All incidents

Coordinated cyberattacks target Minnesota water treatment PLCs

campaignopenJul 30, 2026 — Aug 2, 2026
CISA urges removal of online PLCs after Minnesota water attacks

CISA urges removal of internet‑exposed PLCs after coordinated cyberattacks hit over 30 Minnesota water systems on July 26‑27 2026, knocking out controls at Braham’s plant. The warning follows activity linked to the Iranian group Cyber Av3ngers.

According to SecurityAffairs, the attacks targeted programmable logic controllers that were reachable from the public internet, allowing threat actors to manipulate valve and pump sequences. No CVEs have been assigned to the exploited flaws, but the issue stems from default credentials and insufficient network segmentation. Affected products include various Siemens, Allen‑Bradley and Modicon PLC models commonly used in water treatment.

As noted by SecurityWeek, researchers observed the intrusions beginning on July 26 and lasting through July 27, with sporadic attempts noted until early August. The activity bears hallmarks of Cyber Av3ngers, an Iran‑linked group known for targeting OT in critical infrastructure. While no destructive malware was deployed, the temporary loss of control highlighted the risk to public health.

CISA advises operators to immediately disconnect PLCs from the internet and place them behind dedicated firewalls or in isolated OT zones. Changing all default passwords to strong, unique credentials is essential, as is enforcing multi‑factor authentication for any remote access.

Additional steps: Validate every external connection, disable unnecessary services such as Telnet or FTP, and maintain up‑to‑date firmware from vendors. Continuous monitoring for anomalous PLC traffic and logging of configuration changes can help detect future intrusions early.

Utilities should review their asset inventory to identify any internet‑facing devices, conduct penetration testing on OT networks, and involve OT‑savvy personnel in incident response planning. By reducing the attack surface and strengthening credential hygiene, the sector can lower the likelihood of repeat incidents.

Intelligence briefing updated Aug 2, 2026

Cyber Av3ngers
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline