
More than 30 water utilities across Minnesota got hit at once. That’s not a metaphor. A coordinated cyberattack struck operational technology systems at community water systems on July 26 and 27. One plant went fully offline. The rest kept running on backup procedures.
No one has officially named a culprit yet. But the timing and the technique both point toward a familiar suspect: an Iran-linked group called CyberAv3ngers.
Who are CyberAv3ngers? A hacking group first spotted around 2020, widely believed tied to Iran’s Revolutionary Guard. It started as an online propaganda persona before shifting to real attacks on US water infrastructure in late 2023. Its specialty, hunting down internet-exposed industrial equipment protected by nothing more than a default password.
One Plant Down, Dozens More On Backup
Braham, a small city north of the Twin Cities, felt it worst. Attackers disabled the computerized controls running its well and treatment systems. The plant went completely offline. Operators switched to manual controls and had the facility running again within about two hours.
Other cities reported disruptions too. Maple Plain, Plymouth, and South St. Paul all confirmed impact. Plymouth’s issue centered on cellular-connected equipment out at its water towers. Most utilities never lost operations entirely. Staff fell back on manual procedures and contingency plans instead.
A Pattern That Keeps Repeating
This playbook was not created by CyberAv3ngers. Way back in late 2023, the threat actors compromised more than 75 Unitronics Vision-series controllers, which were all located in water utilities across the United States, Israel, UK, and Ireland. All these devices were publicly accessible through the internet, still using their factory-default passwords.
The cyber criminals took advantage of this successful campaign. They released the IOCONTROL malware kit in 2024-2025, which allowed them to develop a consistent strategy of attacking operational technology and IoT devices. The target base was increased. Rockwell Automation and Allen-Bradley products were added to the list in the beginning of this year. Schneider Electric and Siemens products were targeted on July 22, right before the attacks against utilities in Minnesota.
It is fairly simple to conduct such cyberattacks against small utilities. The main reason for this lies in the fact that most of these utilities operate on a shoestring budget and lack any specialists in OT cybersecurity. Remote access applications such as TeamViewer or AnyDesk are being used to provide remote support but are then completely forgotten.
Nobody Has Named A Culprit Yet
Officials have been careful with attribution so far. Minnesota IT Services confirmed the coordinated nature of the attack without naming a group. The Minnesota CISO, John Israel, called it a problem requiring “a coordinated, whole-of-government response.” He said the FBI, CISA, the EPA, and several state agencies are now involved.
The CyberAv3ngers link rests on pattern-matching, not a confession. Operational style, target selection, and timing all point the same direction. The attack landed just days after CISA’s July 22 advisory on Iran-linked PLC targeting. None of that proves it outright. It’s simply the most consistent explanation available right now.
What stands out isn’t the sophistication. It’s the opposite. Default passwords and internet-facing controllers, not zero-days, keep opening these doors. Officials say drinking water safety was never at risk this time. The margin for that to stay true keeps looking thinner with each repeat.
Conclusion: When Exposed OT Reaches the Physical Process
The Minnesota water attacks show how quickly a weakness at the IT and OT boundary can become an operational event.
Sophistication is not required when basic exposure is widespread.
More than 30 community water systems were targeted during the same two-day period. Braham temporarily lost its computerized operating controls, while other utilities relied on backup procedures and manual operations to keep essential services running.
Drinking water safety was not reported to be at risk.
The margin for keeping it that way became smaller.
Attribution remains unconfirmed. CyberAv3ngers is the leading suspicion because the timing, target selection, and operational pattern resemble previous Iran-linked activity against exposed industrial equipment. That connection should be treated as a strong investigative lead, not a proven conclusion. The exact Minnesota access path has also not been publicly disclosed.
Why This Threat Matters
The campaign shows that attackers do not always need a zero-day or a complex intrusion chain to disrupt critical infrastructure.
- Internet-facing industrial systems can create direct paths into operational environments.
- Default, shared, or weak credentials can reduce authentication to a procedural obstacle.
- Forgotten remote-support tools can leave access paths active long after their original purpose has ended.
- Cellular-connected equipment can create remote paths outside expected enterprise network controls.
- Small utilities often operate with limited OT security staffing and aging infrastructure.
- Legacy equipment may lack modern authentication, centralized monitoring, and detailed logging.
- A compromised control environment can affect wells, pumps, treatment processes, towers, telemetry, and operator visibility.
- Manual operations may preserve service, but they are a resilience measure, not a substitute for security architecture.
The warning is not that every exposed controller will produce a public safety event. It is that weak configuration, unnecessary internet reachability, and insufficient segmentation can give an unauthorized actor influence over a physical process.
Where Xcitium Changes the Outcome
This attack class must be addressed first at the exposed IT and OT boundary, then across the managed systems that administer, support, or communicate with the operational environment.
Xcitium Vulnerability Assessment helps organizations identify internet-facing services, outdated supporting systems, exposed remote-access paths, and configuration weaknesses within the supported assessment scope.
Visibility must lead directly to remediation.
Industrial controllers should not be directly reachable from the public internet. Default and shared credentials must be replaced. Remote access should be restricted, monitored, and disabled when no longer required. IT and OT systems should communicate only through explicitly approved and secured paths.
Device-specific OT security remains essential. Endpoint controls do not replace secure PLC configuration, firmware maintenance, network segmentation, vendor-specific hardening, or tested recovery procedures.
On engineering workstations, HMIs, jump servers, operator endpoints, maintenance laptops, and remote-support systems, Xcitium Advanced EDR, powered by Xcitium’s patented Zero-Dwell platform, applies Execution Governance.
Unknown code does not receive unrestricted execution rights before trust exists.
Code can run without being able to cause damage.
Unknown scripts, tools, services, and payloads are governed before they can alter real system resources on the managed endpoint. Security teams also gain evidence of how unknown execution was restricted and which policies were enforced.
Detection asks, “Did we recognize this activity as malicious?”
Execution Governance asks, “Should unknown execution be allowed to alter the managed systems that support the physical process?”
That is the architectural difference.
Govern the Exposure. Control the Execution.
The Minnesota incidents show how weaknesses defenders have understood for years can still disrupt critical infrastructure.
Remove industrial systems from direct internet exposure.
Replace default, shared, and reused credentials.
Eliminate obsolete or unauthorized remote-access tools.
Require strong authentication wherever the equipment supports it.
Segment operational networks from business systems.
Validate controller configurations and project files against known-good states.
Maintain tested manual operations and recovery procedures.
Govern unknown execution across every managed system that can administer, support, or reach the OT environment.