On July 26 and 27, 2026, a coordinated cyberattack campaign targeted the Operational Technology (OT) networks of more than 30 community water systems across Minnesota. The attacks disrupted automated control systems, forcing some facilities to switch to manual operations and causing at least one water treatment plant to go offline temporarily. While officials have stated that drinking water safety was not compromised, the incident represents a significant and scaled attack on U.S. critical infrastructure. A multi-agency response involving Minnesota IT Services (MNIT), CISA, the FBI, and the EPA is underway. Security researchers suspect the involvement of CyberAv3ngers, a threat group linked to Iran's Islamic Revolutionary Guard Corps (IRGC), based on the attack patterns and timing relative to recent CISA advisories about the group's targeting of internet-exposed PLCs.
The attacks were characterized by their coordinated nature, targeting a large number of small to medium-sized water utilities within a 48-hour window. The primary targets were internet-exposed Programmable Logic Controllers (PLCs) and other automated control systems responsible for managing water treatment and distribution. By compromising these systems, the attackers were able to disrupt normal operations. Publicly confirmed victims include the municipalities of Braham, Plymouth, South St. Paul, and Maple Plain.
The threat actor's motive appears to be disruption rather than financial gain or data theft. While not officially attributed, security firm Tenable noted the attack's consistency with CyberAv3ngers, a group known for targeting Israeli-made PLCs and leaving anti-Israel messages. This incident occurred shortly after a CISA advisory warned that this group was targeting PLCs from major vendors like Rockwell Automation, Schneider Electric, and Siemens.
The specific vulnerabilities and initial access vectors have not been disclosed by investigators. However, based on the context and previous campaigns by similar actors, the attack likely involved the following TTPs:
T0886 - Scanning and Enumeration tools like Shodan to identify internet-exposed PLCs and Human-Machine Interfaces (HMIs). They may have exploited known vulnerabilities in these devices or used default/weak credentials to gain access, aligning with T0819 - Default Credentials.T0829 - Manipulation of Control. This allowed them to shut down pumps, disrupt communication links, and disable automated processes. Disabling safety alarms, a tactic mentioned in the related CISA advisory, could also be part of their playbook, mapping to T0826 - Inhibit Response Function.While officials were quick to state that drinking water remained safe, the operational impact was significant. Forcing over 30 facilities into manual mode strains resources and increases the risk of human error. The temporary shutdown of a water treatment plant, even if brief, is a serious disruption to a critical service. The psychological impact on the public and the operational burden on small municipalities with limited cybersecurity staff cannot be understated. This large-scale, coordinated event demonstrates the systemic risk facing the U.S. water sector, which is composed of thousands of small, often under-resourced, utilities. The incident serves as a stark warning of the potential for widespread disruption of essential services through cyber means.
No specific technical Indicators of Compromise (IPs, domains, hashes) were provided in the source articles.
The following patterns could indicate related activity against OT systems:
D3-NTA: Network Traffic Analysis.D3-LAM: Local Account Monitoring.D3-NI: Network Isolation.D3-MFA: Multi-factor Authentication.Scope of water utility cyberattacks expands to 39+ facilities across seven U.S. states, prompting CISA/FBI warnings on exposed PLCs.
Isolating OT networks from IT and the internet is the most effective defense against these types of attacks.
Strictly control traffic between IT and OT networks, and block all unnecessary inbound connections from the internet.
Change all default credentials on ICS/SCADA devices and enforce strong, unique passwords.
Keep all OT components, including PLC firmware and HMI software, up to date with the latest security patches.
The primary defensive measure for water utilities is to implement robust network isolation. Critical OT assets, especially PLCs and control servers, should never be directly accessible from the internet. Establish a defensible network architecture where the OT network is air-gapped or strictly firewalled from the corporate IT network. All connections that must cross the IT/OT boundary should pass through a demilitarized zone (DMZ) and be subject to deep packet inspection. This directly counters the initial access vector used in the Minnesota attacks, which relied on finding and exploiting internet-exposed control systems. This strategy is the cornerstone of the 'CI Fortify' guidance and is the most effective way to prevent remote adversaries from manipulating physical processes.
For any remote access that is deemed essential for operations, multi-factor authentication is non-negotiable. Instead of exposing RDP or HMI ports to the internet, require personnel to connect through a VPN gateway that enforces MFA. This prevents attackers from gaining access even if they manage to acquire valid credentials through phishing or other means. MFA should be applied to all remote access points into the OT network, as well as for privileged access to engineering workstations and control servers within the environment. This significantly hardens the network against credential-based attacks, which are a common tactic of groups like CyberAv3ngers.
Coordinated cyberattacks begin targeting Minnesota community water systems.
The cyberattacks continue, with over 30 facilities reporting disruptions to their OT systems.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.