Coordinated Attack Disrupts More Than 30 Minnesota Water Utilities
Over two days in July, controllers from three vendors were manipulated into pressure loss, flooding and forced manual operation, with related incidents reported in at least twelve states.

Attacks on 26 and 27 July 2026 affected more than thirty Minnesota communities, with Braham, Plymouth, South St. Paul and Maple Plain publicly named, and related PLC incidents were reported across at least twelve states. CISA advisory AA26-097A, updated on 22 July 2026, covers the campaign.
The targeted equipment spans three vendors: Rockwell Automation MicroLogix 1100 and 1400 series and Logix controllers, Schneider Electric BMX P34 and Modicon M340, and Siemens S7-1200. The documented impacts are what make this worth reading rather than filing. Computerised controls were disabled and systems temporarily shut down. Water pressure was lost and flooding occurred. Operations were forced to manual. Boil-water notices were issued. Operators were locked out by password changes, and PLCs were disconnected by modifying their IP addresses.
Physical consequence from control-system compromise is rare in the public record, and this is a documented case of it.
The vulnerabilities cited are not new. CVE-2021-22681 is an authentication bypass with a CVSS score of 9.8 and no patch available. CVE-2023-3595 also scores 9.8, and CVE-2024-6242 scores 8.4. Attribution points to CyberAv3ngers, linked to the IRGC Cyber-Electronic Command, though federal and state officials had not publicly attributed the Minnesota attacks to a specific actor at the time of reporting.
The entry point was internet-reachable controllers with weak or default authentication rather than a novel exploit, which is the part with a lesson in it. For integrators serving municipal utilities the actions are concrete: inventory MicroLogix and M340 assets in service, remove any direct internet reachability, and plan a migration path for CVE-2021-22681 specifically, because there is no patch for it and the only remedy is architectural.
Small utilities are the hardest case here. A municipal water system with a part-time operator and no security staff is exactly the environment where a controller ends up on a public IP for remote access, and exactly the one least able to respond when that becomes a problem.
Source: Tenable