How Hackers Penetrated Local Water Plants from Braham, Minnesota, to the East Coast

In mid-2026, the homemade pie capital of Minnesota, Braham, lost its entire water supply when an intruder silently took control of the city’s computer systems. Within hours, dozens of other Minnesota cities discovered their water and wastewater utilities had been compromised, and the alarm quickly spread to at least a dozen states — from the Midwest to New Jersey. US officials have attributed the attack to Iran, making it one of the most widespread cyber intrusions yet against America’s critical infrastructure.

The attack did not use exotic malware. Instead, it exploited a painfully simple weakness: programmable logic controllers (PLCs) that operate pumps, chemical feeds, and reservoir levels were sitting on the open internet, often protected by nothing more than a default username and password — if that. Hackers simply logged in as the intended operator and started pulling levers. Temporary service disruptions, boil-water notices, and even local flooding followed. Braham’s 1,800 residents went without water for several hours before the utility regained control.

Water systems are among the oldest pieces of US infrastructure, many built before the internet existed. Over the past decade, municipalities rushed to connect these legacy systems to remote monitoring and control, a trend accelerated by the pandemic. But the “upgrades” left them exposed to modern cyber threats without modern defenses. No deaths or lasting outages resulted from last week’s intrusion, but the incident has exposed a systemic vulnerability that adversaries have been probing for years.

The ‘Flimsiest of Padlocks’: Why Tiny Water Systems Became a Geopolitical Target

‘No Password, No Firewall, No VPN’ — The Anatomy of a Water Plant Hack

The technical barrier to entry was practically nonexistent. PLCs, originally designed to be accessed only inside locked, secure facilities, were found on publicly visible web pages with no authentication. “These were devices with no password, no firewall or VPN shielding them — they just had to log in as whoever the intended operator was,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit that helps critical infrastructure resist hackers. “Any sociopath from anywhere in the world can see these things on the internet.”

Advertisement

The Small-System Problem: 97% of Water Utilities Are Ill-Equipped

About 97% of the country’s 151,000 water systems are small, run by local authorities that lack a dedicated IT team and the budget for robust cybersecurity. For these operators, connecting sensors and controls online was a practical necessity for remote troubleshooting, but security lagged far behind. As Corman put it, “We have more cybersecurity regulations for your credit card than we have for the nation’s water supply.” Only about 420 water facilities voluntarily share cybersecurity information, meaning the sector largely operates without early warning systems or mandatory standards.

From Florida to Norway — A Pattern of Near-Misses

The attack was not the first of its kind and won’t be the last. In 2021, an unknown intruder dialed up sodium hydroxide levels at a Florida water treatment plant more than 100-fold, nearly poisoning the supply. Russian hackers opened a Norwegian dam’s floodgates in 2025. Experts like Corman believe Chinese and Iranian hackers have already infiltrated countless utility networks, gaining what may be “virtual prepositioned” capabilities for future conflict.

The Washington Vacuum: Trump’s Denial and a Hollowed CISA

The federal response has been anything but reassuring. President Trump publicly dismissed the attack as a fabrication, baselessly claiming Minnesota officials were “behind it.” That came months after he proposed $707 million in cuts to the Cybersecurity and Infrastructure Security Agency (CISA), the very body charged with defending critical infrastructure, partly out of anger over the agency’s role in confirming the 2020 election. Jen Easterly, who led CISA under President Biden, noted in a recent op-ed that her old position has remained vacant for 18 months, leaving the agency without permanent leadership as threats multiply. “Nation-state hackers do not respect the jurisdictional lines separating federal, state, and local responsibility,” she wrote.

What Municipalities, State Regulators, and Washington Must Do Now

  • Disconnect critical controls from the public internet. If a water system cannot properly protect a PLC that controls chemical dosing or water release, the safest near-term step is to take it offline. As Joshua Corman advises, “If you can’t protect it, disconnect it.” Operators should identify which functions truly require remote access and which can run on air-gapped, manual systems.
  • Mandate basic cybersecurity hygiene for every water utility — no matter the size. New York State’s recent grants and requirements for security training offer a blueprint. Every system should require multi-factor authentication on remote-access points, change default credentials, and ensure firewalls or VPNs shield operational technology from direct internet exposure.
  • Ramp up incident reporting and monitoring. Only a fraction of water utilities participate in voluntary information-sharing programs. Policymakers should make real-time monitoring and mandatory breach reporting a condition for receiving federal infrastructure funding, enabling a national early warning system akin to what electric utilities have begun building with Congressional support.
  • Restore and fully fund CISA’s infrastructure security mission. The agency’s leadership vacancy and proposed budget cuts undermine its ability to help towns like Braham. Congress and the administration must fill the director post and ensure CISA has the resources to deliver no-cost or low-cost cybersecurity support to the thousands of small water systems that cannot fend for themselves.

Risk & Opportunity Assessment

Commercial RiskLowWater utilities are public, not-for-profit entities; no direct private commercial losses from service disruption, though prolonged outages would pressure municipal budgets.
Competitive RiskLowWater supply is a natural monopoly. The attack does not alter market share among providers.
Regulatory RiskHighThe incident starkly illustrates the absence of federal cybersecurity mandates for water systems. Congressional hearings and state-level regulation (like New York’s) are likely to accelerate, potentially forcing costly upgrades on small systems.
Reputation RiskMediumPublic trust in local water safety may erode, especially if follow-up reporting reveals more severe undetected intrusions. The Trump administration’s dismissal of the attack could further damage the federal government’s credibility on cybersecurity.
Technology DisruptionHighThe move to internet-connected operational technology has far outpaced security. Unless the sector shifts to air-gapped or heavily segmented architectures, future incidents with graver consequences are almost inevitable.
Commercial OpportunityMediumDemand for OT/ICS security services tailored to small utilities will grow. Firms like Dragos and I Am The Cavalry’s volunteer model may gain funding, though the low margins in municipal water mean commercial opportunity is limited compared to the scale of the problem.