A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness.
While the affected communities reported that drinking water remained safe and disruptions were limited, security researchers say the incident marks another escalation in a months-long campaign targeting US water infrastructure amid heightened geopolitical tensions with Iran.
“This is a first-of-its-kind distributed attack on water utilities,” that the water systems experienced coordinated cyber activity over a two-day period from July 26 to July 27. The city of Braham, with roughly 1,700 people in Isanti County, cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the intrusion and prevent the attackers from regaining access while the equipment was reconfigured. The city of an advisory warning that Iranian-affiliated cyber actors continue targeting programmable logic controllers (PLCs) used throughout US critical infrastructure, including water systems.
“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” CISA Acting Director Nick Andersen said in a statement provided to CSO. “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”
“We also encourage all organizations to review the latest guidance on CISA.gov and to report suspected incidents or anomalous activity to us for further support,” Andersen said.
More than another utility hack
Experts agree that the attacks stand apart from previous incidents because they were coordinated across numerous utilities rather than focused on a single victim.
Nozomi’s Mueller believes that this coordination strongly suggests investigators will eventually identify some technical thread connecting the affected communities.
“To be this sector-specific,” he says, “my assumption would be that there is something that ties these together beyond simply being Minnesota water utilities.” He thinks investigators may ultimately discover a shared systems integrator, communications architecture or other common infrastructure that made the utilities collectively vulnerable.
addressing the MicroLogix 1400 family of controllers. Earlier federal guidance identified Rockwell Automation/Allen-Bradley PLCs among the industrial controllers being actively targeted by Iranian-affiliated threat actors before expanding the warning to additional PLC manufacturers.
On July 30, amid the investigation into the Minnesota attacks, CISA issued , senior staff research engineer at Tenable, the first security organization to issue a , former FBI cyber deputy director and now vice president of strategy and policy at Halcyon, says the attacks closely followed recent federal warnings describing an active Iranian campaign targeting operational technology.
“You have the FBI and other US government agencies putting out an urgent warning about Iran targeting operational controls,” she tells CSO. “Then this larger coordinated campaign occurs. Geopolitically, Iran has the strongest motivation to conduct this kind of chaos-driven cyberattack.”
Still, Kaiser acknowledges investigators lack a definitive technical smoking gun. Instead, she argues Iran increasingly benefits from what she calls “strategic ambiguity.”
“They thrive in people suspecting it might be them but not knowing for sure,” she says. “That ambiguity complicates response and buys them time operationally.”
That explanation may help resolve one of the attack’s biggest mysteries.
Unlike previous campaigns by CyberAv3ngers and other Iranian-aligned hacktivist groups, no convincing public victory videos or detailed Telegram posts immediately appeared following the Minnesota attacks. In an unusual delay, an Iranian state publication on X on July 26 for a cyberattack targeting the network infrastructure of SupraNet Communications, a major internet service provider based in Madison, Wisc.
That Handala claimed credit for one attack days earlier but has said nothing about Minnesota deepens the mystery of its silence here.
Fabela noted that absence stood out. “Neither Handala nor CyberAv3ngers has publicly claimed responsibility the way we’ve seen in previous campaigns,” he says. “Normally they post screenshots or proof. We haven’t seen that yet.”
Mueller also found the silence unusual.
“At the peak we were tracking more than a hundred Iranian splinter groups,” he says. “Then everything became very quiet. Even with renewed kinetic activity, we haven’t seen the same level of public boasting.”
Lessons for water utilities
Whatever the final attribution, experts say the attacks reinforce an uncomfortable reality: Attackers often do not need sophisticated zero-day exploits to disrupt operational technology.
Rather, they succeed because industrial control devices remain directly reachable from the internet, protected by weak credentials, or deployed without the network segmentation long recommended by federal agencies.
Fabela summed up the irony this way: “Tying all these pieces together, it seems the threat actors are implementing the CISA-recommended actions for PLCs — without operator permission, of course: set a password, remove them from the internet. Joking, not joking.”
“The guidance is pretty typical,” Caveza says. “Don’t connect these devices directly to the internet. These are things we hope would already be common knowledge—but unfortunately things happen.”
SOCIAL SHARE CARD GENERATOR