A coordinated cyberattack disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026, highlighting ongoing vulnerabilities in critical infrastructure and industrial control systems.
Key Points
- The attacks occurred between July 26 and July 27, 2026, impacting communities including Braham, Plymouth, South St. Paul, and Maple Plain.
- Federal authorities suspect the involvement of Iranian-affiliated actors, specifically the CyberAv3ngers group, which has targeted U.S. infrastructure since 2020.
- CISA Advisory AA26-097A warns that attackers are exploiting internet-exposed PLCs from Rockwell Automation, Schneider Electric, and Siemens to manipulate utility controls.
- CVE-2021-22681, a critical authentication bypass in Rockwell Automation controllers, remains a primary vector for these attacks with no available software patch.
- Defenders are urged to disconnect PLCs from the public internet, implement network segmentation, and set physical mode switches to "Run" to prevent unauthorized logic modifications.