Skip to content

Maple Plain water utility cyber incident

Summary

City of Maple Plain logo

A cybersecurity incident affected automated controls supporting Maple Plain’s municipal water utility on July 27, 2026, but contingency procedures kept drinking water safe and water and wastewater services fully operational. Maple Plain was among more than 30 Minnesota water-system attacks; public attribution remained open despite reports that anonymously briefed officials suspected Iranian hackers.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Maple Plain, Minnesota, experienced malicious cyber activity affecting automated controls used to support its municipal water utility. The city’s press release said employees identified the incident early July 27, took quick action and used established contingency procedures to maintain normal operations. The city did not identify the affected controls or disclose the exact time normal automation resumed.

The incident was part of a broader cluster. FOX 9 reported that Minnesota IT Services characterized activity against technology at more than 30 community water systems during July 26–27 as a coordinated cyberattack. Maple Plain was among the initially disclosed municipalities.

Operational significance

Automated controls support reliable monitoring and operation of municipal water infrastructure. Their loss or degradation required contingency procedures, indicating a real disruption to normal utility operations even though the city maintained public service. Maple Plain said drinking water remained safe, water and wastewater services stayed fully operational, and residents did not need to act.

Later Associated Press reporting said most confirmed Minnesota incidents involved technology used to remotely monitor and control water equipment. Minnesota IT Services described the attacks as taking place July 26–27 and said July 30 that there were no active community requests for residents to modify drinking-water use.

A July 11 boil-water advisory followed a pressure loss that the city attributed to a communication failure between its water tower and treatment plant. No reviewed source links that earlier event to the July 27 cyber incident, so DysruptionHub does not treat it as a cyber-related impact.

Disclosure posture

Maple Plain’s notice gave clear public-safety and continuity information and said the City Council convened an emergency meeting to review the response. It did not identify the affected equipment, access method, system changes, actor or precise restoration time. The state’s later statements added campaign scale, technology context and an end to the observed attack window while preserving uncertainty about whether one culprit caused every incident.

Current status

The incident is assessed as resolved. Maple Plain reported quick containment and fully operational services on July 27, Minnesota IT Services later confined the coordinated attack activity to July 26–27, and no evidence of continuing Maple Plain operational impact was found. The absence of a city-specific controller-restoration timestamp remains a technical documentation gap, but it does not justify treating the attack as operationally active.

Confidence and uncertainty

Confidence is high that malicious activity affected Maple Plain’s water-utility control technology because the city confirmed the cybersecurity incident and Minnesota officials later confirmed malicious activity involving remote monitoring and control systems across the wider cluster. Confidence is also high that contingency procedures maintained safe water and uninterrupted service because Maple Plain directly addressed those outcomes.

Attribution remains unresolved. Axios reported that anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. The same report said Minnesota IT Services had not attributed the activity to a specific actor, and AP reported that neither state officials nor the FBI had publicly identified a culprit. DysruptionHub treats the Iran link as an unconfirmed investigative hypothesis, not attribution of Maple Plain’s incident.

The public record does not support confirmed ransomware or extortion. No ransom demand, threat-actor listing, payment request, encryption claim or data-theft allegation was found. Data impact also remains unresolved because sources do not establish whether operational, administrative or customer information was accessed, copied, altered or removed.

Analytic gaps

The reviewed public sources do not establish the initial access vector, compromised account or device, internet exposure, vulnerability, affected controller or software vendor, configuration change, malware, persistence, dwell time, network segmentation, data-access scope, restoration method or exact automation-restoration time. They also do not establish whether Maple Plain’s incident shared infrastructure, tooling or command-and-control with the other Minnesota water-system incidents or which actor was responsible.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: High

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

Minnesota IT Services characterized the July 26-27 activity against more than 30 community water systems as coordinated, and Maple Plain was among the publicly identified municipalities. City statements independently document a cyber incident affecting automated water controls and requiring contingency procedures; the membership does not establish common infrastructure or actor attribution.

Organizations involved

Impacted location

Sources

Maple Plain, Minnesota, keeps water running after cyber incident

A cybersecurity incident affected automated controls supporting Maple Plain’s water utility, but city employees used contingency procedures and maintained uninterrupted water and wastewater service. Officials said drinking water remained safe and did not identify the affected controls or restoration status.

Cybersecurity incident update

The City of Maple Plain said automated water utility controls were affected, contingency procedures kept water and wastewater services operating, drinking water remained safe, and the city declared a local state of emergency while responding.

Press Release: Cyber Security Incident

The City of Maple Plain said a cybersecurity incident affected automated controls supporting its water utility. Employees used contingency procedures, drinking water remained safe, water and wastewater services stayed fully operational, and residents did not need to take action.

More than 30 Minnesota water systems targeted in cyberattack

FOX 9 reported that Minnesota IT Services described a coordinated cyberattack targeting technology at more than 30 community water systems during July 26–27. Maple Plain was among the initially disclosed municipalities, and state response capabilities were activated.

Report: Iranian hackers likely behind Minnesota municipal water cyberattack

Axios relayed New York Times reporting that three anonymous state officials briefed on the investigation believed Iranian hackers were probably responsible. Axios also reported Minnesota IT Services’ public statement that the active investigation had not attributed the activity to a specific actor.

Cyberattacks on Minnesota water systems investigated as officials warn about Iranian hackers

AP reported that Minnesota IT Services described the coordinated attacks as taking place July 26–27 and said no active community drinking-water-use modification requests remained July 30. Most confirmed incidents involved technology used to remotely monitor and control water equipment; investigators had not determined whether one actor caused every incident.

See something that needs correction?

Signed-in members can report an error, update, or missing source.