# After Attackers Took a Minnesota Town's Water Offline, New York Is Writing Checks
On July 26, someone reached into the operational controls of Braham, Minnesota's water plant and shut them down. The well stopped. The water treatment plant stopped. City officials had to take the entire system offline. Braham has about 1,400 residents. This was not a hypothetical.
That attack was part of a coordinated campaign that eventually touched water and wastewater infrastructure across at least seven states — Minnesota, Michigan, South Dakota, Georgia, and others still being confirmed. More than 30 community systems were hit in a 48-hour window. Federal investigators haven't formally pinned attribution, but Iran has surfaced as the leading suspect, consistent with prior campaigns by Iranian-linked threat actors who have made American water utilities a recurring target for at least four years.
Against that backdrop, New York Governor Kathy Hochul announced Monday that the state is awarding more than $9 million to 153 drinking water and wastewater systems through its SECURE grant program — Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements — to fund assessments and security improvements at local utilities.
It is a meaningful step. It is also a stark illustration of how badly the sector has been neglected.
---
## The Math Behind $9 Million
Divide $9 million across 153 systems and you get roughly $58,800 per utility. The program caps cybersecurity assessments at $50,000 and implementation grants at $100,000. Some systems will receive assessment funding first, others implementation money — the allocations vary by utility size and need.
That ceiling matters. For a small water district running aging SCADA systems on hardware that predates modern network segmentation, $100,000 buys a firewall refresh, maybe a proper VPN gateway, some staff training, and not much else. It does not buy a SOC. It does not buy ongoing monitoring. It does not buy a dedicated security engineer.
The March minimum standards New York introduced — mandatory cybersecurity training for operators, incident reporting requirements, a designated cybersecurity lead at larger systems — are a floor, not a ceiling. And floors only matter if the building has walls.
The SECURE grants are designed to help utilities clear that floor. The open question is what happens in year two, when the one-time assessment money is gone and the utility is back to running on a shoestring municipal budget with a part-time IT person and a network that's theoretically more secure than it was but still connected to the internet in ways it shouldn't be.
---
## Default Passwords and Exposed PLCs: The Actual Problem
After the multistate campaign broke, CISA's guidance was almost embarrassingly basic: remove programmable logic controllers and other operational technology from public internet exposure. Change default credentials. Route remote access through VPNs. Restrict connections to trusted IP addresses.
These are not advanced recommendations. They are 2010-era hygiene that the water sector, as a whole, never fully implemented. The reason is structural: water utilities — especially the small community systems that serve towns like Braham — operate on thin margins, defer capital expenditures for decades, and have historically classified cybersecurity as an IT problem rather than an operational one. In many cases, the PLC controlling a pump station is the same device that's been running since before smartphones existed. Replacing it costs money the utility doesn't have.
Iran, or whoever was behind the July campaign, knows this. Targeting small water systems isn't random opportunism — it's a calculated bet on the likelihood that default credentials are still active, that PLCs are internet-reachable because a contractor configured them that way in 2015 and nobody changed it, and that incident response capability is basically zero. The attack on Braham appears to have involved exactly this kind of access. No zero-days required.
---
## New York's Position: Ahead, But Not Immune
No New York utility has been publicly linked to the multistate campaign, which is either good news or a fact pattern that hasn't fully resolved yet. The state's March cybersecurity standards — among the first mandatory OT security rules for water utilities at the state level in the country — put New York ahead of most states in terms of regulatory posture. The SECURE grants are the financial complement to those rules.
Still, 153 systems receiving grants is a subset of the state's full water infrastructure. New York has hundreds of water and wastewater systems. The utilities receiving SECURE funding are presumably the ones that applied and qualified, not a comprehensive hardening of the entire sector.
The $9 million in security grants also sits next to a $3.8 billion clean water infrastructure investment in the state's FY2027 budget — money for pipes, treatment capacity, physical plant. Physical infrastructure commands orders of magnitude more political capital than cybersecurity, even when adversaries are demonstrating they can reach into the control systems that operate that infrastructure and turn things off.
---
## HackWire Analysis
The Braham attack is the kind of incident that should have gotten more attention than it did. A foreign adversary — almost certainly Iran, based on the tradecraft signatures — walked into a town's water controls and shut them down. Local contingency plans kept drinking water safe, which is good. But the operational playbook that prevented a public health emergency was human operators doing things manually, not cybersecurity controls doing their job. Resilience through redundancy is not a security strategy; it's a last-resort backstop that happens to work until it doesn't.
What makes this moment particularly important is the precedent-setting nature of state-level mandatory OT security standards. New York's March rules are an early test case. If SECURE grants help utilities actually comply — and if compliance translates to measurable reduction in attack surface — that's a template other states can follow. If the grants are too small to fund real improvements and the standards remain paperwork exercises, we'll know that too within the next 18 months when the next campaign runs.
The Iran attribution thread also deserves more scrutiny than it's gotten. Iranian threat actors targeting American water utilities isn't new — the 2021 Oldsmar, Florida incident and subsequent CISA advisories documented a sustained interest in this sector. What's changed is the scale and coordination: 30-plus systems in 48 hours suggests either improved tooling, a pre-positioned access campaign that pre-dated the July attacks, or both. Defenders should be asking whether their systems were pre-compromised before the active phase of the campaign, not just whether they were targeted in the window that's been reported.
For small utilities without in-house security staff, the most immediate action isn't waiting for a grant — it's auditing every internet-facing connection to OT systems this week. If you don't know what's exposed, CISA's CSET tool is free.
— HackWire Editorial
---
## Related Coverage