CRITICALFortiBleed is actively compromising Fortinet firewalls. Is your domain exposed?
Run free scan
CyberXtron
Coordinated Cyberattack on U.S. Water Infrastructure: FBI Investigating 30+ Minnesota Systems.
#cyberxtron#USA#Minnesota#CyberAttack#FBI

Coordinated Cyberattack on U.S. Water Infrastructure: FBI Investigating 30+ Minnesota Systems.

Executive Summary

Between July 26 and July 27, 2026, a coordinated cyberattack struck the operational technology of more than 30 community water and wastewater systems in Minnesota. The intrusions targeted internet exposed programmable logic controllers, briefly taking one treatment plant offline and forcing several utilities onto manual operations. Within days, the FBI and EPA confirmed similar activity across at least seven states in total, and Michigan separately reported impacts to nine of its own water systems. A leaked WaterISAC memo, based on a Minnesota Fusion Center assessment, tied the campaign to Iran affiliated actors.

Key Takeaways

  1. Attackers exploited internet exposed Rockwell Automation and Allen Bradley MicroLogix 1100 and 1400 PLCs, changing IP addresses and passwords to lock operators out of monitoring and control functions.
  2. Operational effects reported to the FBI included loss of water pressure and flooding, with pressure loss creating a risk of untreated groundwater entering distribution pipes.
  3. Drinking water quality was not compromised in the confirmed Minnesota cases, and manual operations by trained staff prevented broader service disruption.
  4. Preliminary intelligence assessments point to Iran affiliated hackers, possibly CyberAv3ngers or a group called Handala, though no group has claimed responsibility and formal attribution remains pending.
  5. The incident reflects a systemic exposure across the US water sector, where roughly 170,000 utilities operate, and where EPA inspections found the majority of reviewed systems out of compliance with baseline risk assessment and emergency planning requirements.

Attacker Profile

April 2026 CISA advisory warning that Iran linked groups were targeting PLCs used in critical infrastructure.

Two named groups have been raised as possible:

  • CyberAv3ngers- a group publicly tied to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command with a history of targeting water sector industrial control systems since late 2023
  • Handala- a separate hacking group linked to prior disruptive incidents including a breach of a US federal official's personal email account earlier in 2026. Analysts describe the operational pattern as consistent with either group's known tradecraft, but caution that specific attribution between the two, or to a third actor entirely, has not been established.

Attack Method

Threat actors targeted internet facing PLCs directly rather than office IT networks. After gaining remote access, they altered device IP addresses and passwords, which cut off legitimate operators' ability to monitor or control connected equipment. At least one affected organization identified unauthorized changes to PLC project files after noticing discrepancies in the underlying control logic. Investigators also noted that shared network and hardware configurations deployed by common third party integrators may have allowed the actors to replicate successful intrusions across multiple utilities with similar setups, helping explain how so many systems were affected inside a 48 hour window.

Contributing factors identified by CISA and the FBI include undocumented remote access paths such as cellular modems installed by vendors or integrators, absence of network segmentation between OT and external connections, and reliance on end of life hardware no longer receiving security patches.

 

Targeted Vulnerability

The core weakness exploited was not a specific software flaw but direct internet exposure of OT devices, specifically Rockwell Automation and Allen Bradley MicroLogix 1100 and 1400 series PLCs, combined with weak or default authentication.

Targeted Country

United States (Minnesota and Michigan)

Targeted Industry

Water and Wastewater Systems, a designated USA critical infrastructure sector.

Victims

Confirmed or named entities include the City of Braham, Minnesota where the water plant briefly went offline.

Plymouth, Minnesota both of which shifted to manual operations after automated controls were affected.

Maple Plain, Minnesota which declared a local state of emergency to coordinate its response. Minnesota state officials confirmed more than 30 community water systems were affected in total, without naming all of them publicly.

 

 MITRE ATT&CK for ICS TTPs

T0883: Internet Accessible Device, used as the initial access vector through exposed PLCs.

T0859: Valid Accounts, reflecting the use of altered or compromised device credentials to maintain control.

T0836: Modify Parameter, corresponding to changes made to PLC configuration, IP addressing, and project logic.

T0831: Manipulation of Control, reflecting unauthorized changes to industrial process behavior via the compromised controllers.

T0813: Denial of Control, reflecting the loss of monitoring and control functionality experienced by operators after credentials and IP addresses were changed.

T0888: Remote System Information Discovery, consistent with attackers identifying and enumerating internet exposed OT assets prior to exploitation.

Mitigation Recommendations

  • Remove PLCs and other OT assets from direct public facing internet exposure, routing any remote access through a secure gateway or jump host rather than a direct connection.
  • Secure cellular modems used for remote field connectivity with strong authentication, and enable and regularly review connection logs for anomalies.
  • Consider isolated remote access architectures such as private access point names, non public network integration, cellular SD WAN, zero trust network access, or site to site VPN.
  • Enforce complex, unique passwords on all OT devices and eliminate default credentials.
  • Restrict network access to PLCs using firewall rules or access control lists limited to authorized control system devices only.
  • Place PLCs in a physically or logically protected run mode outside of active configuration windows to prevent unauthorized logic changes.
  • Validate project files against known good backups before restoring or redeploying them.
  • Maintain and regularly test the organization's ability to shift to manual operations during an OT incident.
  • Maintain a rolling twelve month forecast of end of life OT hardware and prioritize replacement or compensating controls for devices no longer receiving vendor security updates.

Conclusion

This incident illustrates how a relatively simple technique, exploiting internet exposed industrial controllers with weak credential hygiene, can produce wide scale disruption across a fragmented and under resourced critical infrastructure sector. While Minnesota and Michigan utilities avoided a public health impact thanks to trained staff and manual failover procedures, the speed and geographic spread of the campaign, more than 30 systems in Minnesota alone within 48 hours and confirmed activity in at least seven states, points to a scalable and repeatable intrusion method rather than an isolated event. With attribution still unresolved and tension between the United States and Iran ongoing, water utilities of all sizes should treat this as an active warning to audit internet facing OT assets and close the specific gaps the FBI and CISA have publicly identified.

Elevate your security—get curated threat insights in your inbox.