DeNexus Blog - Industrial Cyber Risk Quantification

Braham Water Cyberattack: Anatomy of a Level 3 OT Incident

Written by Donovan Tindill | Jul 29, 2026, 2:56:19 PM

The cyberattack stopped Braham’s well and water-treatment plant for just under two hours, but water stored in the city’s tower kept customers supplied. A five-level impact scale helps distinguish this verified operational effect from both lower-impact IT incidents and more serious events involving service outages, physical damage or public-safety consequences.

Assessment current to 28 July 2026. The investigation remains ongoing.

1. What happened in Braham

On 27 July 2026, the City of Braham, Minnesota, reported that its water-treatment plant was offline for an initially unknown reason. Just under two hours later, the city said the facility had returned to operation and attributed the outage to a malicious cyberattack against its computerized operating systems by unknown actors.

According to the city’s public statements, the attack shut down the facility’s operating controls, resulting in both the well and the water-treatment plant going offline. Officials reported no physical damage to the facility and no impact on water quality or safety. During the interruption, water stored in Braham’s water tower continued supplying residents. The city temporarily asked customers to conserve water until production and treatment were restored [1][2][3].

The most precise description is therefore:

The cyberattack interrupted water production and treatment, but it did not interrupt water distribution to customers.

That distinction matters. This was not merely an administrative IT outage: the incident reached the operational technology (OT) environment and stopped physical processes. However, it was also not a loss of drinking-water service, a contamination event or a destructive attack. Storage capacity and rapid restoration (both good practice risk mitigation measures) prevented the process interruption from becoming a customer-facing outage.

Using the five-level framework introduced below, I classify Braham as a Level 3 cyber incident: a verified physical-process interruption without physical damage, unsafe water or loss of customer service.

Several other Minnesota communities reported similar incidents. Plymouth experienced communications outages involving two water towers and multiple wastewater lift stations. The city said the issue was limited to equipment connected through cellular communications, while personnel continued normal operations using manual procedures. South St. Paul reported effects on some automated controls, and Maple Plain reported effects on certain automated control functions, but both maintained normal water and wastewater operations [2][4].

The timing and operational similarities make a common campaign plausible. They do not yet prove one. No public evidence has established a common threat actor, shared indicators of compromise, a common equipment vendor, a shared cellular platform or remote-access service, or the same initial access method across the affected municipalities.

 

2. The government warning preceded the Minnesota incidents

The Minnesota events did not occur without warning of increased cyber activity against water-sector OT.

On 7 April 2026, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy, US Cyber Command’s Cyber National Mission Force and Department of the Treasury issued joint advisory AA26-097A. It warned of urgent and ongoing Iranian-affiliated targeting of internet-connected OT devices, including programmable logic controllers (PLCs), across water and wastewater, energy, government and other US critical-infrastructure environments [5][6].

The agencies had already observed operational consequences. According to the advisory, malicious interactions with PLC project files and manipulation of information presented on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays had caused disruption and financial loss at some victims.

The 22 July update, five days before the Minnesota incidents, materially expanded the public evidence. The agencies reported that actors had:

  • Accessed internet-facing Rockwell Automation, Schneider Electric and Siemens PLCs, as well as potentially other makes of controller.
  • Used legitimate manufacturers’ programming applications to retrieve PLC project files.
  • Modified or deleted project logic.
  • Manipulated information presented through HMI and SCADA systems.
  • Disabled critical shutdown and alarm logic, potentially allowing systems to enter an unsafe condition without notifying operators.
  • At one victim, added logic that overrode instructions responsible for maintaining safe operating parameters while retaining other downstream process functions [5].

This was not presented as exploitation of a newly discovered zero-day vulnerability. The advisory explicitly describes opportunistic targeting of exposed or inadequately protected devices, often using legitimate engineering software and normal industrial protocols. That is an important correction to the assumption that serious OT consequences always require highly specialized malware or an unknown software flaw.

WaterISAC redistributed the updated advisory to the water sector on 22 July. Its public TLP:CLEAR notice emphasized the expanded PLC scope, the threat to project-file integrity, exposure through cellular modem architectures, and the need to remove controllers from direct internet access [7]. On 27 July, WaterISAC published a restricted TLP:AMBER member notification titled “Minnesota Fusion Center Reports Ongoing Malicious Cyber Activity Impacting Minnesota Water Utilities” [8]. The title, date and classification are public; its restricted contents should not be quoted or treated as public technical evidence.

Timing is relevant; timing is not attribution

As of 28 July, no affected city, Minnesota IT Services, CISA, the FBI, the EPA or WaterISAC has publicly connected the Minnesota incidents to the Iranian-affiliated actors described in AA26-097A.

The advisory and incidents are part of the same threat context, but there is no evidence to prove that Iranian actors attacked Braham, that AA26-097A techniques were used in Minnesota or that the incidents were state-sponsored. Those conclusions would exceed the available evidence.

 

3. A five-level impact severity scale for OT cyber incidents

The term “water cyberattack” covers events with materially different consequences. It can describe an unavailable billing portal, the loss of SCADA visibility, the interruption of a treatment process, a community water outage or physical damage.

The following scale classifies incidents according to their highest publicly verified consequence. It is an analytical framework for this article, not an official CISA or EPA taxonomy. It does not measure the sophistication, intent or identity of the attacker.

Severity Level

Highest verified consequence

Recent example and actual impact

Level 1 — Enterprise or administrative IT disruption

Customer, billing, email or corporate systems are affected, but water and wastewater operations remain unaffected.

American Water, October 2024: systems and the customer and billing platform were taken offline. The company reported no indication that water or wastewater facilities were affected and no impact on water quality [9].

Level 2 — Loss of monitoring, communications or automation

(OTI Severity levels 1-2)[20]

Normal visibility or automated control is unavailable, but operators maintain the physical process through manual or contingency procedures.

Minot, North Dakota, March 2026: ransomware affected a SCADA server, requiring more frequent manual gauge readings for approximately 16 hours. Water remained safe and service continued. Plymouth, July 2026: cellular communications to two towers and multiple lift stations were affected, but manual procedures maintained normal operations [4][10].

Level 3 — Physical-process interruption or manipulation

(OTI Severity levels 2-3) [20]

Production, treatment, pumping, valve operation or another physical process stops or changes, but customers continue receiving safe service.

Braham, July 2026: the well and treatment plant went offline for just under two hours. Tower storage continued supplying customers, with no reported physical damage or water-quality effect [2][3].

Level 4 — Customer service degradation or outage

(OTI Severity levels 3-7) [20]

A cyber-induced process effect reaches customers through reduced pressure, degraded service or loss of supply, without a confirmed physical-damage or safety consequence.

Unnamed Canadian water facility, October 2025: attackers tampered with water-pressure values at an internet-accessible industrial control system, resulting in degraded service to the community [11].

Level 5 — Physical damage or safety/environmental consequence

(OTI Severity levels 6-10) [20]

The event causes equipment or infrastructure damage, unsafe treatment, an uncontrolled release, flooding or bodily injury.

Tureby Alkestrup Waterworks, Denmark, December 2024: attackers changed water pressure, contributing to a burst pipe. About 450 homes reportedly lost water for approximately one hour, while around 50 were without water for about seven hours. No injury was reported [12].

This framework places Braham above incidents in which operators merely lost normal automation or visibility. A well and treatment plant physically stopped operating. It remains below Level 4 because stored water continued reaching customers, and below Level 5 because no equipment damage, unsafe treatment, release or injury was reported.

The severity level impact scale above is limited to this story, to help understand the different impacts that water incidents have had in the past. These levels represent Severity only, they do not incorporate the Reach or Duration. Using the OT Impact Score [20] (https://impact.icsadvisoryproject.com/), the Braham Water incident is in the Minimal impact category because it was a small region with very short duration.

Incident Name

Braham Water (July 2026)

Severity Scale

3: Delivery of product or service is slightly degraded.

Reach Scale

2: Small to medium size city/metro area or medium size company.

Duration Scale

3: Minor degradation rectified in less than six hours.

OTI Impact

0.2 – Minimal

Severity and duration remained low because storage was an operational resilience buffer. It separated the production-and-treatment interruption from the customer experience. The same event could have had a different outcome under different tower levels, demand conditions or restoration times, but the public information does not establish how long Braham could have continued supplying customers.

The examples also should not be treated as a statistically representative incident dataset. Disclosure practices, incident detection and government attribution vary widely. The table shows the range of recent realized consequences, not an independently calculated attack rate.

There is nevertheless credible official evidence of increasing activity. The EPA said in October 2025 that cyberattacks against water systems had increased several-fold in recent years. The Canadian Centre for Cyber Security separately assessed that ransomware incidents against critical infrastructure, including the water sector, were almost certainly becoming more frequent, costly and complex to remediate [13][14].

 

4. Prevent, constrain and sustain

Preventing a Level 2 or Level 3 incident from progressing into Levels 4 or 5 requires more than a single cybersecurity control. Three complementary capabilities are involved:

  1. Prevent unauthorized access and modification.
  2. Constrain what a compromised digital system can physically cause.
  3. Sustain safe service while normal systems and external connections remain unavailable or untrusted.

Prevent access and unauthorized modification

AA26-097A provides threat-specific actions for the activity the federal agencies observed. These include removing PLCs from direct internet exposure; securing cellular modems and remote-access architecture; allowing only authorized communications to controllers; using physical or software programming protection; comparing running controller logic with known-good project files; validating backups before restoration; examining connected modems, HMIs and engineering workstations; and using multifactor authentication and controlled gateways for external OT access [5][7].

These are not novel controls, but the advisory demonstrates why they matter. An attacker does not necessarily require custom industrial malware when a PLC programming interface is reachable, legitimate engineering software can communicate with it and modification protections are absent or inadequately configured.

Water owners and operators should use the complete government advisory and relevant manufacturer guidance rather than treating a shortened article summary as an implementation checklist.

Constrain the physical consequences through Cyber-Informed Engineering

Cyber-Informed Engineering (CIE) addresses a different question. Traditional cybersecurity asks how to prevent an adversary from reaching or changing a system. CIE also asks what the adversary could physically cause after gaining access—and how engineering design can eliminate or limit that consequence.

Idaho National Laboratory describes CIE as integrating cybersecurity into infrastructure design and operation. Its underlying premise is that even well-defended systems can eventually be compromised, so infrastructure should be engineered to minimize damage or fail safely when exposed to a cyber-enabled threat [19].

For a water or wastewater utility, the unacceptable physical consequences may include:

  • Excessive or inadequate chemical dosing.
  • Tank depletion or overflow.
  • Loss of pressure or an excessive pressure excursion.
  • Rapid pump cycling, dead-heading, cavitation or water hammer.
  • Operation of incompatible process states.
  • Uncontrolled wastewater discharge or environmental release.
  • Loss of trustworthy process indication.
  • Damage to pumps, drives, valves or treatment equipment.

CIE then asks which safeguards remain effective when the networked control path is compromised. Depending on the process, these could include independently derived pressure, level or dosing measurements; hardwired high and low limits; mechanical or hydraulic protection; local physical mode selection; rate-of-change or equipment duty-cycle constraints; and independent shutdown functions that do not depend on the same programmable controller, communications path or operator display as routine control.

These are engineering examples, not universal design prescriptions. Every safeguard must be evaluated against the specific hydraulic process, treatment chemistry, equipment design and regulatory obligations. An incorrectly designed interlock can create a hazard of its own.

The relevant engineering implication from AA26-097A is straightforward: where an attacker can alter PLC logic, HMI values, alarms and automated shutdown functions, the highest-consequence protections should not all depend on the integrity of that same digital path.

Sustain critical service during prolonged isolation

Recent allied guidance extends resilience planning beyond short incident-response windows.

Canada’s Critical Infrastructure Resilience and Escalated Threat Navigation initiative, or CIREN, says essential-service operators should be prepared to isolate systems for up to three months, operate independently and rebuild systems following a severe cyber incident [15]. Australia’s CI Fortify guidance similarly calls for the ability to isolate vital OT and enabling systems for three months while maintaining critical services, and to rebuild those systems completely when existing environments or backups cannot be trusted [16].

The United Kingdom’s National Cyber Security Centre advises critical national infrastructure organizations to prepare for attacks capable of shutting critical operations for extended periods, corrupting recovery data and damaging industrial control systems. Its guidance emphasizes continued operation and recovery while the threat remains active [17]. CISA’s US CI Fortify initiative similarly focuses on maintaining a baseline continuity of essential services through isolation and recovery [18].

This should not be reported as a government prediction of three-month water outages. The recommendation is to ensure that essential services can continue while normal connectivity, automation, vendors, telecommunications or corporate systems remain unavailable or cannot yet be trusted.

For water-sector operators, that requires four areas of engineering and operational evidence.

  • Minimum safe service: The utility must identify which wells, pumps, treatment stages, storage facilities, laboratory functions and wastewater assets are required to maintain a defined minimum safe operating state.
  • External dependencies: The analysis must account for cellular communications, corporate identity services, cloud-hosted functions, remote vendor support, telecommunications, electrical power, fuel, treatment chemicals and other services that may sit outside the isolation boundary.
  • Operational endurance: Manual operation must be assessed over weeks or months, not only during a short exercise. Staffing, shift coverage, travel to remote stations, manual sampling, fatigue, consumables and critical spares may become the limiting factors.
  • Trusted recovery: The organization needs tested offline copies of firmware, PLC project files, HMI configurations, documentation and operating procedures, together with compatible replacement equipment and defined criteria for determining that process logic, instrumentation, alarms and safety functions are trustworthy before reconnection.

Braham demonstrates the value of one such resilience layer: stored water gave operators time to restore production without interrupting supply. A prolonged-isolation plan asks the next question—how long can that minimum safe service be sustained if restoration takes days or weeks rather than hours?

 

5. What remains unknown

Several unanswered questions could materially change the technical assessment of the Minnesota incidents:

  1. Which assets were affected? No PLC, remote terminal unit, HMI, SCADA application, modem, telemetry platform, firmware version or equipment manufacturer has been publicly identified.
  2. What caused the Braham shutdown? The public record does not establish whether an actor issued a direct stop command, changed project logic or configuration, interrupted communications, or caused equipment to enter a fail-safe state.
  3. Did the affected municipalities share a dependency? A common systems integrator, cellular provider, managed-service provider, remote-access product or equipment platform has not been confirmed.
  4. Do the forensic findings overlap AA26-097A? No government agency has publicly reported a match to the advisory’s indicators, infrastructure or techniques.
  5. What was the available resilience margin? Braham has not disclosed its tower level, customer demand or the length of time stored water could have maintained service. There is also no public confirmation concerning persistence, project-file theft, data exfiltration, ransomware or an extortion demand.

Until those questions are answered, statements that Iranian actors attacked Braham, that chemical dosing was manipulated, that the same actor attacked every city or that residents lost safe water would be unsupported.

 

Conclusion

Braham is appropriately classified as a Level 3 water-sector cyber incident. The incident reached the physical process and stopped the well and treatment plant, but it did not progress to loss of water service, physical damage, unsafe treatment, environmental release or injury.

We don’t what to minimize the event nor exaggerate it.

AA26-097A shows that threat actors are actively accessing internet-connected controllers, taking project files, modifying process logic and interfering with alarms and shutdown functions. It does not establish that those actors were responsible for the Minnesota incidents. The current evidence supports heightened attention, not premature attribution.

The practical response is also broader than improving perimeter security. Water owners and operators need to prevent unauthorized access, use Cyber-Informed Engineering to constrain unacceptable physical consequences, and maintain a minimum safe service while connected systems are isolated, investigated and rebuilt.

The objective is to ensure that a control-system compromise remains a contained operational incident rather than progressing into loss of safe water, equipment damage, environmental release or injury.

 

References

[1] Krueger, Andrew. “Officials in Minnesota Cities Say Cyberattacks Targeted Water Systems.” MPR News, 27 July 2026, updated 28 July 2026, https://www.mprnews.org/story/2026/07/27/braham-cyberattack-knocked-water-system-offline. Accessed 28 July 2026.

[2] Lentz, Nicholas. “Cyberattack Briefly Shuts Down Braham Water Plant, Targets at Least 4 Other Minnesota Communities.” CBS Minnesota, 28 July 2026, https://www.cbsnews.com/minnesota/news/cyberattack-malware-braham-water-plant-outage/. Accessed 28 July 2026.

[3] KSTP. “Cyberattack Blamed for Water Issues in Braham, Plymouth; Others Possibly at Risk.” KSTP 5 Eyewitness News, 27 July 2026, https://kstp.com/kstp-news/top-news/braham-water-plant-offline-residents-asked-to-conserve-water/. Accessed 28 July 2026.

[4] City of Plymouth. “Communications Outages at Plymouth Water Facilities, Water Levels and Quality Unaffected.” City of Plymouth, Minnesota, 27 July 2026, https://www.plymouthmn.gov/Home/Components/News/News/8977/542. Accessed 28 July 2026.

[5] Federal Bureau of Investigation, et al. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure. Joint Cybersecurity Advisory AA26-097A, originally published 7 Apr. 2026, updated 22 July 2026, https://www.ic3.gov/CSA/2026/260722.pdf. Accessed 28 July 2026.

[6] United States Environmental Protection Agency. “EPA, FBI, CISA, NSA Issue Joint Cybersecurity Advisory to Water System Regarding Iranian-Affiliated Cyber Attacks.” 7 Apr. 2026, https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian. Accessed 28 July 2026.

[7] Snow, Chase. “CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A).” WaterISAC, 22 July 2026, https://www.waterisac.org/tlpclear-cisa-updates-iranian-affiliated-plc-targeting-advisory-aa26-097a. Accessed 28 July 2026.

[8] Snow, Chase. “WaterISAC Notification—Minnesota Fusion Center Reports Ongoing Malicious Cyber Activity Impacting Minnesota Water Utilities.” WaterISAC, 27 July 2026, https://www.waterisac.org/tlpamber-waterisac-notification-minnesota-fusion-center-reports-ongoing-malicious-cyber-activity-impacting-minnesota-water-utilities. Accessed 28 July 2026. TLP:AMBER; member content restricted.

[9] American Water. “American Water Reactivating Systems After Cyber Event.” American Water Newsroom, 10 Oct. 2024, https://newsroom.amwater.com/2024-10-10-American-Water-Reactivating-Systems-After-Cyber-Event. Accessed 28 July 2026.

[10] Wood, Colin. “Water Treatment Plant in North Dakota Suffered Ransomware Attack.” StateScoop, 1 Apr. 2026, https://statescoop.com/minot-north-dakota-water-treatment-ransomware/. Accessed 28 July 2026.

[11] Canadian Centre for Cyber Security. “AL25-016: Internet-Accessible Industrial Control Systems Abused by Hacktivists.” 29 Oct. 2025, https://www.cyber.gc.ca/en/alerts-advisories/al25-016-internet-accessible-industrial-control-systems-ics-abused-hacktivists. Accessed 28 July 2026.

[12] Burrows, Emma. “Denmark Blames Russia for Cyberattacks on Water Utility That Left Houses without Water.” Associated Press, 19 Dec. 2025, https://apnews.com/article/russia-denmark-cyberattacks-moscow-putin-sabotage-d9776a44bf6b80574eb54a5edf64ee19. Accessed 28 July 2026.

[13] United States Environmental Protection Agency. “EPA Releases New Resources to Help Protect Water Systems, Strengthen Cyber Resilience.” 23 Oct. 2025, https://www.epa.gov/newsreleases/epa-releases-new-resources-help-protect-water-systems-strengthen-cyber-resilience. Accessed 28 July 2026.

[14] Canadian Centre for Cyber Security. The Cyber Threat to Canada’s Water Systems: Assessment and Mitigation. 25 Nov. 2025, https://www.cyber.gc.ca/en/guidance/cyber-threat-canadas-water-systems-assessment-mitigation. Accessed 28 July 2026.

[15] Canadian Centre for Cyber Security. “Critical Infrastructure Resilience and Escalated Threat Navigation Initiative.” 17 Apr. 2026, https://www.cyber.gc.ca/en/cyber-security-readiness/critical-infrastructure-resilience-escalated-threat-navigation-initiative. Accessed 28 July 2026.

[16] Australian Signals Directorate. CI Fortify: Guidance for Australian Critical Infrastructure Service Continuity and Resilience. Australian Cyber Security Centre, Oct. 2025, https://www.cyber.gov.au/sites/default/files/2025-10/CI%20Fortify.pdf. Accessed 28 July 2026.

[17] National Cyber Security Centre. “How to Prepare for and Plan Your Organisation’s Response to Severe Cyber Threat: A Guide for CNI.” 28 Jan. 2026, https://www.ncsc.gov.uk/collection/how-to-prepare-and-plan-your-organisations-response-to-severe-cyber-threat-a-guide-for-cni. Accessed 28 July 2026.

[18] Cybersecurity and Infrastructure Security Agency. “CISA Unveils New Initiative to Fortify America’s Critical Infrastructure.” 5 May 2026, https://www.cisa.gov/news-events/news/cisa-unveils-new-initiative-fortify-americas-critical-infrastructure. Accessed 28 July 2026.

[19] Menser, Paul. “Securing Water Systems against Cyber-Threats: Idaho Leads with Cyber-Informed Engineering.” Idaho National Laboratory, 6 Mar. 2025, https://inl.gov/feature-story/securing-water-systems-against-cyber-threats-idaho-leads-with-cyber-informed-engineering/. Accessed 28 July 2026.

[20] “OTI Impact Score Portal.” https://impact.icsadvisoryproject.com/methodology, Accessed 28 July 2026.