AUTO-UPDATED

Coordinated “cyberattack” on Minnesota water utilities: What you need to know

A coordinated cyberattack disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026, highlighting ongoing vulnerabilities in critical infrastructure and industrial control systems.

Key Points

  • The attacks occurred between July 26 and July 27, 2026, impacting communities including Braham, Plymouth, South St. Paul, and Maple Plain.
  • Federal authorities suspect the involvement of Iranian-affiliated actors, specifically the CyberAv3ngers group, which has targeted U.S. infrastructure since 2020.
  • CISA Advisory AA26-097A warns that attackers are exploiting internet-exposed PLCs from Rockwell Automation, Schneider Electric, and Siemens to manipulate utility controls.
  • CVE-2021-22681, a critical authentication bypass in Rockwell Automation controllers, remains a primary vector for these attacks with no available software patch.
  • Defenders are urged to disconnect PLCs from the public internet, implement network segmentation, and set physical mode switches to "Run" to prevent unauthorized logic modifications.

Why it Matters

These incidents demonstrate the severe risks posed by internet-exposed industrial equipment, which often lacks robust security and cannot be easily patched. As geopolitical tensions rise, small utilities with limited cybersecurity resources remain prime targets for state-sponsored actors seeking to disrupt essential public services.
Tenable.com Published by Research Special Operations
Read original