← Back to Daily Briefing

A coordinated cyberattack targeted over 30 Minnesota water and wastewater utilities, leveraging internet-exposed industrial control systems (ICS) via cellular modems. The campaign utilized critical vulnerabilities in Rockwell Automation controllers (CVE-2021-22681, CVE-2023-3595, CVE-2024-6242) and targeted Schneider Electric and Siemens PLCs. Threat actors, attributed to the Iranian-linked CyberAv3ngers (IRGC-CEC), progressed to "Phase 4" capabilities, employing legitimate vendor engineering software to exfiltrate PLC project files and manipulate Add-On Instructions (AOIs) to disable safety protocols. This resulted in operational shutdowns in Braham and transitions to manual operations across multiple municipalities, though no water quality contamination was reported.

  • Incident Overview & Scope

    • Targeted over 30 Minnesota communities within a 48-hour window on July 26-27, 2026.
    • Primary targets were small, rural utilities relying on cellular-connected OT equipment without robust network segmentation.
    • Operational impacts included plant shutdowns in Braham and a declared state of emergency in Maple Plain.
  • Technical Exploitation Vectors

    • Exploited CVE-2021-22681 (CVSS 9.8) to achieve critical authentication bypass in Rockwell Automation Logix controllers.
    • Utilized CVE-2023-3595 and CVE-2024-6242 to facilitate remote code execution and bypass "Trusted Slot" security features.
    • Deployed Dropbear SSH on victim modems to establish persistent remote access to the OT environment.
  • Advanced TTPs & Payload Analysis

    • Utilized legitimate vendor tools (Studio 5000, EcoStruxure Control Expert, TIA Portal) to masquerade as authorized engineering personnel.
    • Manipulated Add-On Instructions (AOIs) to suppress alarms and bypass safety protocols, potentially enabling undetected physical damage.
    • Altered HMI and SCADA display data to mask unsafe system conditions from human operators.
    • Exfiltrated proprietary PLC project files via third-party hosted infrastructure for further offline analysis.
  • Threat Actor Profile: CyberAv3ngers (IRGC-CEC)

    • Attribution points to the Iranian-linked CyberAv3ngers ecosystem acting in retaliation for U.S. kinetic operations ("Operation Epic Fury").
    • Deployment of the IOCONTROL malware platform, specifically engineered for the takeover of IoT and OT devices.
    • Demonstrated a strategic shift from simple credential abuse to deep exploitation of vendor-specific engineering protocols.
  • Systemic Risks & Mitigation

    • Highlighting a critical vulnerability: 74.6% of global internet-exposed Rockwell Automation devices are located in the U.S.
    • Over 70% of U.S. water systems are currently failing to comply with mandatory risk assessment laws.
    • Urgent recommendation to decommission internet-exposed PLC management interfaces and implement strict hardware-based network segmentation.

Related posts

  1. blackswan-cybersecurity.com — THREAT ADVISORY Iranian-Affiliated Cyber Operations Targeting U.S. Water, Energy, and Critical Infrastructure Sectors July 27, 2026
  2. techjacksolutions.com — CISA Joint Advisory AA26-097A Updated: Iranian State-Affiliated Actors Modifying PLC Safety Logic in U.S. Critical Infrastructure, Scope Expanded to Siemens and Schneider Electric
  3. TechNadu — Coordinated Cyberattack Hits 30+ Minnesota Water Systems as Officials Suggest Iran-Linked Pattern
  4. it.slashdot.org — More Than 30 Minnesota Water Systems Targeted In Cyberattack
  5. Malware News — Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
  6. thehackernews.com — Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
  7. csoonline.com — A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?
  8. it.slashdot.org — Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says
  9. Wired Security — 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
  10. Security Affairs — CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
  11. The Register - Security — Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
  12. SOCFortress — Vulnerabilities in Internet-Facing Industrial Control Systems
  13. malware-log.hatenablog.com — LevelBlue review finds attackers exploited exposed PLCs and remote access to disrupt US water infrastructure
  14. techjacksolutions.com — US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
  15. Schneier on Security — Iran Cyberattacks Against Minnesota Water Systems
  16. The Record by Recorded Future — Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents
  17. The Record by Recorded Future — Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity
  18. serisec.com — Multistate Water System Attacks Widen, Iran Suspected
  19. Security Affairs — Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
  20. SecurityWeek — CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
  21. Dark Reading — Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
  22. cybersecuritydive.com — CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
  23. techjacksolutions.com — CISA Warns of Iranian-Affiliated Actors Targeting Industrial Control Systems
  24. gbhackers.com — Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
  25. Cybersecurity News — Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators
  26. cybrsecmedia.com — CISA Warns: Iranian Cyber Campaign Now Threatens "Potentially All" Exposed PLCs
  27. Infosecurity-magazine
  28. cyberscoop.com — Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
  29. cybersecuritydive.com — Authorities investigating a coordinated cyberattack against Minnesota water systems
  30. Tenable Blog — Coordinated “cyberattack” on Minnesota water utilities: What you need to know
  31. Rescana
  32. Nationalcioreview
  33. Mprnews
  34. CISA RSS — CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
  35. Industrial Cyber — Minnesota water cyberattacks prompt CISA warning on growing threats targeting internet-exposed PLCs
  36. bleepingcomputer.com — CISA warns of cyberattacks disrupting U.S. water utilities
  37. The Record by Recorded Future — CISA warns of spike in attacks on water systems as Minnesota incidents probed
  38. Cybersecuritydive
  39. Meritalk
  40. Nextgov
  41. Cbsnews
  42. Reddit
  43. Industrial Cyber — FBI and EPA warn hackers target internet-connected PLCs at US water utilities, leading to operational disruptions
  44. thehackernews.com — ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
  45. levelblue.com — Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems
  46. Theguardian
  47. Industrial Cyber — LevelBlue review finds attackers exploited exposed PLCs and remote access to disrupt US water infrastructure
  48. Wflaorlando
  49. Newsweek
  50. Computing
  51. Columbiagorgenews
  52. Timesnews
  53. Ajc
  54. Dragos
  55. Emberot
  56. Waterisac
  57. Dragos
  58. Youtube
  59. Koeed
  60. Facilitiesdive
  61. Dispel
  62. Cbsnews
  63. Weisradio
  64. Wanaen
  65. Tomshardware
  66. Darkreading
  67. Cybermagazine
  68. SecurityWeek — Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
  69. SecurityWeek — Water Sector Cyberattacks Reportedly Hit at Least 12 States
  70. SecurityWeek — New Jersey, Alabama Join States Targeted in Water Cyberattacks

LINK COPIED TO CLIPBOARD