Skip to content

Maple Plain, Minnesota, keeps water running after cyber incident

Automated utility controls were affected, but the city said drinking water remained safe and water and wastewater services stayed fully operational.

White elevated water tower against a blue sky with antennas mounted on top and a green maple-leaf logo reading “Maple Plain” on the tank.
Maple Plain’s 400,000-gallon water tower, built in 1988, carries the city’s name and maple-leaf logo. (Minnesota Water Towers)

A cybersecurity incident affected automated controls supporting Maple Plain’s water utility Monday, but the Minnesota city said its drinking water remained safe and water and wastewater services continued without interruption.

City employees used contingency procedures to maintain normal operations after identifying the incident early Monday, according to a city news release. Maple Plain did not identify the affected controls or say whether they had been restored.

The affected technology supported water infrastructure. Maple Plain is a small city in western Hennepin County, about 20 miles west of Minneapolis.

Screenshot of a City of Maple Plain Facebook post announcing a July 27, 2026, cybersecurity incident affecting automated water utility controls. The post says contingency procedures kept water and wastewater services operating, drinking water remained safe, and the city declared a local state of emergency while responding.
The City of Maple Plain said in a July 27 Facebook post that a cybersecurity incident affected automated water utility controls, but drinking water remained safe and water and wastewater services continued without interruption. (City of Maple Plain)

The City Council held an emergency meeting Monday afternoon to review the response and measures to protect critical infrastructure and public services. Officials said residents did not need to take action.

Maple Plain was the fourth Minnesota municipality to publicly report a July 27 cyber incident involving water or wastewater technology.

In Braham, a cyberattack disabled computerized operating controls and temporarily shut down the city’s well and water treatment plant. Public works crews restored the plant within about two hours, and officials said the drinking water remained safe.

Plymouth reported a suspected cyberattack that disrupted cellular communications with two water towers and several wastewater lift stations. Crews used manual procedures, and officials said water levels, water quality and service were unaffected.

South St. Paul said a cybersecurity incident affected some automated water utility controls, but employees maintained normal water and wastewater operations through contingency procedures. The city also said its drinking water remained safe.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

Braham officials said they had been told that at least four other communities were attacked “with the same result.” Maple Plain’s disclosure means at least one municipality referenced by Braham has not been publicly identified.

The cities used different descriptions for the incidents. Braham confirmed a cyberattack, Plymouth said it suspected one, and Maple Plain and South St. Paul described cybersecurity incidents without identifying an attack method.

Federal agencies had recently warned that Iranian-affiliated cyber actors were targeting internet-facing programmable logic controllers used across U.S. critical infrastructure, including water systems. The advisory said the activity could disrupt operations by manipulating industrial controls and display data.

Officials have not linked the Minnesota incidents to that campaign. They also had not disclosed how Maple Plain’s systems were accessed, which equipment or software was affected, or whether data was accessed or stolen.

No ransom demand or threat actor had been identified, and officials had not confirmed whether the four incidents shared an attacker, technology provider or vulnerability.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Critical Infrastructure

See all

More from DysruptionHub Staff

See all