Iranian-Linked Hackers Hit 30+ Minnesota Water Systems in Coordinated OT Attack Targeting Unpatchable PLC Flaws

Iranian-Linked Hackers Hit 30+ Minnesota Water Systems in Coordinated OT Attack Targeting Unpatchable PLC Flaws

A coordinated cyberattack hit more than 30 community water and wastewater systems across Minnesota over the weekend of July 26-27, temporarily shutting down a water treatment plant in Braham and forcing other cities to disconnect automated equipment, state officials confirmed. Minnesota IT Services (MNIT) said the incidents shared common timing, access methods, and infrastructure profiles — strongly suggesting a single coordinated campaign targeting operational technology (OT) at the state's water utilities.

A technician's hands installing an industrial PLC control module into a rack chassis

What Happened Across Minnesota

Four cities publicly described the damage. Braham — a community of roughly 1,700 people in east-central Minnesota — had its water plant knocked offline after attackers disabled the computerized operating controls that govern the well and treatment facility. The city asked residents to minimize water use while public works crews scrambled to restore service, which took about two hours.

Plymouth, a much larger city of about 80,000 people, took a more cautious route. Its IT department proactively disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the intrusion from spreading and to prevent re-targeting while systems were reconfigured. Operations continued through manual procedures. "The issue is limited to equipment connected via cellular communications within the system," the city said in a public statement.

South St. Paul reported that some automated utility controls were affected but contingency procedures kept water flowing. Maple Plain declared a local state of emergency to speed up its response. All four cities confirmed drinking water remained safe and no boil-water advisories were issued. The Minnesota Department of Health is working directly with affected systems to monitor water quality.

A Warning That Arrived Four Days Too Early

The attacks came just four days after the Cybersecurity and Infrastructure Security Agency dropped a major update to Advisory AA26-097A on July 22. That update — co-signed by the FBI, NSA, EPA, and the Department of Energy — expanded what was already a serious warning about Iranian-affiliated actors exploiting internet-exposed programmable logic controllers across U.S. critical infrastructure.

Three things changed in that advisory. First, CISA broadened the confirmed target list beyond Rockwell Automation controllers to include Schneider Electric BMX P34/Modicon M340 PLCs and Siemens S7-1200 PLCs, and noted activity on ports associated with other OT vendors — suggesting opportunistic scanning beyond the named manufacturers. Second, it documented for the first time that attackers had been exfiltrating PLC project files: using legitimate vendor engineering software like Rockwell's Studio 5000 Logix Designer, Schneider's EcoStruxure Control Expert, and Siemens' TIA Portal, hosted on leased infrastructure, to pull industrial control programs out of victim environments.

Third, and perhaps most alarming, the advisory added detection guidance for a technique called Add-On Instruction manipulation. AOIs are reusable code modules embedded in PLC programs. In one confirmed incident, investigators found that actors had inserted malicious AOIs into an otherwise normal project file — disabling safety shutdown and alarm systems while simultaneously feeding falsified data to operator displays. The operators watching their screens saw nothing wrong, but the equipment beneath the displays was operating in an unsafe state.

The Unpatchable Flaw at the Center of It All

Security researchers at Tenable believe the attack bears the hallmarks of CyberAv3ngers — a hacking operation formally attributed to Iran's IRGC Cyber-Electronic Command and one of the most documented state-directed threats to U.S. water infrastructure. The group has been active since at least 2020 and is tracked under multiple designations, including Storm-0784 (Microsoft), Bauxite (Dragos), and UNC5691 (Mandiant).

A laptop terminal screen showing hexadecimal data and a "DATA TRANSFER COMPLETE" message, representing the cyber operation infrastructure

The vulnerability enabling this latest phase of attacks is CVE-2021-22681, an authentication bypass in Rockwell Automation's Logix controller ecosystem with a CVSS score of 9.8 out of 10 — critical by any measure. The flaw stems from an insufficiently protected cryptographic key used to verify communications between Studio 5000 Logix Designer and Logix PLCs. Any attacker who obtains or intercepts that key can pose as legitimate engineering software and gain direct, unauthenticated access to affected controllers.

The brutal part: there is no patch. Rockwell Automation has stated that CVE-2021-22681 cannot be fully fixed with a software update. Organizations that rely on patch-based remediation workflows are stuck. The only defenses are architectural — network segmentation, engineering workstation isolation, CIP Security enablement, and physical mode switch hardening.

Why Water Utilities Keep Getting Hit

The vulnerability surface is enormous. Censys analysis conducted in April 2026 identified 5,219 internet-exposed hosts globally that self-identified as Rockwell Automation or Allen-Bradley devices. The United States accounts for 74.6% of that exposure — 3,891 hosts. A disproportionate share of these devices operate on cellular carrier networks, matching the exact attack vector described in Plymouth's public statement about its cellular-connected water tower equipment.

The EPA warned in 2024 that more than 70% of U.S. water systems were failing to develop or update risk assessments and emergency response plans as required by law. An audit of 1,000 water systems serving 193 million people found 97 with critical or high-risk vulnerabilities. The U.S. has between 150,000 and 170,000 water systems, and most of them are small, rural, and under-resourced.

Denis Calderone, CTO of Suzu Labs, noted that water towers, lift stations, and pump stations often connect back to SCADA systems over cellular modems — and those secondary communication links are routinely overlooked during vulnerability assessments. "In our experience, secondary or alternative communication links are often overlooked when doing risk and vulnerability analysis," Calderone told SecurityWeek. "It is not too surprising that the vector of attack may have been via these cellular connections."

CyberAv3ngers' Capability Escalation

CyberAv3ngers has demonstrated a deliberate four-phase capability escalation over six years. In Phase One (2020-2022), it operated mostly as a propaganda persona, claiming responsibility for infrastructure disruptions that investigators later assessed as fabricated. Phase Two (October 2023-January 2024) was the breakout: the group compromised at least 75 Unitronics Vision Series PLCs across the U.S., Israel, the UK, and Ireland by exploiting default passwords on internet-exposed devices. The Municipal Water Authority of Aliquippa, Pennsylvania, became the highest-profile victim.

In Phase Three (2024-2025), the group deployed IOCONTROL, a custom-built malware platform for IoT and OT devices. OpenAI disclosed in October 2024 that CyberAv3ngers had used ChatGPT to assist with target reconnaissance and code debugging. Phase Four (March 2026 to present) is the current campaign, pivoting to CVE-2021-22681 exploitation against Rockwell, Schneider, and Siemens equipment.

The July 22 advisory update revealed actors had been active from as early as September 2025 through July 2026 — a sustained, multi-year campaign that is still ongoing. MNIT said on July 28 that it was not aware of any active requests for residents to change their drinking-water use, and that the investigation remains active. Attribution has not been officially finalized, though the operational pattern matches Iranian-linked activity documented by CISA, the FBI, and multiple private-sector researchers.

What This Means for Critical Infrastructure

The Minnesota attacks represent a dangerous escalation in how state-backed groups target OT environments. Not because the techniques are new — exploiting internet-exposed PLCs has been documented for years — but because the scale and coordination are unprecedented for a single U.S. state. More than 30 systems hit in a two-day window, all sharing common access methods and target profiles, suggests an operational playbook designed for rapid, multi-site exploitation.

Seemant Sehgal, founder and CEO of BreachLock, warned that investigators need to establish the common thread because the same vulnerability "almost certainly exists in water infrastructure well beyond Minnesota." That assessment is hard to argue with when 3,891 Rockwell devices are still visible from the internet inside U.S. borders, and more than 70% of water systems have not completed federally mandated risk assessments.

In a statement, MNIT Assistant Commissioner and Chief Information Security Officer John Israel put it plainly: "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response." The state is coordinating containment, investigation, recovery, and threat-intelligence sharing with CISA, the EPA, the FBI, and affected utilities. The outcome of that investigation will determine whether this is a one-time coordinated strike or the opening phase of a broader campaign against U.S. water infrastructure.

Cybersecurity Source: The Hacker News — Coordinated Cyberattack Targets 30+ Minnesota Water Systems Source: Tenable — Minnesota Water Cyber Attack and CISA Advisory AA26-097A Source: SecurityWeek — Dozens of Minnesota Water Utilities Targeted Source: TechTimes — Iranian Hackers Exploited Unpatchable PLC Flaw

← Back to Home