← Back to Daily Briefing

A coordinated cyberattack targeted over 30 Minnesota water and wastewater utilities, leveraging internet-exposed industrial control systems (ICS) via cellular modems. The campaign utilized critical vulnerabilities in Rockwell Automation controllers (CVE-2021-22681, CVE-2023-3595, CVE-2024-6242) and targeted Schneider Electric and Siemens PLCs. Threat actors, attributed to the Iranian-linked CyberAv3ngers (IRGC-CEC), progressed to "Phase 4" capabilities, employing legitimate vendor engineering software to exfiltrate PLC project files and manipulate Add-On Instructions (AOIs) to disable safety protocols. This resulted in operational shutdowns in Braham and transitions to manual operations across multiple municipalities, though no water quality contamination was reported.

  • Incident Overview & Scope

    • Targeted over 30 Minnesota communities within a 48-hour window on July 26-27, 2026.
    • Primary targets were small, rural utilities relying on cellular-connected OT equipment without robust network segmentation.
    • Operational impacts included plant shutdowns in Braham and a declared state of emergency in Maple Plain.
  • Technical Exploitation Vectors

    • Exploited CVE-2021-22681 (CVSS 9.8) to achieve critical authentication bypass in Rockwell Automation Logix controllers.
    • Utilized CVE-2023-3595 and CVE-2024-6242 to facilitate remote code execution and bypass "Trusted Slot" security features.
    • Deployed Dropbear SSH on victim modems to establish persistent remote access to the OT environment.
  • Advanced TTPs & Payload Analysis

    • Utilized legitimate vendor tools (Studio 5000, EcoStruxure Control Expert, TIA Portal) to masquerade as authorized engineering personnel.
    • Manipulated Add-On Instructions (AOIs) to suppress alarms and bypass safety protocols, potentially enabling undetected physical damage.
    • Altered HMI and SCADA display data to mask unsafe system conditions from human operators.
    • Exfiltrated proprietary PLC project files via third-party hosted infrastructure for further offline analysis.
  • Threat Actor Profile: CyberAv3ngers (IRGC-CEC)

    • Attribution points to the Iranian-linked CyberAv3ngers ecosystem acting in retaliation for U.S. kinetic operations ("Operation Epic Fury").
    • Deployment of the IOCONTROL malware platform, specifically engineered for the takeover of IoT and OT devices.
    • Demonstrated a strategic shift from simple credential abuse to deep exploitation of vendor-specific engineering protocols.
  • Systemic Risks & Mitigation

    • Highlighting a critical vulnerability: 74.6% of global internet-exposed Rockwell Automation devices are located in the U.S.
    • Over 70% of U.S. water systems are currently failing to comply with mandatory risk assessment laws.
    • Urgent recommendation to decommission internet-exposed PLC management interfaces and implement strict hardware-based network segmentation.

Related posts

  1. blackswan-cybersecurity.com — THREAT ADVISORY Iranian-Affiliated Cyber Operations Targeting U.S. Water, Energy, and Critical Infrastructure Sectors July 27, 2026
  2. techjacksolutions.com — CISA Joint Advisory AA26-097A Updated: Iranian State-Affiliated Actors Modifying PLC Safety Logic in U.S. Critical Infrastructure, Scope Expanded to Siemens and Schneider Electric
  3. TechNadu — Coordinated Cyberattack Hits 30+ Minnesota Water Systems as Officials Suggest Iran-Linked Pattern
  4. Malware News — Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
  5. feeds.feedburner.com — Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
  6. gbhackers.com — Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
  7. Cybersecurity News — Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators
  8. cybrsecmedia.com — CISA Warns: Iranian Cyber Campaign Now Threatens "Potentially All" Exposed PLCs
  9. cyberscoop.com — Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
  10. cybersecuritydive.com — Authorities investigating a coordinated cyberattack against Minnesota water systems
  11. Tenable Blog — Coordinated “cyberattack” on Minnesota water utilities: What you need to know
  12. Rescana
  13. Nationalcioreview
  14. Mprnews
  15. SecurityWeek — Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

LINK COPIED TO CLIPBOARD