More than 30 community water systems in Minnesota were hit by a coordinated attack on July 26–27, 2026. The offensive exploited programmable logic controllers (PLCs) exposed to the internet, specifically Rockwell Automation Logix models affected by CVE-2021-22681, a critical vulnerability with a CVSS 9.8 score for which no patch exists. According to Tenable analysis and CISA documentation, the cryptographic key for authentication is embedded in the engineering software, rendering the bypass credential-agnostic.
Editor's note: DeafNews was unable to independently verify with Rockwell Automation the confirmation that no patch is available. Claims of unpatchability derive from Tenable analysis and CISA advisories. Additionally, the Minnesota Department of Information Technology (MNIT) explicitly declined to provide official attribution of the attack to a specific actor.
- Over 30 water systems in Minnesota struck on July 26–27, 2026 in a coordinated attack; four cities publicly disclosed impact: Braham, Plymouth, South St. Paul, and Maple Plain.
- CVE-2021-22681 is a critical authentication bypass (CVSS 9.8) in Rockwell Automation Logix PLCs; the cryptographic key is embedded in the engineering software.
- CISA added the vulnerability to the KEV catalog in March 2026; advisory AA26-097A, updated July 22, 2026, expanded scope to Schneider Electric PLCs (BMX P34/Modicon M340) and Siemens (S7-1200).
- MNIT confirmed a common incident profile — similar timelines, access methods, target types — describing them as a coordinated attack, without providing official attribution.
Key Stat5,219 Rockwell Automation hosts exposed globally on the internet (Censys, April 2026); 74.6% (3,891 systems) reside in the United States.
How the Flaw Works
CVE-2021-22681 stems from a Rockwell Automation design choice. The cryptographic key for authenticating to Logix PLCs is embedded in the engineering software. Anyone with that software can extract the key and authenticate to the controllers as an engineer, without a username or password. According to CISA, this flaw cannot be fixed without breaking backward compatibility with existing installations.
Advisory AA26-097A, dated July 22, 2026, documents observed tactics: exfiltration of project files, manipulation of Add-On Instructions (AOIs), and alteration of HMI/SCADA displays to mask unsafe operating conditions. Operators saw normal parameters while physical processes were diverted. There was no ransomware or extortion demand: the objective was industrial process manipulation.
According to Censys (April 2026), 5,219 Rockwell Automation hosts are exposed globally on the internet; 74.6%, or 3,891 systems, reside in the United States. A disproportionate share traverse cellular networks, making segmentation problematic for remote utilities with limited connectivity.
The July 26–27 Attack: Timeline
The offensive against Minnesota water systems began on July 26, 2026. In Braham, a town of roughly 1,700 residents, the plant remained offline for about two hours. In Plymouth, population ~80,000, IT staff disconnected cellular equipment at two water towers and multiple wastewater lift stations. South St. Paul suffered impact on automated controls. Maple Plain declared a local emergency.
The Minnesota Department of Health confirmed that drinking water quality was not compromised and no boil-water advisories were issued in the state. However, operational impact was tangible: according to the FBI and EPA in their July 30, 2026 PSA, the Rockwell MicroLogix 1100 and 1400 series were identified as targets, with operational effects including loss of pressure and flooding in other jurisdictions.
The offensive's scope exceeded Minnesota. According to ABC News (Aug. 4) and CBS News (Aug. 6), at least 12 U.S. states were affected. The FBI/EPA PSA of July 30 confirmed seven. Confirmed victims include the Clayton County Water Authority in Georgia (300,000 customers, boil-water advisory issued), Columbus Water Works in Georgia, nine systems in Michigan, plus cases in South Dakota and New Jersey.
Attribution: Consistency Without Confirmation
The U.S. government has formally attributed the CyberAv3ngers group to the IRGC Cyber-Electronic Command (IRGC-CEC) through Treasury sanctions (February 2024) and the Rewards for Justice program. CyberAv3ngers is tracked under multiple vendor designations: Storm-0784, Bauxite, UNC5691, G1027. CISA advisory AA26-097A — signed by FBI, CISA, NSA, EPA, DOE, and Treasury — assesses that "an APT actor group affiliated with Iran" is responsible for the PLC exploit campaign.
For Minnesota specifically, attribution stops. MNIT explicitly declined to provide public attribution. Scott Caveza, senior staff research engineer at Tenable, assessed that "these tactics remain consistent with the tradecraft attributed to CyberAv3ngers and other IRGC-CEC affiliated groups." This is a consistency assessment, not a confirmation. The possibility of copycat actors replicating shared TTPs remains open.
Technical Debt as Permanent Vulnerability
CVE-2021-22681 represents a distinct risk category: the unremediable design flaw. This is not an implementation bug fixed with an update, but an architectural decision that prioritized backward compatibility over security. According to Tenable analysis and CISA documentation, no patch is available or planned for this vulnerability.
Minnesota responded with physical disconnection: Plymouth severed cellular equipment, cutting the remote attack surface. Braham operated the plant manually during the outage. These responses are reactive, not preventive: the flaw remains in deployed devices.
The regulatory context amplifies the pressure. The EPA in 2024 found that over 70% of U.S. water systems were non-compliant with 2018 risk assessment requirements. An audit of 1,000 systems identified 97 critical or high-risk vulnerabilities. With 150,000–170,000 total water systems, most small and resource-constrained, the attack surface remains vast.
Immediate Actions
Actions documented in primary sources for this specific case include: disconnection of exposed cellular equipment, as implemented by Plymouth; manual plant operation during outages, as in Braham; monitoring CISA advisories for updates on AA26-097A; verification of EPA compliance with risk assessment requirements.
Available sources do not specify detailed technical recommendations beyond these documented responses. Reporting OT system anomalies to CISA and the FBI is the standard procedure indicated in government advisories.
Why It Matters
The Minnesota case demonstrated the operational feasibility of coordinated attacks on distributed, small utilities. Braham Mayor Nate George summarized: "Local governments in Minnesota must defend essential systems against foreign adversaries and sophisticated criminals, often with limited staff, outdated technology, and inadequate resources."
The attack raises an architectural question: when a design flaw is embedded in decades of installed infrastructure, security can no longer be just patching. Minnesota's response — physical disconnection, manual operation — is functional but costly. Pressure on U.S. water systems, already under regulatory standards, will continue to grow with the exposure of legacy OT devices.
Sources: Tenable (coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know); TechTimes (iranian-hackers-exploited-unpatchable-plc-flaw-breach-30-minnesota-water-systems); AdYog (minnesota-water-systems-coordinated-plc-attack); CISA AA26-097A; CISA AA23-335A; The Hacker News (coordinated-cyberattack-targets-30).
Information verified against cited sources and current as of publication.
Sources
- https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know
- https://www.techtimes.com/articles/322059/20260729/iranian-hackers-exploited-unpatchable-plc-flaw-breach-30-minnesota-water-systems.htm
- https://pulse.adyog.com/insights/minnesota-water-systems-coordinated-plc-attack
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
- https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html