A coordinated cyberattack targeted over 30 Minnesota water and wastewater utilities, leveraging internet-exposed industrial control systems (ICS) via cellular modems. The campaign utilized critical vulnerabilities in Rockwell Automation controllers (CVE-2021-22681, CVE-2023-3595, CVE-2024-6242) and targeted Schneider Electric and Siemens PLCs. Threat actors, attributed to the Iranian-linked CyberAv3ngers (IRGC-CEC), progressed to "Phase 4" capabilities, employing legitimate vendor engineering software to exfiltrate PLC project files and manipulate Add-On Instructions (AOIs) to disable safety protocols. This resulted in operational shutdowns in Braham and transitions to manual operations across multiple municipalities, though no water quality contamination was reported.
-
Incident Overview & Scope
- Targeted over 30 Minnesota communities within a 48-hour window on July 26-27, 2026.
- Primary targets were small, rural utilities relying on cellular-connected OT equipment without robust network segmentation.
- Operational impacts included plant shutdowns in Braham and a declared state of emergency in Maple Plain.
-
Technical Exploitation Vectors
- Exploited CVE-2021-22681 (CVSS 9.8) to achieve critical authentication bypass in Rockwell Automation Logix controllers.
- Utilized CVE-2023-3595 and CVE-2024-6242 to facilitate remote code execution and bypass "Trusted Slot" security features.
- Deployed Dropbear SSH on victim modems to establish persistent remote access to the OT environment.
-
Advanced TTPs & Payload Analysis
- Utilized legitimate vendor tools (Studio 5000, EcoStruxure Control Expert, TIA Portal) to masquerade as authorized engineering personnel.
- Manipulated Add-On Instructions (AOIs) to suppress alarms and bypass safety protocols, potentially enabling undetected physical damage.
- Altered HMI and SCADA display data to mask unsafe system conditions from human operators.
- Exfiltrated proprietary PLC project files via third-party hosted infrastructure for further offline analysis.
-
Threat Actor Profile: CyberAv3ngers (IRGC-CEC)
- Attribution points to the Iranian-linked CyberAv3ngers ecosystem acting in retaliation for U.S. kinetic operations ("Operation Epic Fury").
- Deployment of the IOCONTROL malware platform, specifically engineered for the takeover of IoT and OT devices.
- Demonstrated a strategic shift from simple credential abuse to deep exploitation of vendor-specific engineering protocols.
-
Systemic Risks & Mitigation
- Highlighting a critical vulnerability: 74.6% of global internet-exposed Rockwell Automation devices are located in the U.S.
- Over 70% of U.S. water systems are currently failing to comply with mandatory risk assessment laws.
- Urgent recommendation to decommission internet-exposed PLC management interfaces and implement strict hardware-based network segmentation.
Related posts
- blackswan-cybersecurity.com — THREAT ADVISORY Iranian-Affiliated Cyber Operations Targeting U.S. Water, Energy, and Critical Infrastructure Sectors July 27, 2026
- techjacksolutions.com — CISA Joint Advisory AA26-097A Updated: Iranian State-Affiliated Actors Modifying PLC Safety Logic in U.S. Critical Infrastructure, Scope Expanded to Siemens and Schneider Electric
- TechNadu — Coordinated Cyberattack Hits 30+ Minnesota Water Systems as Officials Suggest Iran-Linked Pattern
- Malware News — Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
- feeds.feedburner.com — Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- gbhackers.com — Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
- Cybersecurity News — Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators
- cybrsecmedia.com — CISA Warns: Iranian Cyber Campaign Now Threatens "Potentially All" Exposed PLCs
- cyberscoop.com — Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
- cybersecuritydive.com — Authorities investigating a coordinated cyberattack against Minnesota water systems
- Tenable Blog — Coordinated “cyberattack” on Minnesota water utilities: What you need to know
- Rescana
- Nationalcioreview
- Mprnews
- SecurityWeek — Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks