Iran-Linked Hackers Suspected in Minnesota Water Attack

A coordinated cyberattack hit 30+ Minnesota water utilities, knocking one plant offline. Iran-linked CyberAv3ngers are the leading suspect.

Audit Every Path That Can Touch the Plant
  • July 31, 2026

More than 30 water utilities across Minnesota got hit at once. That’s not a metaphor. A coordinated cyberattack struck operational technology systems at community water systems on July 26 and 27. One plant went fully offline. The rest kept running on backup procedures.

No one has officially named a culprit yet. But the timing and the technique both point toward a familiar suspect: an Iran-linked group called CyberAv3ngers.

Who are CyberAv3ngers? A hacking group first spotted around 2020, widely believed tied to Iran’s Revolutionary Guard. It started as an online propaganda persona before shifting to real attacks on US water infrastructure in late 2023. Its specialty, hunting down internet-exposed industrial equipment protected by nothing more than a default password.

One Plant Down, Dozens More On Backup

Braham, a small city north of the Twin Cities, felt it worst. Attackers disabled the computerized controls running its well and treatment systems. The plant went completely offline. Operators switched to manual controls and had the facility running again within about two hours.

Other cities reported disruptions too. Maple Plain, Plymouth, and South St. Paul all confirmed impact. Plymouth’s issue centered on cellular-connected equipment out at its water towers. Most utilities never lost operations entirely. Staff fell back on manual procedures and contingency plans instead.

30+ Water Utilities, One Coordinated Hit

Utilities Hit
30+ in Minnesota
Suspected Actor
CyberAv3ngers
How They Got In
Default Passwords
Systems Targeted
Water Plant OT/ICS
What Happened
  • On July 26-27, control systems at 30+ Minnesota water utilities were hit in a single coordinated push.
  • Braham’s plant dropped fully offline; staff switched to manual controls and had it running again in ~2 hours.
  • Maple Plain, Plymouth, and South St. Paul reported disruptions too; most sites leaned on backup procedures rather than losing operations outright.
The Likely Culprit
  • No group has been named officially, but the timing and technique line up with CyberAv3ngers, a crew widely tied to Iran’s Revolutionary Guard.
  • Started as a propaganda front around 2020, then pivoted to real US water-infrastructure attacks in late 2023.
  • Its trademark: hunting internet-facing industrial gear protected by nothing more than a factory-default password.
A Familiar Playbook
  • Late 2023: the same style of attack hit 75+ internet-exposed Unitronics controllers across four countries, all still on default logins.
  • That success seeded the IOCONTROL malware kit, later expanded to Rockwell and Allen-Bradley gear.
  • Schneider Electric and Siemens equipment were added to the target list on July 22, days before Minnesota was hit.
Why Small Utilities Keep Losing
Factor Detail
Utilities Hit 30+ across Minnesota, one weekend
2023 Precedent 75+ Unitronics PLCs, 4 countries
Target List Growth Rockwell, Siemens, Schneider added since
Root Cause Default passwords and forgotten remote-access tools

A Pattern That Keeps Repeating

This playbook was not created by CyberAv3ngers. Way back in late 2023, the threat actors compromised more than 75 Unitronics Vision-series controllers, which were all located in water utilities across the United States, Israel, UK, and Ireland. All these devices were publicly accessible through the internet, still using their factory-default passwords.

The cyber criminals took advantage of this successful campaign. They released the IOCONTROL malware kit in 2024-2025, which allowed them to develop a consistent strategy of attacking operational technology and IoT devices. The target base was increased. Rockwell Automation and Allen-Bradley products were added to the list in the beginning of this year. Schneider Electric and Siemens products were targeted on July 22, right before the attacks against utilities in Minnesota.

It is fairly simple to conduct such cyberattacks against small utilities. The main reason for this lies in the fact that most of these utilities operate on a shoestring budget and lack any specialists in OT cybersecurity. Remote access applications such as TeamViewer or AnyDesk are being used to provide remote support but are then completely forgotten.

Nobody Has Named A Culprit Yet

Officials have been careful with attribution so far. Minnesota IT Services confirmed the coordinated nature of the attack without naming a group. The Minnesota CISO, John Israel, called it a problem requiring “a coordinated, whole-of-government response.” He said the FBI, CISA, the EPA, and several state agencies are now involved.

The CyberAv3ngers link rests on pattern-matching, not a confession. Operational style, target selection, and timing all point the same direction. The attack landed just days after CISA’s July 22 advisory on Iran-linked PLC targeting. None of that proves it outright. It’s simply the most consistent explanation available right now.

What stands out isn’t the sophistication. It’s the opposite. Default passwords and internet-facing controllers, not zero-days, keep opening these doors. Officials say drinking water safety was never at risk this time. The margin for that to stay true keeps looking thinner with each repeat.

Conclusion: When Exposed OT Reaches the Physical Process

The Minnesota water attacks show how quickly a weakness at the IT and OT boundary can become an operational event.

Sophistication is not required when basic exposure is widespread.

More than 30 community water systems were targeted during the same two-day period. Braham temporarily lost its computerized operating controls, while other utilities relied on backup procedures and manual operations to keep essential services running.

Drinking water safety was not reported to be at risk.

The margin for keeping it that way became smaller.

Attribution remains unconfirmed. CyberAv3ngers is the leading suspicion because the timing, target selection, and operational pattern resemble previous Iran-linked activity against exposed industrial equipment. That connection should be treated as a strong investigative lead, not a proven conclusion. The exact Minnesota access path has also not been publicly disclosed.

Why This Threat Matters

The campaign shows that attackers do not always need a zero-day or a complex intrusion chain to disrupt critical infrastructure.

  • Internet-facing industrial systems can create direct paths into operational environments.
  • Default, shared, or weak credentials can reduce authentication to a procedural obstacle.
  • Forgotten remote-support tools can leave access paths active long after their original purpose has ended.
  • Cellular-connected equipment can create remote paths outside expected enterprise network controls.
  • Small utilities often operate with limited OT security staffing and aging infrastructure.
  • Legacy equipment may lack modern authentication, centralized monitoring, and detailed logging.
  • A compromised control environment can affect wells, pumps, treatment processes, towers, telemetry, and operator visibility.
  • Manual operations may preserve service, but they are a resilience measure, not a substitute for security architecture.

The warning is not that every exposed controller will produce a public safety event. It is that weak configuration, unnecessary internet reachability, and insufficient segmentation can give an unauthorized actor influence over a physical process.

Where Xcitium Changes the Outcome

This attack class must be addressed first at the exposed IT and OT boundary, then across the managed systems that administer, support, or communicate with the operational environment.

Xcitium Vulnerability Assessment helps organizations identify internet-facing services, outdated supporting systems, exposed remote-access paths, and configuration weaknesses within the supported assessment scope.

Visibility must lead directly to remediation.

Industrial controllers should not be directly reachable from the public internet. Default and shared credentials must be replaced. Remote access should be restricted, monitored, and disabled when no longer required. IT and OT systems should communicate only through explicitly approved and secured paths.

Device-specific OT security remains essential. Endpoint controls do not replace secure PLC configuration, firmware maintenance, network segmentation, vendor-specific hardening, or tested recovery procedures.

On engineering workstations, HMIs, jump servers, operator endpoints, maintenance laptops, and remote-support systems, Xcitium Advanced EDR, powered by Xcitium’s patented Zero-Dwell platform, applies Execution Governance.

Unknown code does not receive unrestricted execution rights before trust exists.

Code can run without being able to cause damage.

Unknown scripts, tools, services, and payloads are governed before they can alter real system resources on the managed endpoint. Security teams also gain evidence of how unknown execution was restricted and which policies were enforced.

Detection asks, “Did we recognize this activity as malicious?”

Execution Governance asks, “Should unknown execution be allowed to alter the managed systems that support the physical process?”

That is the architectural difference.

Govern the Exposure. Control the Execution.

The Minnesota incidents show how weaknesses defenders have understood for years can still disrupt critical infrastructure.

Remove industrial systems from direct internet exposure.

Replace default, shared, and reused credentials.

Eliminate obsolete or unauthorized remote-access tools.

Require strong authentication wherever the equipment supports it.

Segment operational networks from business systems.

Validate controller configurations and project files against known-good states.

Maintain tested manual operations and recovery procedures.

Govern unknown execution across every managed system that can administer, support, or reach the OT environment.

Like what you see? Share with a friend.

Move Away From Detection With Patented Threat Prevention Built For Today's Challenges.

No one can stop zero-day malware from entering your network, but Xcitium can prevent if from causing any damage. Zero infection. Zero damage.

Book a Demo