{"id":8943,"date":"2026-07-30T21:53:36","date_gmt":"2026-07-30T21:53:36","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8943"},"modified":"2026-07-30T21:53:36","modified_gmt":"2026-07-30T21:53:36","slug":"a-coordinated-attack-hit-30-minnesota-water-systems-who-did-it-and-what-does-a-rockwell-notice-add-to-the-picture","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8943","title":{"rendered":"A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness.<\/p>\n<p class=\"wp-block-paragraph\">While the affected communities reported that drinking water remained safe and disruptions were limited, security researchers say the incident marks another escalation in a months-long campaign targeting US water infrastructure amid heightened geopolitical tensions with Iran.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is a first-of-its-kind distributed attack on water utilities,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/markusmuellerics\/\">Markus Mueller<\/a>, field CISO at Nozomi Networks, tells CSO. \u201cBased on the publicly available information, it was clearly aimed at disruption rather than financial gain.\u201d<\/p>\n<h2 class=\"wp-block-heading\">What happened?<\/h2>\n<p class=\"wp-block-paragraph\">Minnesota IT Services <a href=\"https:\/\/mn.gov\/mnit\/media\/blog\/?id=38-761869\">disclosed<\/a> that the water systems experienced coordinated cyber activity over a two-day period from July 26 to July 27. The city of Braham, with roughly 1,700 people in Isanti County, <a href=\"https:\/\/www.mprnews.org\/story\/2026\/07\/27\/braham-cyberattack-knocked-water-system-offline\">suffered<\/a> the most visible operational impact after shutting down portions of its water system for roughly two hours while operators regained control of affected systems.<\/p>\n<p class=\"wp-block-paragraph\">The city of Plymouth <a href=\"https:\/\/www.plymouthmn.gov\/Home\/Components\/News\/News\/8977\/542\">disconnected<\/a> cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the intrusion and prevent the attackers from regaining access while the equipment was reconfigured. The city of <a href=\"https:\/\/www.startribune.com\/plymouth-south-st-paul-water-system-cyber-attack\/601872810\">South St. Paul<\/a> said some automated controls were affected, and the city of Maple Plain declared a local state of emergency to expand its response.<\/p>\n<p class=\"wp-block-paragraph\">The incident comes just days after CISA, the FBI, NSA and EPA <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\">expanded<\/a> an advisory warning that Iranian-affiliated cyber actors continue targeting programmable logic controllers (PLCs) used throughout US critical infrastructure, including water systems.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,\u201d CISA Acting Director Nick Andersen said in a statement provided to CSO. \u201cWe urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe also encourage all organizations to review the latest guidance on CISA.gov and to report suspected incidents or anomalous activity to us for further support,\u201d Andersen said.<\/p>\n<h2 class=\"wp-block-heading\">More than another utility hack<\/h2>\n<p class=\"wp-block-paragraph\">Experts agree that the attacks stand apart from previous incidents because they were coordinated across numerous utilities rather than focused on a single victim.<\/p>\n<p class=\"wp-block-paragraph\">Nozomi\u2019s Mueller believes that this coordination strongly suggests investigators will eventually identify some technical thread connecting the affected communities.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTo be this sector-specific,\u201d he says, \u201cmy assumption would be that there is something that ties these together beyond simply being Minnesota water utilities.\u201d He thinks investigators may ultimately discover a shared systems integrator, communications architecture or other common infrastructure that made the utilities collectively vulnerable.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/ronniefabela\/\">Ron Fabela<\/a>, an industrial control systems researcher who closely tracks attacks against operational technology, reached a similar conclusion after examining publicly available information.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI searched Minnesota\u2019s public IP space and didn\u2019t find obvious exposed water infrastructure,\u201d he says. \u201cMany of these utilities use cellular communications, which makes them much harder to identify than internet-facing industrial systems.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That distinction could explain why dozens of geographically clustered utilities were affected while neighboring infrastructure apparently was not.<\/p>\n<h2 class=\"wp-block-heading\">The Rockwell connection<\/h2>\n<p class=\"wp-block-paragraph\">An additional development could prove significant as investigators continue examining the attacks.<\/p>\n<p class=\"wp-block-paragraph\">According to a source familiar with the federal investigation, authorities are examining whether vulnerable Rockwell Automation MicroLogix 1400 PLCs served as a common enabling factor in the campaign.<\/p>\n<p class=\"wp-block-paragraph\">Fabela ran a targeted Shodan search on Plymouth\u2019s public IP space and found the city using at <a href=\"https:\/\/www.shodan.io\/host\/166.163.186.2\">least<\/a> <a href=\"https:\/\/www.shodan.io\/host\/166.163.186.6\">two<\/a> Rockwell Automation MicroLogix 1400 controllers.<\/p>\n<p class=\"wp-block-paragraph\">The possibility aligns with both recent federal warnings and a July 30 <a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1790.html\">Rockwell Automation security advisory<\/a> addressing the MicroLogix 1400 family of controllers. Earlier federal guidance identified Rockwell Automation\/Allen-Bradley PLCs among the industrial controllers being actively targeted by Iranian-affiliated threat actors before expanding the warning to additional PLC manufacturers.<\/p>\n<p class=\"wp-block-paragraph\">On July 30, amid the investigation into the Minnesota attacks, CISA issued <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/30\/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs\">fresh guidance<\/a> urging water and wastewater utilities to remove publicly exposed PLCs and other operational technology from the internet as quickly as possible.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.tenable.com\/profile\/scott-caveza\">Scott Caveza<\/a>, senior staff research engineer at Tenable, the first security organization to issue a <a href=\"https:\/\/www.tenable.com\/blog\/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-knowhttps:\/www.tenable.com\/blog\/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know\">report<\/a> on the incident, cautioned that the timing alone does not establish causation. \u201cThe timing certainly makes it suspicious,\u201d Caveza says. \u201cRockwell Automation devices have routinely been targeted by these groups before, so it\u2019s definitely plausible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">If exposed PLCs did provide attackers with access, the implications extend beyond simple monitoring.<\/p>\n<p class=\"wp-block-paragraph\">\u201cDepending on configuration,\u201d Caveza explains, \u201can attacker could gain monitoring capability, manipulate what operators see, or in some circumstances modify operational settings.\u201d Fortunately, manual safety controls built into most water facilities make catastrophic consequences considerably more difficult.<\/p>\n<p class=\"wp-block-paragraph\">The relatively quick recovery in Braham appears consistent with that assessment. Operators restored systems within roughly two hours, and no boil-water orders were issued.<\/p>\n<p class=\"wp-block-paragraph\">CISA\u2019s July 30 alert did not identify the equipment involved in the Minnesota incidents or address whether Rockwell controllers played a role. However, the agency\u2019s renewed emphasis on removing internet-exposed PLCs closely mirrors both Rockwell\u2019s own mitigation guidance and one of the questions investigators are now examining: whether exposed Rockwell controllers provided a common avenue into multiple utilities.<\/p>\n<h2 class=\"wp-block-heading\">Attribution remains the biggest unanswered question<\/h2>\n<p class=\"wp-block-paragraph\">Federal agencies have stopped short of publicly identifying those responsible, although most experts believe Iranian-affiliated actors remain the leading suspects.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/cynthia-kaiser-cyber\/\">Cynthia Kaiser<\/a>, former FBI cyber deputy director and now vice president of strategy and policy at Halcyon, says the attacks closely followed recent federal warnings describing an active Iranian campaign targeting operational technology.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou have the FBI and other US government agencies putting out an urgent warning about Iran targeting operational controls,\u201d she tells CSO. \u201cThen this larger coordinated campaign occurs. Geopolitically, Iran has the strongest motivation to conduct this kind of chaos-driven cyberattack.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Still, Kaiser acknowledges investigators lack a definitive technical smoking gun. Instead, she argues Iran increasingly benefits from what she calls \u201cstrategic ambiguity.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThey thrive in people suspecting it might be them but not knowing for sure,\u201d she says. \u201cThat ambiguity complicates response and buys them time operationally.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That explanation may help resolve one of the attack\u2019s biggest mysteries.<\/p>\n<p class=\"wp-block-paragraph\">Unlike previous campaigns by CyberAv3ngers and other Iranian-aligned hacktivist groups, no convincing public victory videos or detailed Telegram posts immediately appeared following the Minnesota attacks. In an unusual delay, an Iranian state publication <a href=\"https:\/\/wanaen.com\/handala-launches-widespread-attack-on-minnesota-water-infrastructure\/\">attributed<\/a> the attack to threat group Handala only on July 29, days after the incident.<\/p>\n<p class=\"wp-block-paragraph\">Handala itself has been silent, even though it <a href=\"https:\/\/x.com\/H4ND4L4\/status\/2081289467390771391?s=20\">claimed credit<\/a> on X on July 26 for a cyberattack targeting the network infrastructure of SupraNet Communications, a major internet service provider based in Madison, Wisc.<\/p>\n<p class=\"wp-block-paragraph\">That Handala claimed credit for one attack days earlier but has said nothing about Minnesota deepens the mystery of its silence here.<\/p>\n<p class=\"wp-block-paragraph\">Fabela noted that absence stood out. \u201cNeither Handala nor CyberAv3ngers has publicly claimed responsibility the way we\u2019ve seen in previous campaigns,\u201d he says. \u201cNormally they post screenshots or proof. We haven\u2019t seen that yet.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Mueller also found the silence unusual.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAt the peak we were tracking more than a hundred Iranian splinter groups,\u201d he says. \u201cThen everything became very quiet. Even with renewed kinetic activity, we haven\u2019t seen the same level of public boasting.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Lessons for water utilities<\/h2>\n<p class=\"wp-block-paragraph\">Whatever the final attribution, experts say the attacks reinforce an uncomfortable reality: Attackers often do not need sophisticated zero-day exploits to disrupt operational technology.<\/p>\n<p class=\"wp-block-paragraph\">Rather, they succeed because industrial control devices remain directly reachable from the internet, protected by weak credentials, or deployed without the network segmentation long recommended by federal agencies.<\/p>\n<p class=\"wp-block-paragraph\">Fabela summed up the irony this way: \u201cTying all these pieces together, it seems the threat actors are implementing the CISA-recommended actions for PLCs \u2014 without operator permission, of course: set a password, remove them from the internet. Joking, not joking.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe guidance is pretty typical,\u201d Caveza says. \u201cDon\u2019t connect these devices directly to the internet. These are things we hope would already be common knowledge\u2014but unfortunately things happen.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness. While the affected communities reported that drinking water remained safe [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8944,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8943","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8943"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8943"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8943\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8944"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}