South St. Paul officials said a cybersecurity incident affected automated controls supporting parts of the Minnesota city’s water utility Monday, but drinking water remained safe and water and wastewater services continued normally.
Public works employees implemented established contingency procedures after the incident was identified early Monday, allowing the city to maintain operations. “Drinking water remains safe,” the city said. Residents did not need to take action.
The disruption affected technology supporting portions of the utility, not the safety of the water supply or the city’s ability to provide water and wastewater services. South St. Paul, a Dakota County community of about 20,500 people immediately south of St. Paul, operates municipal water and wastewater services.

The city said it was working with technology partners and coordinating with state and federal agencies. Staff continued monitoring the system and working to restore normal automated operations.
The incident occurred the same morning Plymouth and Braham reported cyberattacks affecting water infrastructure. Plymouth said two water towers and several lift stations were affected beginning overnight Sunday, while Braham’s well and water treatment plant briefly went offline.
Plymouth said water remained safe and service continued. Braham’s plant returned to service in less than two hours, and officials there said water quality and safety were not affected. Braham officials said they had been told at least four other communities experienced similar attacks, but they did not identify them or publicly link the incidents to one actor.
Five days before the Minnesota incidents, federal agencies updated an advisory warning that Iran-affiliated actors were targeting internet-connected programmable logic controllers used by U.S. critical infrastructure operators. The agencies said the activity had caused operational disruptions, including erased configurations, manipulated sensor readings and interference with control system interfaces. No agency or affected city has publicly linked the South St. Paul, Plymouth or Braham incidents to that activity.
The South St. Paul incident also follows a March ransomware attack that disrupted automated controls at the water treatment plant in Minot, North Dakota. Operators took manual readings for about 16 hours while water service remained safe.
South St. Paul is also the third Twin Cities municipality with St. Paul in its name to disclose a cyber incident within a year, after broader incidents in St. Paul and North St. Paul. Officials have not linked the cases.
South St. Paul said water and wastewater service remained reliable while the investigation continued and employees worked to restore normal automated operations.
Officials had not disclosed how the systems were accessed, what equipment or software was affected, whether malware or ransomware was involved, or whether the incident was related to the Plymouth and Braham incidents or the activity described in the federal advisory.
No threat actor or specific attack method had been confirmed. DysruptionHub found no public ransomware claim at the time of publication.