BLOG

Date
06-08-2026

Industrial Cybersecurity

The Minnesota Water Cyberattack, Explained: What Happened and What the CISA Alert Means

Over the weekend of July 26 and 27, 2026, a coordinated cyberattack struck the operational technology running more than 30 community water systems across Minnesota. It did not target office email or billing systems. It went after the pumps, wells, water towers, and wastewater lift stations that keep water moving, the programmable logic controllers that physically run the treatment process. Days later, the attacks had spread to at least seven states, and federal agencies issued an urgent warning to every water utility in the country.

This article explains what happened, who is suspected, and, most importantly, what the resulting CISA alert means for water and wastewater operators across the United States and Canada. The details matter, because the pattern behind this incident is not new, and it is not going away.

Note: this is a developing story and attribution is still under federal investigation at the time of writing. The account here reflects what US authorities and security researchers reported in the days following the attack. Some specifics may be updated as forensic analysis continues.

What Actually Happened

Minnesota IT Services disclosed the attack on July 28 and activated a statewide cybersecurity incident response. The intrusions hit the operational technology, not the corporate IT networks, of more than 30 municipal water systems. In practical terms, that meant attackers reaching the industrial controllers that operate the physical water infrastructure.

The worst-hit community was Braham, a town of roughly 1,700 people, where officials said attackers shut down the operating controls and took the water treatment plant and a well offline. Other communities were forced into sustained manual operations, running processes by hand that are normally automated, and some issued boil water notices as a precaution. In most cases, drinking water remained safe, and contingency measures held, but the disruption was real and the message was unmistakable.

Federal agencies moved quickly. The FBI, EPA, and CISA all warned that attackers were targeting internet-exposed industrial controllers used by water and wastewater utilities, and that in some cases operators had lost control of their own equipment. CISA reported that the activity had resulted in boil water notices and sustained manual operations, and that attackers were changing PLC passwords to lock operators out of their own systems.

Who Are CyberAv3ngers?

Suspicion has centered on CyberAv3ngers, an Iran-linked threat group that US authorities associate with Iran's Islamic Revolutionary Guard Corps. Attribution for the Minnesota attacks remains officially pending, but the timing and technique align closely with the group's documented pattern, and multiple US officials have pointed toward a possible Iranian connection.

CyberAv3ngers are not new to US water infrastructure. The group has previously targeted water utilities, and their signature is the exploitation of internet-exposed programmable logic controllers, often the small, widely deployed controllers that many utilities never realized were reachable from the public internet. Their goal is frequently disruption and intimidation rather than sophisticated sabotage, which is precisely what makes small, under-resourced water systems attractive targets: the impact is high and the barrier to entry is low.

The uncomfortable truth is that these attacks often do not require advanced exploits. When a controller is directly reachable from the internet, sometimes protected by nothing more than a default or weak password, an attacker does not need a sophisticated vulnerability. They need only to find the device and log in. That is why CISA's guidance focuses less on patching and more on exposure.

The Technical Pattern Behind the Attacks

The Minnesota incident sits within a broader campaign that CISA has been tracking and warning about for months. Understanding the technical pattern is what turns a news story into an actionable lesson.

  • Internet-exposed PLCs are the entry point. The common thread across these attacks is programmable logic controllers reachable directly from the public internet. CISA's central instruction has been blunt: remove publicly exposed PLCs and other operational technology from the internet as soon as possible.

  • The target list is expanding. A July 2026 update to CISA's advisory found the activity had grown beyond Rockwell Automation controllers to include Schneider Electric and Siemens devices, widening the population of at-risk equipment considerably.

  • Attackers are locking operators out. A defining feature of this wave is attackers changing PLC passwords to lock operators out of their own equipment, which is what forces utilities into manual operation.

  • Reconnaissance, not just disruption. CISA also documented attackers stealing PLC project files, the engineering logic of the plant itself. Exfiltrating that logic is reconnaissance for a more targeted future attack, not just disruption for its own sake.

  • A hard-to-patch flaw in the mix. Part of the campaign has exploited a critical Rockwell vulnerability rated CVSS 9.8 with no available patch, which makes network isolation, rather than patching, the essential defense.

Why This Matters Beyond Minnesota

It would be easy to file this as a Minnesota problem, or a small-town problem. It is neither. Within days the same activity had reached at least seven states, and CISA's acting director confirmed the agency was observing a significant increase in threat actors targeting PLCs at water utilities generally. The alert was national because the exposure is national.

The deeper issue is structural. Much of the operational technology supporting water and wastewater systems was never designed for today's threat environment. These are essential utilities, often run by small municipalities with limited budgets and no dedicated OT security staff, operating equipment that predates the idea that a water pump might be a geopolitical target. When critical infrastructure becomes part of broader geopolitical cyber conflict, as water now has, the operators least equipped to defend themselves are the ones on the front line.

What This Means for Canadian Utilities

Canadian water operators should not read this as a US-only story. The controllers in question, Rockwell, Schneider, Siemens, are the same makes and models deployed in Canadian municipal water systems. The exposure pattern, internet-reachable PLCs protected by weak controls, is identical on both sides of the border. A threat group scanning the internet for exposed controllers does not check nationality first.

Canadian utilities face the same fundamental question the Minnesota incident poses to every operator: is any of our operational technology reachable from the public internet, and if so, why? The answer to that question, not the location of the utility, is what determines exposure.

The Core Lesson

Strip away the geopolitics and the specific group, and the Minnesota attack delivers one lesson that CISA has been repeating for years: operational technology does not belong on the public internet. The guidance has not changed because the fundamental exposure has not changed. Get PLCs off the internet, put any necessary remote access behind a VPN or a gateway, and strengthen the controls on the devices that run physical processes.

The uncomfortable part is that this guidance has, in CISA's own framing, largely gone unheeded. The Minnesota attack is what that gap looks like when an adversary decides to exploit it. The utilities that treat this as a prompt to act, rather than a story about someone else, are the ones that will not be the subject of the next alert.

Frequently Asked Questions

What happened in the Minnesota water cyberattack?

In late July 2026, a coordinated cyberattack hit the operational technology of more than 30 Minnesota community water systems, targeting the PLCs that run pumps, wells, and treatment processes. At least one town, Braham, had its treatment plant and well taken offline, and several communities shifted to manual operations and issued boil water notices. The activity spread to at least seven states within days.

Who was behind the Minnesota water attack?

Attribution remains under federal investigation, but suspicion has centered on CyberAv3ngers, an Iran-linked group associated with the Islamic Revolutionary Guard Corps that has previously targeted US water infrastructure. Multiple US officials have pointed toward a possible Iranian connection, though no official attribution had been confirmed at the time of writing.

What did the CISA alert say?

CISA warned that threat actors are targeting internet-exposed PLCs at water utilities, changing PLC passwords to lock out operators, and that the activity had caused boil water notices and manual operations. Its central instruction was to remove publicly exposed PLCs and other OT from the internet as soon as possible, and to route any necessary remote access through a VPN or gateway.

Does this threat affect Canadian water utilities?

Yes. The targeted controllers, from Rockwell, Schneider, and Siemens, are the same makes used in Canadian municipal water systems, and the exposure pattern of internet-reachable PLCs is identical. Threat actors scanning for exposed controllers do not filter by country, so Canadian utilities face the same underlying risk.

 

Talk to an OT Security Expert

If the Minnesota attack has you asking whether your own water or wastewater systems are exposed, that is exactly the right question, and the fastest way to answer it is to look. Book a free consultation with one of our OT security engineers, and we will help you find out what, if anything, is reachable from the internet, for water utilities across the US and Canada.

[ Primary CTA: Book Your Free Consultation ]

[ Secondary CTA: Talk to an OT Security Expert ]


 

BOOK YOUR CONSULTATION