A coordinated cyberattack on July 26 and 27 disrupted operational technology at more than 30 municipal water systems across Minnesota, forcing at least four communities to switch to manual operations and prompting one city to declare a local state of emergency. The attack targeted internet-facing programmable logic controllers, changed device passwords and IP addresses to lock out legitimate operators, and temporarily disabled automated well and treatment plant controls. Attribution remains unconfirmed, but the tactics, techniques, and infrastructure closely match patterns documented in previous campaigns by CyberAv3ngers, an Iranian threat group linked to the Islamic Revolutionary Guard Corps Cyber-Electronic Command.
What Happened
The attack began around midnight on July 26. Attackers remotely accessed internet-connected PLCs at water facilities across Minnesota using vendor engineering software to authenticate to the devices directly, then changed credentials and network configurations to block legitimate operator access.
The cities of Plymouth, South St. Paul, Maple Plain, and Braham all confirmed incidents. In Braham, the water tower was unable to be automatically filled for more than an hour after the attack disabled operational controls to the water plant. Plymouth and South St. Paul were forced to switch from automated to manual operations. Maple Plain Mayor Julie Maas-Kusske declared a local state of emergency, activating emergency response crews to restore systems. Minnesota IT Services (MNIT) moved quickly to isolate affected systems and assist with containment.
At least one municipal well and treatment plant were taken offline during the attack window. No contamination of drinking water supply was reported. The disruption was operational rather than safety-critical, but the attack demonstrated an adversary willing and able to manipulate water treatment control systems at scale.
Connection to CISA Advisory AA26-097A
CISA updated Advisory AA26-097A on July 22, four days before the Minnesota attacks began. The updated advisory expanded the scope of documented Iranian PLC exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation, documented project file exfiltration for the first time, and added detection guidance for manipulation of reusable code blocks embedded in PLC programs.
The advisory warned explicitly that Iranian-affiliated actors had been compromising internet-connected PLCs across US water, energy, and government sectors. The overlap in timing between the advisory update and the Minnesota attacks is significant: either the advisory was prompted by intelligence about an imminent campaign, or the attacks were already underway when the advisory was issued.
The expanded scope to include Schneider Electric and Siemens devices is particularly relevant. Prior CyberAv3ngers activity focused heavily on Rockwell Automation Micro800-series PLCs; the AA26-097A update signals the group has broadened its target set to cover a larger proportion of US operational technology.
CyberAv3ngers: Prior Pattern
CyberAv3ngers is assessed with high confidence to be linked to the IRGC Cyber-Electronic Command, the Iranian Revolutionary Guard’s offensive cyber arm. The group’s documented activity includes the November 2023 attack on Aliquippa, Pennsylvania’s Municipal Water Authority, in which threat actors tampered directly with Unitronics PLCs and displayed a political message on an operator HMI.
The group’s modus operandi is consistent across known incidents: locate internet-facing PLCs via Shodan or similar scanning infrastructure, exploit default credentials or known vulnerabilities in vendor remote access software, alter device configuration to prevent legitimate access, and claim or publicise the disruption. The July 2026 Minnesota attacks follow the same playbook at significantly expanded scale, targeting more than 30 systems simultaneously rather than isolated facilities.
Sector Implications
The US water sector remains one of the most persistently targeted critical infrastructure sectors, and one of the least uniformly protected. A 2024 EPA assessment found that approximately 70% of water utilities inspected over a three-year period violated safe drinking water standards in ways that included significant cybersecurity vulnerabilities. Internet-facing PLCs without multi-factor authentication, default vendor credentials, and no network segmentation between IT and OT environments are endemic across smaller municipal operators.
The Minnesota incident is not an outlier; it is a demonstration of what coordinated targeting of known weaknesses at scale looks like. The attack affected small community water systems, precisely the operators with the least IT security capacity and the highest exposure of unprotected internet-facing control equipment.
Recommended Actions
CISA’s guidance following the Minnesota attacks focuses on three priorities:
Remove PLCs from direct internet exposure. Any PLC or SCADA system accessible without a VPN or industrial firewall is a direct target. Immediate action is to place these devices behind a network boundary that requires authenticated remote access.
Change default credentials. Vendor default usernames and passwords on Rockwell, Schneider, and Siemens PLCs must be changed. The advisory AA26-097A identifies specific devices and credential patterns observed in active exploitation.
Enable logging on OT devices. Many attacks against water utilities go undetected for extended periods because operators lack visibility into what changes were made to PLC configurations. Enabling and retaining audit logs for configuration changes is a minimum requirement for any incident response capability.
Water utility operators should also review the AA26-097A indicators of compromise and run those against network logs for the period surrounding the July 22-27 window.