Hackers Hit 30 Minnesota Water Systems
in 48 Hours, One Plant Went Dark
Braham’s water plant shut down. Maple Plain declared a state of emergency. Plymouth went manual. The attack hit operational technology at 30+ community utilities on July 26-27, and the suspected tool is a five-year-old PLC flaw that has no vendor patch.
The Minnesota water systems cyberattack started on a Sunday night and reached across 30 communities before Monday was over. On July 26 and 27, 2026, hackers hit operational technology at more than 30 community water and wastewater utilities across Minnesota. In Braham, a town of roughly 1,700 people an hour north of the Twin Cities, the attack disabled computerized operating controls and shut down the well and water treatment plant entirely. Residents were told to minimize water use until the plant could be restarted. It came back online roughly two hours later, but the town was left with whatever water was already stored in its tower.
Three other cities disclosed the attack on Monday. Plymouth, population 80,000, reported that cellular communications at two water towers and multiple wastewater lift stations went offline and the city switched to manual operations. South St. Paul confirmed that automated controls were affected but staff maintained service by running the system by hand. Maple Plain declared a local state of emergency to expedite its response. The Minnesota Department of Health said water quality was never affected and no boil-water advisories were issued anywhere in the state.
The remaining 26-plus affected Minnesota water systems have not been named. Minnesota IT Services classified the full list as nonpublic, citing operational security during an active investigation. But the attack’s timing is not a coincidence. Four days before the assault, on July 22, CISA updated Advisory AA26-097A — its running documentation of Iranian-affiliated PLC exploitation activity — to expand the scope of targeted devices from Rockwell Automation to Schneider Electric and Siemens, and to add new detection guidance for manipulated Add-On Instructions inside PLC programs. The suspected tool behind the Minnesota water systems attack is CVE-2021-22681, a five-year-old Rockwell Automation authentication bypass rated CVSS 9.8 that has no vendor patch and never will.
How were the Minnesota water systems hit?
Attackers targeted operational technology — the SCADA systems that manage pumps, valves, and remote monitoring — at 30+ community water and wastewater utilities across Minnesota in a coordinated 48-hour campaign on July 26-27.
Who is suspected?
Attribution is pending federal investigation, but the timing aligns with CISA Advisory AA26-097A documenting Iranian-affiliated CyberAv3ngers PLC exploitation activity. CyberAv3ngers is formally linked to Iran’s IRGC Cyber-Electronic Command and sanctioned by the U.S. Treasury.
Did anyone lose water?
Braham’s water plant shut down for approximately two hours. Plymouth, South St. Paul, and Maple Plain switched to manual operations. No water quality was affected, no boil-water advisories were issued, and no customer data was compromised.
What vulnerability was used?
CVE-2021-22681 (CVSS 9.8) is an authentication bypass in Rockwell Automation Logix controllers. It was added to CISA’s KEV catalog in March 2026. There is no vendor patch available and Rockwell has stated none is planned for the affected product generation.
What Happened Across the Minnesota Water Systems
Braham’s plant went dark for two hours
Worst hitBraham was the most operationally complete attack of the four publicly disclosed incidents. The hackers disabled the town’s computerized operating controls, which shut down the well and the water treatment plant. For roughly two hours, Braham had no active water production — residents were living off whatever volume was already stored in the water tower. City Administrator Kevin Stahl told local media that the attackers used malicious software to compromise a wireless connection to the water plant. The town’s response was direct: shut the entire computer system down, cut external access, and wait for federal guidance on how to reconnect.
Braham’s mayor, Nate George, framed the incident in structural terms that apply to every small town on the list. Local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology, and inadequate resources. A community of 1,700 people does not have a dedicated SOC. It has a city administrator who also handles budgets, roads, and zoning — and who is now also responsible for defending against an IRGC-linked threat actor.
Plymouth, South St. Paul, and Maple Plain went manual
Confirmed targetsPlymouth — population 80,000 and the largest of the four disclosed cities — reported that cellular communications at two water towers and multiple wastewater lift stations went offline late Sunday. Public Works Director Michael Thompson confirmed the city was operating the system manually. Denis Calderone, CTO of Suzu Labs, noted in SecurityWeek that the cellular communications vector is the revealing detail: water towers, lift stations, and pump stations connect back to the SCADA system over cellular modems, and those secondary communication links are frequently overlooked in risk assessments.
South St. Paul confirmed that automated controls were affected but Public Works staff maintained normal water and wastewater operations through manual procedures. Maple Plain went further and declared a local state of emergency to expedite the city’s response. Maple Plain officials also noted that some details about the incident cannot be shared because releasing them could raise risks to infrastructure or interfere with the ongoing cybersecurity investigation.
26+ more cities remain unnamed
Nonpublic scopeMinnesota IT Services classified the full list of affected Minnesota water systems as nonpublic, citing risks to infrastructure and the ongoing investigation. Only the four cities that voluntarily disclosed — Braham, Plymouth, South St. Paul, and Maple Plain — are named in the public record. That leaves at least 26 additional communities somewhere in Minnesota whose water or wastewater operational technology was targeted in the same 48-hour window, with no public accounting of what happened, how far the attackers got, or what remediation is underway.
The information gap is defensible from an operational-security standpoint — naming every affected system while the investigation is active could give the attackers intelligence about which defenses worked and which did not. But it also means that residents of those communities have no way to know whether their water system was touched, how the local response went, or what changes are being made. For a basic public service like drinking water, that opacity carries a different kind of cost.
We thought all of our bases were covered,
but bad actors, they also have a plan.
Why the Minnesota Water Systems Attack Changes the Conversation
CyberAv3ngers and CVE-2021-22681
Attribution trailFormal attribution for the Minnesota water systems attack is pending the federal investigation, but the circumstantial alignment is strong enough that multiple outlets have connected the dots. CyberAv3ngers is an Iranian state-directed threat group formally attributed to Iran’s IRGC Cyber-Electronic Command. The U.S. Treasury sanctioned the group in February 2024 after its first documented phase of U.S. water infrastructure attacks. Since then, CISA has tracked the group through four escalating capability phases, culminating in the July 22, 2026 update to Advisory AA26-097A that expanded the scope of targeted PLCs to include Schneider Electric and Siemens devices.
The suspected exploitation vector is CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers rated CVSS 9.8. The flaw was disclosed in 2021 and added to CISA’s Known Exploited Vulnerabilities catalog in March 2026 after confirmed exploitation by Iranian-affiliated actors. There is no vendor patch. Rockwell has stated that the affected product generation will not receive a fix, which means every Logix controller in the field is permanently vulnerable unless the operator deploys compensating controls — network segmentation, key-switch enforcement, or physical disconnection from any reachable network path.
CISA’s July 22 advisory update was a four-day warning
TimingCISA’s update to Advisory AA26-097A on July 22 expanded the documented scope of Iranian PLC exploitation in three specific ways. First, it added Schneider Electric BMX P34/Modicon M340 and Siemens S7-1200 PLCs as confirmed targets alongside Rockwell Automation. Second, it documented project-file exfiltration for the first time — attackers stealing the programming files that define how a PLC operates, which gives them the blueprint to modify or sabotage the process. Third, it provided new detection guidance for manipulation of Add-On Instructions, the reusable code modules embedded in PLC programs.
The FBI observed at one victim facility that a malicious project file retained normal downstream ladder logic while inserting modified Add-On Instructions that disabled safety shutdown and alarm systems. The attackers also manipulated data on HMI and SCADA displays, allowing equipment to operate in unsafe conditions without alerting operators. That capability — disabling alarms while the equipment runs outside safe parameters — is the bridge between disruption and physical danger. It came four days before the Minnesota water systems were hit.
Five Eyes published OT isolation guidance the same day
International contextOn July 28 — the same day MNIT activated its statewide cybersecurity response — CISA jointly published CI Fortify with Australia’s Signals Directorate, the UK’s National Cyber Security Centre, and Canada’s Centre for Cyber Security. The guidance advises critical infrastructure operators to isolate essential OT systems from the rest of their networks so that services keep running even if a breach occurs. The document is not formally linked to the Minnesota incident, but publishing Five Eyes OT isolation guidance on the same day as a statewide water-utility response is the kind of timing that does not happen by accident in the intelligence coordination world.
CI Fortify’s core recommendation is straightforward: segment OT networks so that compromise of the IT network or internet-facing systems does not give attackers a path to the controllers that run physical processes. For the Minnesota water systems that were hit through cellular modems connecting remote assets back to the SCADA system, that segmentation was either incomplete or not present. The guidance is free and public. Implementing it at a small water utility with no dedicated network engineer is the expensive part.
Small towns are the actual attack surface
Structural problemThe Minnesota water systems attack is a demonstration of what happens when nation-state capability meets municipal-level defense. CyberAv3ngers, if the attribution holds, is an IRGC-backed group with documented capability across four phases of escalation, Treasury sanctions, and a dedicated CISA advisory. The defending organizations are small-town public works departments where the same person who manages the water plant also manages the sewer system, the streets, and the parks budget. That mismatch is not a failure of effort — it is a structural problem that no amount of advisory publishing can solve by itself.
The math is clear. There are approximately 50,000 community water systems in the United States. The vast majority serve small communities. Most do not have dedicated cybersecurity staff. Many run legacy SCADA systems with PLCs that are a decade or more old, connected to the internet through cellular modems or VPN tunnels that were set up once and never audited again. The Minnesota water systems incident is not an outlier — it is a preview of what happens when a determined actor decides to target the long tail of American critical infrastructure rather than the hardened top end.
- Inventory every PLC in the water/wastewater environment — identify Rockwell Automation Logix controllers subject to CVE-2021-22681 (no vendor patch exists)
- Segment OT networks from IT and internet-facing systems — follow CI Fortify guidance to isolate controllers so that a breach in one layer cannot reach physical process control
- Audit cellular modem connections at remote assets — water towers, lift stations, and pump stations connected via cellular are the vector Plymouth’s disclosure highlighted
- Enable Rockwell key-switch enforcement — compensating control documented in CISA AA26-097A for sites that cannot replace hardware
- Hunt for modified Add-On Instructions in PLC programs — FBI observations document attackers inserting AOIs that disable safety shutdowns and alarm systems
- Verify manual-operation readiness — every Minnesota water utility that survived did so because staff could run the plant by hand, which requires training, physical presence, and documented procedures
⚠️ What the Minnesota Water Systems Attack Does Not Mean
1. Water quality was not affected. The Minnesota Department of Health confirmed that water quality was unaffected at all systems hit in the July 26-27 attacks. No boil-water advisories were issued. The attacks targeted automated controls, not the treatment chemistry itself.
2. Attribution is not final. CyberAv3ngers and CVE-2021-22681 are the leading alignment based on CISA advisory timing and known capability, but the federal investigation has not published a formal attribution. Other actors with similar PLC exploitation capability exist.
3. This is not the first time. CyberAv3ngers has targeted U.S. water infrastructure across four documented phases since 2020. The Aliquippa, Pennsylvania attack in November 2023 used the same group’s tooling. The Minnesota water systems incident is the latest — and largest — in a running series, not an isolated event.
Local governments are expected to defend
essential systems against foreign adversaries,
often with limited staff and aging technology.