Minnesota water systems cyberattack showing a water treatment facility with SCADA warning alerts and 30 affected city markers on a map
🛡 Cybersecurity · Critical Infrastructure

Hackers Hit 30 Minnesota Water Systems
in 48 Hours, One Plant Went Dark

Braham’s water plant shut down. Maple Plain declared a state of emergency. Plymouth went manual. The attack hit operational technology at 30+ community utilities on July 26-27, and the suspected tool is a five-year-old PLC flaw that has no vendor patch.

📅 July 31, 2026 ⏱ 8 min read
30+ cities hit in 48 hours
Iran-linked CyberAv3ngers suspected
CVE-2021-22681, CVSS 9.8, no patch
Attack Window
Sunday to Monday
48hrs
PLC Flaw Age
CVE-2021-22681, no patch
5yrs
Cities Disclosed
Braham, Plymouth, S. St. Paul, Maple Plain
4

The Minnesota water systems cyberattack started on a Sunday night and reached across 30 communities before Monday was over. On July 26 and 27, 2026, hackers hit operational technology at more than 30 community water and wastewater utilities across Minnesota. In Braham, a town of roughly 1,700 people an hour north of the Twin Cities, the attack disabled computerized operating controls and shut down the well and water treatment plant entirely. Residents were told to minimize water use until the plant could be restarted. It came back online roughly two hours later, but the town was left with whatever water was already stored in its tower.

Three other cities disclosed the attack on Monday. Plymouth, population 80,000, reported that cellular communications at two water towers and multiple wastewater lift stations went offline and the city switched to manual operations. South St. Paul confirmed that automated controls were affected but staff maintained service by running the system by hand. Maple Plain declared a local state of emergency to expedite its response. The Minnesota Department of Health said water quality was never affected and no boil-water advisories were issued anywhere in the state.

The remaining 26-plus affected Minnesota water systems have not been named. Minnesota IT Services classified the full list as nonpublic, citing operational security during an active investigation. But the attack’s timing is not a coincidence. Four days before the assault, on July 22, CISA updated Advisory AA26-097A — its running documentation of Iranian-affiliated PLC exploitation activity — to expand the scope of targeted devices from Rockwell Automation to Schneider Electric and Siemens, and to add new detection guidance for manipulated Add-On Instructions inside PLC programs. The suspected tool behind the Minnesota water systems attack is CVE-2021-22681, a five-year-old Rockwell Automation authentication bypass rated CVSS 9.8 that has no vendor patch and never will.

📊 The Minnesota Water Systems Attack, at a Glance
What Happened

How were the Minnesota water systems hit?

Attackers targeted operational technology — the SCADA systems that manage pumps, valves, and remote monitoring — at 30+ community water and wastewater utilities across Minnesota in a coordinated 48-hour campaign on July 26-27.

Who Did It

Who is suspected?

Attribution is pending federal investigation, but the timing aligns with CISA Advisory AA26-097A documenting Iranian-affiliated CyberAv3ngers PLC exploitation activity. CyberAv3ngers is formally linked to Iran’s IRGC Cyber-Electronic Command and sanctioned by the U.S. Treasury.

Physical Impact

Did anyone lose water?

Braham’s water plant shut down for approximately two hours. Plymouth, South St. Paul, and Maple Plain switched to manual operations. No water quality was affected, no boil-water advisories were issued, and no customer data was compromised.

The Flaw

What vulnerability was used?

CVE-2021-22681 (CVSS 9.8) is an authentication bypass in Rockwell Automation Logix controllers. It was added to CISA’s KEV catalog in March 2026. There is no vendor patch available and Rockwell has stated none is planned for the affected product generation.

What Happened Across the Minnesota Water Systems

01

Braham’s plant went dark for two hours

Worst hit

Braham was the most operationally complete attack of the four publicly disclosed incidents. The hackers disabled the town’s computerized operating controls, which shut down the well and the water treatment plant. For roughly two hours, Braham had no active water production — residents were living off whatever volume was already stored in the water tower. City Administrator Kevin Stahl told local media that the attackers used malicious software to compromise a wireless connection to the water plant. The town’s response was direct: shut the entire computer system down, cut external access, and wait for federal guidance on how to reconnect.

Braham’s mayor, Nate George, framed the incident in structural terms that apply to every small town on the list. Local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology, and inadequate resources. A community of 1,700 people does not have a dedicated SOC. It has a city administrator who also handles budgets, roads, and zoning — and who is now also responsible for defending against an IRGC-linked threat actor.

💡 Why Braham matters as a case study. The two-hour plant outage is short, but the principle is not. If the attackers’ goal had been destruction rather than disruption, the same access that turned off the well could have manipulated treatment chemistry, disabled alarms, or changed dosing rates. CISA’s updated advisory specifically documents FBI observations of malicious Add-On Instructions that disabled safety shutdown and alarm systems at other facilities.
02

Plymouth, South St. Paul, and Maple Plain went manual

Confirmed targets

Plymouth — population 80,000 and the largest of the four disclosed cities — reported that cellular communications at two water towers and multiple wastewater lift stations went offline late Sunday. Public Works Director Michael Thompson confirmed the city was operating the system manually. Denis Calderone, CTO of Suzu Labs, noted in SecurityWeek that the cellular communications vector is the revealing detail: water towers, lift stations, and pump stations connect back to the SCADA system over cellular modems, and those secondary communication links are frequently overlooked in risk assessments.

South St. Paul confirmed that automated controls were affected but Public Works staff maintained normal water and wastewater operations through manual procedures. Maple Plain went further and declared a local state of emergency to expedite the city’s response. Maple Plain officials also noted that some details about the incident cannot be shared because releasing them could raise risks to infrastructure or interfere with the ongoing cybersecurity investigation.

💡 Why manual fallback is not a long-term answer. Every city that switched to manual operations did so successfully, which is genuinely good news. But manual operation depends on having operators physically present at every facility around the clock. Small municipalities typically automate precisely because they cannot staff 24/7 coverage. Running on manual for days or weeks burns through overtime budgets and goodwill that small public works departments do not have in reserve.
03

26+ more cities remain unnamed

Nonpublic scope

Minnesota IT Services classified the full list of affected Minnesota water systems as nonpublic, citing risks to infrastructure and the ongoing investigation. Only the four cities that voluntarily disclosed — Braham, Plymouth, South St. Paul, and Maple Plain — are named in the public record. That leaves at least 26 additional communities somewhere in Minnesota whose water or wastewater operational technology was targeted in the same 48-hour window, with no public accounting of what happened, how far the attackers got, or what remediation is underway.

The information gap is defensible from an operational-security standpoint — naming every affected system while the investigation is active could give the attackers intelligence about which defenses worked and which did not. But it also means that residents of those communities have no way to know whether their water system was touched, how the local response went, or what changes are being made. For a basic public service like drinking water, that opacity carries a different kind of cost.

💡 What “30+” probably means. MNIT’s statement uses “more than 30” without giving an upper bound. Reporting from Braham officials referenced being told that “at least four other communities” were attacked “with the same result,” which suggests the successful-intrusion count may be smaller than the total targeting count. The distinction between “targeted” and “compromised” is meaningful and has not been clarified publicly.

We thought all of our bases were covered,
but bad actors, they also have a plan.

Kevin Stahl · Braham City Administrator

Why the Minnesota Water Systems Attack Changes the Conversation

04

CyberAv3ngers and CVE-2021-22681

Attribution trail

Formal attribution for the Minnesota water systems attack is pending the federal investigation, but the circumstantial alignment is strong enough that multiple outlets have connected the dots. CyberAv3ngers is an Iranian state-directed threat group formally attributed to Iran’s IRGC Cyber-Electronic Command. The U.S. Treasury sanctioned the group in February 2024 after its first documented phase of U.S. water infrastructure attacks. Since then, CISA has tracked the group through four escalating capability phases, culminating in the July 22, 2026 update to Advisory AA26-097A that expanded the scope of targeted PLCs to include Schneider Electric and Siemens devices.

The suspected exploitation vector is CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers rated CVSS 9.8. The flaw was disclosed in 2021 and added to CISA’s Known Exploited Vulnerabilities catalog in March 2026 after confirmed exploitation by Iranian-affiliated actors. There is no vendor patch. Rockwell has stated that the affected product generation will not receive a fix, which means every Logix controller in the field is permanently vulnerable unless the operator deploys compensating controls — network segmentation, key-switch enforcement, or physical disconnection from any reachable network path.

💡 What “unpatchable” means in practice. CVE-2021-22681 is not a bug that is waiting for a fix. Rockwell has made a design decision that the affected architecture will not be updated. The only remediation is compensating controls or hardware replacement. For a small Minnesota water utility running a Rockwell PLC installed a decade ago, “replace the hardware” is a six-figure capital expense that competes with every other infrastructure need in the town’s budget.
05

CISA’s July 22 advisory update was a four-day warning

Timing

CISA’s update to Advisory AA26-097A on July 22 expanded the documented scope of Iranian PLC exploitation in three specific ways. First, it added Schneider Electric BMX P34/Modicon M340 and Siemens S7-1200 PLCs as confirmed targets alongside Rockwell Automation. Second, it documented project-file exfiltration for the first time — attackers stealing the programming files that define how a PLC operates, which gives them the blueprint to modify or sabotage the process. Third, it provided new detection guidance for manipulation of Add-On Instructions, the reusable code modules embedded in PLC programs.

The FBI observed at one victim facility that a malicious project file retained normal downstream ladder logic while inserting modified Add-On Instructions that disabled safety shutdown and alarm systems. The attackers also manipulated data on HMI and SCADA displays, allowing equipment to operate in unsafe conditions without alerting operators. That capability — disabling alarms while the equipment runs outside safe parameters — is the bridge between disruption and physical danger. It came four days before the Minnesota water systems were hit.

💡 The advisory-to-attack gap. Whether the Minnesota attackers read the CISA update and acted or had already planned the operation independently is unknowable from public reporting. What is knowable is that the advisory described a threat actor with exactly the capability set needed to execute what happened on July 26-27, and that the advisory landed in the middle of the same operational window. That timing makes the updated advisory the most relevant context for understanding the Minnesota incident.
06

Five Eyes published OT isolation guidance the same day

International context

On July 28 — the same day MNIT activated its statewide cybersecurity response — CISA jointly published CI Fortify with Australia’s Signals Directorate, the UK’s National Cyber Security Centre, and Canada’s Centre for Cyber Security. The guidance advises critical infrastructure operators to isolate essential OT systems from the rest of their networks so that services keep running even if a breach occurs. The document is not formally linked to the Minnesota incident, but publishing Five Eyes OT isolation guidance on the same day as a statewide water-utility response is the kind of timing that does not happen by accident in the intelligence coordination world.

CI Fortify’s core recommendation is straightforward: segment OT networks so that compromise of the IT network or internet-facing systems does not give attackers a path to the controllers that run physical processes. For the Minnesota water systems that were hit through cellular modems connecting remote assets back to the SCADA system, that segmentation was either incomplete or not present. The guidance is free and public. Implementing it at a small water utility with no dedicated network engineer is the expensive part.

💡 Why segmentation keeps failing. The CI Fortify recommendation assumes the utility has the expertise and budget to design a segmented network architecture, maintain it, and monitor it. Most of the 30+ Minnesota water systems on the affected list serve small communities with part-time IT support at best. The guidance is correct. The resource model to implement it does not exist at the municipal level without state or federal funding assistance.
07

Small towns are the actual attack surface

Structural problem

The Minnesota water systems attack is a demonstration of what happens when nation-state capability meets municipal-level defense. CyberAv3ngers, if the attribution holds, is an IRGC-backed group with documented capability across four phases of escalation, Treasury sanctions, and a dedicated CISA advisory. The defending organizations are small-town public works departments where the same person who manages the water plant also manages the sewer system, the streets, and the parks budget. That mismatch is not a failure of effort — it is a structural problem that no amount of advisory publishing can solve by itself.

The math is clear. There are approximately 50,000 community water systems in the United States. The vast majority serve small communities. Most do not have dedicated cybersecurity staff. Many run legacy SCADA systems with PLCs that are a decade or more old, connected to the internet through cellular modems or VPN tunnels that were set up once and never audited again. The Minnesota water systems incident is not an outlier — it is a preview of what happens when a determined actor decides to target the long tail of American critical infrastructure rather than the hardened top end.

💡 The federal funding question. CISA’s guidance, the Five Eyes CI Fortify publication, and EPA water-sector cybersecurity initiatives all exist. What does not exist at scale is the funding mechanism to turn that guidance into implemented controls at 50,000 small water systems. Until that gap closes, the Minnesota pattern — advisory, attack, statewide response, repeat — is the structural steady state.
🛡 Minnesota Water Systems Response Checklist
  • Inventory every PLC in the water/wastewater environment — identify Rockwell Automation Logix controllers subject to CVE-2021-22681 (no vendor patch exists)
  • Segment OT networks from IT and internet-facing systems — follow CI Fortify guidance to isolate controllers so that a breach in one layer cannot reach physical process control
  • Audit cellular modem connections at remote assets — water towers, lift stations, and pump stations connected via cellular are the vector Plymouth’s disclosure highlighted
  • Enable Rockwell key-switch enforcement — compensating control documented in CISA AA26-097A for sites that cannot replace hardware
  • Hunt for modified Add-On Instructions in PLC programs — FBI observations document attackers inserting AOIs that disable safety shutdowns and alarm systems
  • Verify manual-operation readiness — every Minnesota water utility that survived did so because staff could run the plant by hand, which requires training, physical presence, and documented procedures

⚠️ What the Minnesota Water Systems Attack Does Not Mean

1. Water quality was not affected. The Minnesota Department of Health confirmed that water quality was unaffected at all systems hit in the July 26-27 attacks. No boil-water advisories were issued. The attacks targeted automated controls, not the treatment chemistry itself.

2. Attribution is not final. CyberAv3ngers and CVE-2021-22681 are the leading alignment based on CISA advisory timing and known capability, but the federal investigation has not published a formal attribution. Other actors with similar PLC exploitation capability exist.

3. This is not the first time. CyberAv3ngers has targeted U.S. water infrastructure across four documented phases since 2020. The Aliquippa, Pennsylvania attack in November 2023 used the same group’s tooling. The Minnesota water systems incident is the latest — and largest — in a running series, not an isolated event.

Local governments are expected to defend
essential systems against foreign adversaries,
often with limited staff and aging technology.

Nate George · Mayor of Braham, Minnesota
✅ Bottom Line

The Minnesota Water Systems Attack, in Five Lines

1
30+ community water utilities targeted in 48 hours — July 26-27, 2026, the largest coordinated OT attack on U.S. water infrastructure documented to date
2
Braham’s plant shut down, Maple Plain declared emergency — Plymouth and South St. Paul switched to manual operations; water quality was unaffected at all sites
3
Iran-linked CyberAv3ngers suspected via CVE-2021-22681 — a five-year-old unpatchable Rockwell PLC authentication bypass rated CVSS 9.8
4
CISA updated its Iranian PLC advisory four days earlier — expanding scope to Schneider Electric and Siemens and documenting Add-On Instruction manipulation
5
The structural problem is resource mismatch — 50,000 U.S. community water systems, most with no dedicated cybersecurity staff, defending against state-backed threat actors
🔗 Tenable’s full analysis of the Minnesota water systems cyberattack and its connection to CISA Advisory AA26-097A is available at Tenable’s research blog, with city-level reporting from the Star Tribune, CBS Minnesota, FOX 9, and MinnPost.

💬 Minnesota Water Systems Cyberattack FAQ

Q. Is my drinking water safe if I live in Minnesota?
Yes. The Minnesota Department of Health confirmed that water quality was unaffected at all systems hit in the July 26-27 Minnesota water systems attacks. No boil-water advisories were issued anywhere in the state. The attacks targeted automated controls, not the water treatment chemistry itself. All four publicly named cities maintained or quickly restored water service.
Q. Why can’t Rockwell just patch CVE-2021-22681?
CVE-2021-22681 is an authentication bypass in Rockwell Automation Logix controllers that traces to the product architecture itself, not a bug in the software that sits on top. Rockwell has stated that the affected product generation will not receive a firmware fix. The only remediations are compensating controls — network segmentation, key-switch enforcement, restricting physical access — or replacing the hardware with a newer generation that does not have the architectural flaw.
Q. Were only water systems targeted, or other infrastructure too?
MNIT’s statement specifically references community water systems. The broader CISA Advisory AA26-097A documents Iranian-affiliated PLC exploitation across water, energy, and government sectors. Whether non-water Minnesota infrastructure was also targeted in the July 26-27 window has not been disclosed. The advisory’s expanded scope to Schneider and Siemens devices suggests the same actor has interest beyond water, but the Minnesota disclosure is limited to water and wastewater utilities.
Q. How does this compare to previous U.S. water cyberattacks?
The Minnesota water systems attack is the largest coordinated OT attack on U.S. water infrastructure publicly documented, measured by the number of utilities hit in a single campaign window. Prior incidents include the Aliquippa, Pennsylvania attack in November 2023, also attributed to CyberAv3ngers, and the Oldsmar, Florida incident in 2021 where an operator attempted to alter sodium hydroxide levels remotely. The Minnesota attack’s 30+ simultaneous targets mark a significant escalation in scale compared to those single-facility precedents, and the operational coordination required to hit that many targets in a 48-hour window indicates a level of pre-positioned access or automated targeting capability that previous campaigns did not demonstrate publicly.
Editor’s Note. This article draws on official statements from Minnesota IT Services, the City of Braham, the City of Maple Plain, the City of Plymouth, and the City of South St. Paul, CISA Advisory AA26-097A (updated July 22, 2026), the Five Eyes CI Fortify publication, and reporting from The Hacker News, BleepingComputer, SecurityWeek, Help Net Security, Star Tribune, CBS Minnesota, FOX 9, MinnPost/Civic Media, and Tenable. All dates, city names, and population figures were verified against primary sources as of July 31, 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top