Skip to main content
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours
Cybersecurity

Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours

#12037Article ID
Continue Reading
This article is available in the following languages:

Click to read this article in another language

🎧 Audio Version
Download Podcast

On July 26, 2026, over 30 municipal water systems across Minnesota were targeted in a coordinated 48-hour cyberattack. Attributed to CyberAv3ngers, an IRGC-linked group, the assault exploited CVE-2021-22681—an unpatchable architectural flaw in Rockwell PLCs. Braham's water treatment plant was shut down, while other utilities switched to manual operations. Fortunately, drinking water quality remained safe with no boil-water advisories issued.

Share this brief:

Cyberattack on 30 American Cities' Drinking Water

How a coordinated cyber operation paralyzed Minnesota's critical infrastructure for 48 hours

PLAY
Key Attack Highlights
  • 🎮
    Attack Timeline
    - July 26-27, 2026 - A coordinated 48-hour operation
  • 🎧
    Attack Scope
    - Over 30 municipal water systems in Minnesota
  • 🚀
    Suspected Attacker
    - Cyber group linked to Iran
  • 🗡️
    Vulnerability Used
    - CVE-2021-22681 in Rockwell PLCs - no patch available

The Night of July 26: When Water for 30 Cities Came Under Threat

On the night of July 26, 2026, a coordinated and unprecedented cyberattack began targeting more than 30 municipal water and wastewater systems across Minnesota. This attack, which continued for 48 hours, was one of the most extensive cyber operations against American critical infrastructure in recent years.

In Braham, a city with about 1,700 residents, the water treatment plant completely shut down. Residents woke up that morning to shocking news: the computerized controls managing the wells and water treatment plant had been disabled by unknown actors.

🎯

At a Glance

  • Over 30 municipal water systems in Minnesota targeted in coordinated attack
  • Braham water treatment plant completely shut down
  • Attack executed over 48 hours on July 26-27, 2026
  • No changes reported in drinking water quality
  • CyberAv3ngers prime suspect using CVE-2021-22681

How the Attack Began: Four Cities, Four Different Stories

Nate George, Braham's mayor, said in a statement: Minnesota's local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources.

⚠️

Critical Infrastructure Under Siege

The Minnesota attacks represent a dangerous evolution in cyber warfare tactics. Unlike previous incidents targeting individual facilities, this was a synchronized multi-target operation designed to overwhelm local response capabilities. Security experts warn that this coordinated approach could become the new standard for state-sponsored attacks on American critical infrastructure.
تصویر 1

Plymouth, with a population of approximately 80,000, had a different experience. Rather than losing service, the city's IT division took a preemptive step: it disconnected the cellular-connected equipment at two water towers and multiple wastewater lift stations from the network to stop the intrusion and prevent re-targeting while systems were reconfigured. Operations continued through manual procedures throughout.

South St. Paul reported that some automated utility controls were affected but that contingency procedures prevented any major impact to operations. Maple Plain declared a local state of emergency to accelerate its response.

Ensuring Water Safety: No Danger to Citizens

Minnesota IT Services confirmed the incidents shared a common profile - similar timing, access methods, and target types - and described them as a coordinated attack on operational technology at community water systems statewide.

No boil-water advisories were issued. The Minnesota Department of Health confirmed that drinking water quality was unaffected at all impacted systems. As of July 29, the investigation remained active and authorities have not publicly identified the attackers, the access method used, the specific equipment affected, or whether any data was exfiltrated.

تصویر 2

Four Days Before: A Warning That Went Unheeded

The timing of the Minnesota attacks is not incidental. On July 22 - precisely four days before the intrusions began - CISA, along with the FBI, NSA, EPA, and the Department of Energy, published a significant update to Advisory AA26-097A titled "Iranian-Affiliated Cyber Actors Exploit PLCs Across U.S. Critical Infrastructure."

That update substantially expanded what was already a serious warning in three ways. It broadened the scope of confirmed targeting beyond Rockwell Automation devices to include Schneider Electric and Siemens PLCs - specifically the Schneider Electric BMX P34/Modicon M340 and the Siemens S7-1200.

It documented, for the first time, confirmed exfiltration of PLC project files: using legitimate vendor engineering software - Rockwell's Studio 5000 Logix Designer, Schneider's EcoStruxure Control Expert, and Siemens' TIA Portal - hosted on leased third-party infrastructure, attackers had been pulling industrial control project files out of victim environments.

Timeline: From Warning to Attack

July 22, 2026: CISA, FBI, NSA, EPA and DOE update Advisory AA26-097A - expanding targeting to Schneider and Siemens PLCs

July 26, 2026 (night): Coordinated attacks on Minnesota water systems begin

July 27, 2026 (morning): Braham treatment plant shuts down - cities initiate manual operations

July 27, 2026 (noon): Braham recovers service after 2 hours

July 28, 2026: MNIT officially announces coordinated attack

July 29, 2026: Investigation continues - over 30 affected systems confirmed

And it added new detection guidance for the manipulation of Add-On Instructions, or AOIs - reusable code modules embedded in PLC programs. In one confirmed incident documented by investigators, actors inserted malicious AOIs into an otherwise normal PLC project file that disabled safety shutdown and alarm systems, while simultaneously feeding falsified data to operator displays to mask what was happening at the hardware level.

"
CISA's updated reporting shows a worrying expansion in Iran-linked critical infrastructure targeting focused on the United States
U.S. Federal Security Agencies - Advisory AA26-097A

CVE-2021-22681: The Flaw That Cannot Be Fixed

At the center of the current Iranian campaign is CVE-2021-22681, a critical authentication bypass in Rockwell Automation's Logix controller family. The flaw is architectural: the cryptographic key Rockwell's Studio 5000 Logix Designer software uses to authenticate communication sessions with Logix PLCs is embedded in the software in a recoverable form.

Anyone who can extract that key - and Iranian-affiliated actors have clearly done so - can impersonate legitimate engineering software and gain direct, unauthenticated access to any internet-facing Logix controller. Once connected, the attacker has engineering-level privileges: they can download project files, upload modified logic, disable alarms, and alter what operators see on their screens.

CVE-2021-22681 was disclosed by Rockwell Automation in February 2021 and assigned a CVSS 3.x severity score of 9.8 out of 10. The flaw went unexploited in the wild for five years - not because it was obscure, but because OT environments are extraordinarily difficult to patch.

تصویر 3

Water treatment plants, energy facilities, and wastewater systems cannot take their industrial controllers offline on a standard IT patching cycle without disrupting services that must run continuously. The result is a permanent gap: a critical, known vulnerability sitting exposed in infrastructure that cannot safely be updated to close it.

Confirmed in-the-wild exploitation began in March 2026, when CISA added CVE-2021-22681 to its Known Exploited Vulnerabilities catalog. Rockwell Automation has since confirmed what was already clear from the flaw's architecture: there is no patch available and none is forthcoming. The authentication system would have to be redesigned from the ground up - at the cost of compatibility with every PLC already deployed.

🔴

CVE-2021-22681: An Unfixable Flaw

CVSS Score: 9.8 out of 10 (Critical)

Disclosure Date: February 2021

First Exploitation: March 2026 (5 years later)

Patch Status: No patch available and Rockwell confirmed none will be provided

Reason: Architectural flaw - cryptographic key embedded in software

Solution: Architectural only - remove from internet, network segmentation, enable CIP Security

Global Exposed Devices: 5,219 hosts (74.6% in United States)

CyberAv3ngers: Four Phases and a Proliferating Playbook

No official attribution for the Minnesota attacks has been announced. But security researchers at Tenable's Research Special Operations team assessed that the operational pattern - the targeting of internet-facing PLCs at water utilities, the specific infrastructure affected, and the timing relative to the July 22 CISA advisory - is consistent with the CyberAv3ngers threat ecosystem.

📊

CyberAv3ngers Evolution: Four Attack Phases

PhaseTimelineTarget TypePrimary TechniqueImpact Level
Phase 12020-2022Israeli infrastructurePropaganda claimsLow - mostly fabricated
Phase 2Oct 2023 - Jan 2024Unitronics PLCs (75 devices)Default passwordsMedium - manual control required
Phase 32024-2025Linux IoT/ICS systemsIOCONTROL malwareMedium - sustained access
Phase 4Mar 2026 - presentRockwell/Schneider/Siemens PLCsCVE-2021-22681 exploitationHigh - coordinated multi-target

CyberAv3ngers - a threat group attributed by security researchers to Iranian state actors - has been active since at least 2020. According to U.S. Treasury Department reports from February 2024, the group has operational ties to Iranian security entities and has been identified in multiple campaigns against Western critical infrastructure.

تصویر 4

The group's evolution is a documented escalation across four phases. From 2020 to 2022, it operated largely as a propaganda persona, claiming attacks on Israeli infrastructure that were later assessed as fabricated.

Between October 2023 and January 2024, it compromised at least 75 Unitronics Vision Series PLCs across the United States, United Kingdom, Israel, and Ireland - exploiting default passwords on internet-exposed devices - in what CISA confirmed was likely four separate attack waves. The highest-profile victim was the Municipal Water Authority of Aliquippa, Pennsylvania, which was forced to switch a pumping station to manual control.

In 2024 and 2025, the group deployed IOCONTROL, a custom-built Linux malware platform designed for industrial control and IoT environments, using MQTT over TLS to blend its command-and-control traffic with legitimate network activity.

Since March 2026, the group shifted to what Tenable describes as Phase Four: active exploitation of CVE-2021-22681, connecting directly to internet-facing Rockwell PLCs using legitimate engineering software and using that access to download, modify, and re-upload controller logic across water, energy, and government sectors.

🎧
Scott Caveza - Tenable Research
Security Analyst Note
CyberAv3ngers' techniques have proliferated to more than 60 affiliated hacktivist groups coordinated through an Electronic Operations Room. Researchers warn that these proxy groups - replicating the group's ICS exploitation playbook with less discipline than the core unit - increase the risk of unintended physical consequences. An operator who does not fully understand the effects of modifying PLC logic in a water treatment environment may inadvertently create conditions that affect water quality or service continuity in ways the core CyberAv3ngers organization would deliberately avoid.

The Broader Campaign: Water Infrastructure as a Target

The Minnesota attacks did not emerge from a vacuum. Throughout spring and summer 2026, cyber tensions between the United States and Middle Eastern regional actors have escalated. Security researchers have observed a similar pattern in attacks on water infrastructure on both sides - indicating a period of escalating reciprocal cyber operations.

This pattern of reciprocity - where physical attacks on one side's infrastructure lead to cyber responses from the other - is a concerning feature of modern conflicts. The evolution from physical attacks to cyber operations allows state actors to target civilian objectives without direct military consequences.

تصویر 5

The following day, the Handala threat group - attributed by security researchers to Iran and also known as Void Manticore - claimed it had breached California Water Service billing systems in Bakersfield, Visalia, and Chico, publishing 5 gigabytes of exfiltrated data including customer personal information.

On July 23 - three days before the Minnesota attacks began - Handala escalated its warnings further, claiming a cyberattack on Maryland's operational technology infrastructure and issuing a statement declaring that U.S. water, electricity, and transportation networks would be front-line targets of its future operations.

Why Small Water Utilities Keep Losing

The Minnesota attacks are the latest chapter in a much longer story: the chronic vulnerability of small U.S. water utilities to cyberattack - a vulnerability that is structural rather than individual.

A March 2024 EPA enforcement alert found that 70% of water systems inspected by the agency since 2023 were in violation of a provision requiring them to develop or update risk assessments and emergency response plans.

A 2024 EPA Inspector General report found critical or high-severity cybersecurity vulnerabilities in 97 of 1,000 audited drinking water systems - systems collectively serving approximately 26.6 million people. A 2024 GAO report found that EPA has struggled to identify legal authorities to effectively address water sector cyber risks.

The United States has approximately 150,000 to 170,000 water systems in total. Many are small, rural, and operating with a single IT contractor - or none at all. Tenable's researchers note that the pattern of CyberAv3ngers' success against small water utilities is not coincidental but structural.

Many of these organizations manage their operational technology environments using consumer-grade remote access tools such as TeamViewer or AnyDesk, or by directly exposing PLC management interfaces to the public internet - access methods that bypass enterprise security controls entirely.

تصویر 6

The problem is compounded by inadequate network segmentation between IT and OT environments. When a PLC is reachable from the same network segment as an email server, the blast radius of any compromise extends far beyond the initial entry point. When that PLC also controls water pressure, chemical dosing, or sewage pump operations, the consequences of a sustained compromise can extend into the physical world.

GAME REVIEW SUMMARY
6.0
Serious structural vulnerability
PROS
  • Swift MNIT response and cooperation with FBI, CISA, EPA
  • No changes reported in drinking water quality
  • Plymouth's preemptive actions in disconnecting cellular equipment
  • Braham's quick service recovery in 2 hours
CONS
  • Over 30 water systems exposed to coordinated attack
  • CVE-2021-22681 remains unpatchable and exploitable
  • 70% of water systems in violation of EPA security requirements
  • 5,219 Rockwell devices exposed globally to internet

What Every Water Utility Must Do Now

CISA's updated Advisory AA26-097A provides specific, prioritized defensive guidance for organizations operating internet-exposed PLCs, particularly those running Rockwell Automation, Schneider Electric, or Siemens equipment.

The single highest-priority action is removing PLCs from direct internet exposure. CVE-2021-22681 allows unauthenticated access to any internet-accessible Rockwell Logix controller - no credentials required, no prior foothold needed, and no patch available. Every such device is exploitable right now.

Where remote access is operationally necessary, a secure gateway with multifactor authentication is the minimum acceptable substitute for direct internet exposure.

Beyond that, CISA recommends: setting physical mode switches on PLCs to Run mode to block remote modification of controller logic; downloading the updated CISA-issued indicators of compromise and deploying them in SIEM, IDS, and firewall platforms; implementing network segmentation to isolate engineering workstations; auditing all cellular OT connections and replacing consumer cellular modems with industrial cellular gateways that support VPN tunnels and multifactor authentication.

تصویر 7

Minnesota's Lessons: What Must Change?

The Minnesota attacks demonstrate that the cybersecurity problem of American water infrastructure has moved beyond a technical issue to become a structural crisis. Temporary solutions are no longer sufficient - we need a complete overhaul in how these critical systems are protected, monitored, and managed.

📊

Alarming U.S. Water Security Statistics

70% of water systems in violation of EPA security requirements

97 of 1,000 audited systems have critical vulnerabilities

26.6 million people served by vulnerable systems

150,000-170,000 total water systems in United States

5,219 Rockwell devices exposed to internet globally

74.6% of exposed devices are in the United States

Nate George, Braham's mayor, articulated this reality well: Minnesota's local governments are expected to defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, aging technology and inadequate resources. This is a nationwide problem that requires a nationwide solution.

🔧

Three Structural Priorities for Water Infrastructure Protection

1. Dedicated Federal Funding: EPA and CISA must create grant programs specifically targeting rural and small water utilities for OT security upgrades, secure gateway deployment, and cybersecurity professional hiring.

2. Mandatory Requirements: EPA must use its enforcement power to mandate compliance. Every water system with a publicly-accessible PLC must have an enforceable remediation timeline.

3. National Disclosure Standard: A federal mandate for timely incident reporting to CISA can help prevent future attacks.

Three Essential Structural Changes

First, dedicated federal funding for small water utility cybersecurity. EPA and CISA must create grant programs specifically targeting rural and small water utilities for OT security upgrades, secure gateway deployment, and cybersecurity professional hiring. Without financial resources, most of these systems cannot make necessary investments.

Second, mandatory requirements for network segmentation and removal of internet-connected PLCs. EPA must use its enforcement power to mandate compliance. Every water system with a publicly-accessible PLC must have an enforceable remediation timeline. This is no longer an optional recommendation - this is a national vulnerability.

Third, a national standard for critical infrastructure cyber incident disclosure. Minnesota was an exception because MNIT acted quickly and transparently. Many similar incidents are never publicly reported, meaning the broader security community cannot learn from them. A federal mandate for timely incident reporting to CISA can help prevent future attacks.

The Role of Vendors: An Ignored Responsibility

Rockwell Automation, Schneider Electric, and Siemens have a significant role in this crisis. CVE-2021-22681 is a product design flaw - not a software bug that can be patched. This was an architectural choice that sacrificed security for convenience.

These vendors must take greater responsibility for helping customers remediate these vulnerabilities. This includes offering secure gateways at reduced prices, providing free migration services for transitioning from insecure architectures, and developing next-generation controllers with security by design.

The ICS industry consortium should develop minimum security standards for all new OT equipment. If a PLC cannot implement proper authentication, it should not be certified for deployment in critical infrastructure.

تصویر 8

The Long-Term Threat: Beyond Minnesota

Minnesota is a warning, not an anomaly. The techniques used in these attacks are proliferating to affiliated hacktivist groups. CyberAv3ngers has developed a playbook that includes CVE-2021-22681 exploitation, AOI manipulation, and use of cellular equipment as entry vectors.

🛡️

Immediate Action Plan for Water Utilities

Day 1 - Emergency Assessment: Conduct immediate inventory of all internet-facing PLCs and cellular connections. Document every Rockwell, Schneider, and Siemens controller with external network access.

Days 2-3 - Network Isolation: Disconnect all non-essential internet-facing control systems. Implement emergency network segmentation between IT and OT environments using available hardware.

Week 1-2 - Secure Gateway Deployment: Deploy secure VPN gateways with multifactor authentication for necessary remote access. Replace consumer cellular modems with industrial-grade secure gateways.

Week 2-4 - Monitoring Enhancement: Enable logging on all PLCs and network equipment. Deploy CISA indicators of compromise. Establish baseline behavior for anomaly detection.

Ongoing - Backup and Recovery: Create offline backups of all PLC logic and configurations. Test manual operation procedures. Document emergency response workflows and train staff.

This playbook is now in the hands of dozens of groups that may lack the operational discipline of the core CyberAv3ngers unit. The risk of an incident that inadvertently impacts water quality or service continuity increases with each new group that adopts these techniques.

Moreover, geopolitical tensions between the United States and Iran remain unresolved. Iranian cyber operations against American water infrastructure have escalated since the April ceasefire, not declined. The logic of reciprocity driving these attacks - U.S. strikes on Iranian water reservoirs leading to Iranian cyber attacks on American water systems - is persistent.

The Future of Water Security: A Path Forward

The long-term solution requires a multi-layered approach. At the technical level, every water system must: remove PLCs from direct internet exposure; implement secure gateways with MFA for remote access; enforce network segmentation between IT and OT; enable continuous monitoring for anomalous activity; and maintain offline backups of PLC logic and configurations.

Technical Defense-in-Depth Strategy

Network segmentation is not optional - it is the foundational layer of any defensible OT architecture. Water utilities must implement multiple security zones: a demilitarized zone (DMZ) for internet-facing services, an IT corporate zone for business systems, and an isolated OT zone for industrial control systems. Traffic between zones must pass through inspecting firewalls with strict whitelist rules. No PLC should ever be reachable from the corporate network without passing through a secured gateway that logs and authenticates every connection.

Multi-factor authentication is essential for any remote access pathway. The Plymouth incident demonstrated how cellular modems with weak authentication become the entire attack surface. Industrial cellular gateways with VPN tunnels, certificate-based authentication, and geofencing capabilities should replace consumer-grade cellular modems. If an operator needs remote access to troubleshoot a field device, they should authenticate through multiple factors - something they know, something they have, and ideally something they are.

Continuous monitoring with behavioral baselines can detect anomalous activity before it escalates. Water utilities should deploy network monitoring tools that understand industrial protocols like EtherNet/IP, Modbus, and CIP. These tools should establish normal communication patterns - which devices talk to which other devices, at what frequency, with what command types - and alert on deviations. An engineering workstation that suddenly connects to a field PLC at 2 AM when no maintenance is scheduled should trigger an immediate investigation.

Offline backups of PLC logic and configuration files are the last line of defense. If an attacker does gain access and modify controller logic, operators need a known-good baseline to restore from. These backups must be stored offline - not on a network share that the same attacker could reach - and tested regularly to ensure they can be restored quickly during an incident. The backup should include not just the ladder logic but also the device configuration, network settings, and any Add-On Instructions or custom function blocks.

At the organizational level, water utilities need: cybersecurity training programs for staff; incident response plans with tested emergency procedures; regular security audits by third-party assessors; and collaboration with neighbors for threat intelligence sharing.

تصویر 9

Organizational Readiness and Human Factors

Technology alone cannot secure water infrastructure - the human element is equally critical. Every employee at a water utility, from the plant operator to the administrative assistant, needs basic cybersecurity awareness training. Phishing simulations tailored to the water sector can help staff recognize social engineering attempts targeting operational technology credentials. One compromised email account with access to the engineering workstation can become the entry point for a sophisticated attack.

Incident response plans must move beyond generic IT disaster recovery templates. Water utilities need OT-specific response playbooks that address scenarios like unauthorized PLC logic modification, loss of SCADA visibility, or ransomware affecting control systems. These plans should specify: who has authority to disconnect systems from the network, how to transition to manual operations safely, what communication protocols to follow with state and federal agencies, and under what conditions to notify the public. Tabletop exercises that walk through realistic attack scenarios help identify gaps before a real incident occurs.

Third-party security assessments bring an external perspective that internal teams may lack. A qualified ICS security assessor can identify vulnerabilities that operators accustomed to their environment might overlook - the default password still active on a backup PLC, the undocumented VPN connection a contractor installed years ago, or the network tap that provides visibility but also creates an unmonitored access point. These assessments should happen annually at minimum, with more frequent reviews after significant system changes.

Information sharing with neighboring utilities and through sector ISACs (Information Sharing and Analysis Centers) multiplies defensive effectiveness. When one utility detects a reconnaissance scan against their PLCs, sharing those indicators with neighbors allows the broader community to defend preemptively. The Minnesota attacks affected 30+ systems because attackers could execute a coordinated campaign across multiple independent targets. A coordinated defense that shares real-time threat intelligence can level that asymmetry.

At the policy level, we need: federal legislation for water infrastructure cybersecurity; dedicated funding for security upgrades; better cooperation between EPA, CISA and state agencies; and international diplomacy to establish norms against cyber attacks on civilian critical infrastructure.

Final Message: This Is a National Security Issue

The Minnesota attacks demonstrated that water system cybersecurity is no longer a local IT problem - it is a national security issue. When nation-state actors can coordinately attack 30+ water systems in one state, we face a systematic vulnerability that requires a systematic response.

Clean drinking water is a fundamental right, not a privilege. Protecting the systems that provide that water must be a national priority. Minnesota showed us what happens when that protection fails. The question is: Will we listen?

The silence in Braham on the morning of July 27 - when the water treatment plant shut down and 1,700 people were cut off from their water - was a glimpse of a future where cyberattacks disable not just data but essential services. This is a future we must prevent.

The cost of inaction is clearly on display: more vulnerability, more attacks, and eventually, a catastrophic incident that impacts not just control systems but the water itself. We still have time to prevent that future - but the window is closing.

Minnesota was a test case. The next one might be much worse. Will we be ready?

Frequently Asked Questions

Is Minnesota's drinking water safe after the cyberattack?

Yes, according to state and local officials. The Minnesota Department of Health confirmed that water quality was unaffected at all systems hit in the July 26-27 attacks, and no boil-water advisories were issued anywhere in the state. The attacks targeted automated control systems - the equipment that manages pumps, valves, and remote monitoring - rather than the water treatment chemistry itself.

Who is CyberAv3ngers, and are they definitely behind this attack?

CyberAv3ngers is a threat group attributed by security researchers and Western intelligence agencies to Iranian state actors. As of July 29, no U.S. government agency has officially attributed the Minnesota attacks to CyberAv3ngers. The attribution comes from Tenable's Research Special Operations team, which assessed that the operational pattern is consistent with the CyberAv3ngers playbook.

Why can't water utilities just patch CVE-2021-22681?

There is no patch. Rockwell Automation has confirmed that CVE-2021-22681 cannot be addressed with a software update because the flaw is architectural - it stems from a shared cryptographic key embedded in the engineering software that cannot be changed without breaking compatibility with every Logix PLC already deployed. The only remediation is architectural - removing the PLC from internet exposure, adding network segmentation, enabling CIP Security.

What is the single most important step a water utility operator should take right now?

Disconnect any PLC with a public IP address from the internet immediately. CVE-2021-22681 requires no prior credentials, no phishing, no insider access - only a network connection to an exposed Rockwell Logix controller and a cryptographic key that Iranian-affiliated actors have already extracted. The Plymouth incident demonstrated exactly how a cellular modem connecting a field PLC to a public IP becomes the entire attack surface.

How does Minnesota compare to previous water infrastructure attacks?

The Minnesota attacks are the largest known coordinated operation against U.S. water systems to date. Previous CyberAv3ngers attacks in 2023-2024 targeted 75 Unitronics PLCs across four countries but were primarily individual devices. Minnesota attacks targeted 30+ systems simultaneously using a more sophisticated vulnerability in broader industrial equipment. This represents a significant escalation in capability and scope.

Should we expect more attacks?

Yes. CyberAv3ngers' techniques have proliferated to over 60 affiliated hacktivist groups, and CVE-2021-22681 remains unpatchable. As long as thousands of Rockwell PLCs remain internet-connected, they will remain exploitable targets. The geopolitical situation between the U.S. and Iran remains tense, and water infrastructure remains a propaganda target with potential physical impact.

Additional Gallery: Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours

Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 1
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 2
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 3
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 4
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 5
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 6
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 7
Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours - Gallery image 8
Majid Ghorbaninazhad
Article Author
Majid Ghorbaninazhad

Majid Ghorbaninejad, founder of TakinGame with 25 years in the gaming industry.

TakinGame Community

Your feedback directly impacts our roadmap.

+500 Active Participations
Follow the Author

Contents

Cyberattack on 30 U.S. Cities' Drinking Water | How CyberAv3ngers Paralyzed Minnesota for 48 Hours