On July 26-27, 2026, a coordinated cyberattack struck more than 30 municipal water systems across Minnesota, targeting programmable logic controllers (PLCs) to modify passwords and lock operators out of treatment systems. One plant — Braham’s water treatment facility — went offline entirely, prompting the city to ask residents to minimise water use until treatment resumed. Multiple other utilities reported disrupted communications at water towers and lift stations and shifted to manual operation.
U.S. intelligence agencies assess that Iran-linked CyberAv3ngers — a threat group attributed to Iran’s Islamic Revolutionary Guard Corps Cyber Command (IRGC-CC) — is the likely actor. CISA updated its advisory AA26-097A in response, specifically adding detection guidance for malicious modifications to reusable code modules in Rockwell Automation PLC programs.
What the Attack Exploited
The campaign exploited two weaknesses in water utility OT environments:
Unitronics Vision Series PLCs with default credentials. Tenable’s analysis identified that CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs across the United States, Israel, the United Kingdom, and Ireland by exploiting default passwords that operators had not changed after deployment. Unitronics Vision PLCs are widely deployed in small to medium water treatment facilities for process control, monitoring, and remote access. The devices include a built-in web interface accessible with default credentials if not configured otherwise — a well-documented attack surface that CyberAv3ngers has used in prior campaigns against US water utilities, including the 2023 attack on Aliquippa Municipal Water Authority in Pennsylvania.
CVE-2021-22681 — unpatchable Rockwell Automation PLC flaw. Security researchers suspect the campaign also leveraged CVE-2021-22681, a vulnerability in Rockwell Automation/Allen-Bradley PLCs for which no patch exists. CISA’s update to advisory AA26-097A four days before the Minnesota attacks — adding guidance on detecting malicious changes in reusable code modules — now reads as directly relevant. The advisory’s scope covers Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLC products, with internet-facing deployments representing the highest risk.
In both exploitation paths, the consequence is the same: attackers modify authentication credentials on the PLC, locking out legitimate operators and either maintaining persistent access to the control system or simply degrading the facility’s ability to operate.
Why This Campaign Pattern Is Significant
CyberAv3ngers targeting water utilities is not new. The group hit the Aliquippa water authority in late 2023 and has repeatedly demonstrated that small to medium water utilities — which often operate with minimal IT security staff, legacy OT equipment, and internet-exposed management interfaces — represent accessible targets for a state-aligned group willing to create operational disruption.
What is escalating is the scale and coordination. More than 30 facilities hit simultaneously in one US state represents a meaningful shift from the isolated individual-facility attacks documented in prior campaigns. Coordinating access to dozens of separate utility OT environments requires either prior persistent access across multiple targets (suggesting a longer reconnaissance and staging phase preceding the July 26-27 window) or exploitation of a common internet-facing service or vendor platform that provides leverage across many utilities at once.
The timing also warrants attention. On July 23 — three days before the Minnesota attacks began — Handala, a separate Iran-affiliated group attributed to MOIS (Ministry of Intelligence and Security), issued a statement explicitly declaring US water, electricity, and transportation networks as priority targets. Handala had separately claimed attacks on Maryland operational technology infrastructure and on California Water Service billing systems. Whether the Minnesota attacks represent coordination between IRGC-CC (CyberAv3ngers) and MOIS (Handala) operations, or parallel campaigns by distinct Iranian cyber units with similar tasking, has not been confirmed.
The FBI has since confirmed that water systems in seven states were targeted in the same timeframe — Minnesota’s incident is the most visible but not the only one.
Recommended Actions
For water utilities:
- Immediately audit all internet-facing OT device credentials. Unitronics Vision Series and any Rockwell, Siemens, or Schneider PLC with a web-accessible management interface should be checked for default credentials and changed where found.
- Disable remote access to PLCs from the public internet where it is not operationally required. If remote access is required, place management interfaces behind a VPN with multi-factor authentication.
- Review CISA advisory AA26-097A and apply the detection guidance for Rockwell Automation environments. Where CVE-2021-22681 is relevant to your deployment, verify whether mitigating controls (network segmentation, access control at the network layer) are in place.
- Enable tamper alerts for PLC authentication configuration changes. Any modification to PLC login credentials outside a controlled change process is an incident indicator.
For state and regional water sector authorities:
- Conduct emergency contact verification with utilities across your jurisdiction to identify any additional affected sites not yet reporting publicly.
- Activate information-sharing channels with the WaterISAC, CISA, and FBI. CyberAv3ngers’ activity is being tracked; sharing indicators enables faster containment attribution.
For other critical infrastructure operators:
CyberAv3ngers’ use of default credentials against internet-facing OT management interfaces is not water-sector-specific. The same campaign pattern translates to any sector operating PLCs, SCADA endpoints, or industrial remote access devices with unchanged default credentials or internet-facing management interfaces. The combination of Handala’s explicit threat statements and the scale of the Minnesota campaign signals that Iranian OT operations are in an active and escalating phase.