systems. Security researchers at Tenable flagged tactical similarities to CyberAv3ngers, a group formally tied to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command, echoing patterns seen in covert operations tracked via surveillance app deployments by state-sponsored actors. CISA’s acting director referenced an existing advisory warning of exactly this scenario.
Old Infrastructure, New Enemies
Small-town water operators are expected to fend off nation-state hackers with skeleton crews and controllers that predate most streaming services.
Braham’s mayor, Nate George, put it bluntly to the New York Times: local governments face foreign adversaries with limited staff, aging technology, and inadequate resources. Since U.S.–Iran military conflict resumed in February 2026, Iranian cyber operations have escalated sharply — including a March hack on medical equipment supplier Stryker that forced a companywide shutdown. Metro State cybersecurity professor Faisal Kalim warned the Minnesota attack “could have been much more severe,” noting hackers targeted systems that, if manipulated differently, could cause physical damage.
The technical exposure is stark. Rockwell Logix controllers vulnerable to CVE-2021-22681 can be accessed without authentication, according to Security Boulevard. No vendor patch exists. The known fixes read like a checklist from 2021:
- Pull PLCs off the internet
- Segment networks
- Keep offline backups
Officials acknowledge the slim possibility of a false-flag operation mimicking Iranian tradecraft, though experienced analysts consider that scenario unlikely given current evidence.
The investigation remains active, and attribution could still shift. But the uncomfortable reality is already clear: America’s water infrastructure runs on aging hardware, skeleton crews, and the assumption that someone can sprint to the control room fast enough when the screens go black. Reviewing reliable security systems has never been more urgent for communities that cannot afford to rely on luck alone. That’s not a cybersecurity strategy. That’s luck.





























