A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don’t appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota’s IT Services (MNIT) unit.
Attacks Follow Recent US Government Warning
The attacks come days after the US Cybersecurity and Infrastructure Security Agency (CISA) updated a warning from earlier this year about Iran-affiliated threat groups targeting programmable logic controllers (PLCs) and other Internet-connected OT devices at critical infrastructure organizations across the US, including water systems. The advisory specifically identified PLCs from Rockwell Automation/Allen Bradley, Schneider Electric, and Siemens as being of interest to the attackers, while warning that any Internet-exposed PLC could be a potential target.
MNIT is investigating the July 26 and July 27 attacks in collaboration with the state’s Department of Public Safety, Minnesota Department of Health, CISA, FBI, the US Environmental Protection Agency, and other stakeholders. It hasn’t released any specifics on the attacks yet, including what kind of automated systems the attackers might have targeted, or how. CISA itself has described the attackers as manipulating PLC project files and altering data displayed on human machine interface (HMI) and SCADA systems to disrupt target environments.
The city of Braham, Minn., about 50 miles north of Minneapolis, urged residents on July 27 to minimize water use because its water plant was “offline for an unknown reason.” Braham Mayor Nate George updated the statement a day later to report the issue had been resolved without any disruption to water services. The cyberattack forced the city of Maple Plain, Minn., to declare a local state of emergency so it could coordinate resources and expedite emergency measures to respond to the attack. “While the incident affected certain automated control functions, established contingency procedures were immediately implemented,” to ensure water and wastewater operations remained uninterrupted, the city said in a statement.
Officials in South St. Paul, Minn., used similar language to describe a cyber incident involving automated controls tied to the city’s water utility system, and said existing contingency measures ensured normal water and wastewater operations. The city of Plymouth, Minn., reported disruptions to communications at two of the city’s water towers and multiple lift stations within the city but said water quality and water levels remained unaffected.
All Signs Point to Iran
Minnesota officials have not attributed the attacks to any actor, but some researchers believe they bear the fingerprints of Iranian threat groups.
Scott Caveza, senior staff research engineer at Tenable, says the operational tradecraft heavily suggests involvement of Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) and CyberAv3ngers. “The tactics mirror the group’s known capabilities: exploiting Internet-facing PLCs and native vendor engineering software to bypass authentication and extract project files,” Caveza says. “The timing of attack, which occurred days after an update to a CISA advisory warning of active Iranian targeting of US water sector PLCs, is also indicative of a possible Iranian connection.”
Unlike financially motivated actors whose attacks might spillover into OT environments, Iranian state-directed groups like CyberAv3ngers, specifically target the OT environment, Caveza notes. “They invest in understanding PLC protocols, use the same vendor engineering tools as legitimate operators, and build purpose-specific capabilities.” The likely objective is geopolitical leverage through demonstrated access to critical infrastructure, not monetization, he adds.
The fact that the attacks hit more than 30 water systems almost simultaneously is noteworthy as well. Sean Tufts, field chief technology officer (CTO) at Claroty, says that while attackers are constantly scanning for the same exposed operational technology across many organizations, the level of geographic concentration in the recent attacks suggests there may be more connecting these systems than simple coincidence.
MicroLogix controllers, he says, could be one common denominator. “They are widely used across critical infrastructure, so the attackers most likely searched broadly for Internet-exposed devices and found a cluster in Minnesota,” Tufts notes. “But the scale also raises questions about whether the affected utilities share a common IT backbone, integrator, remote-access pathway or another ecosystem-level dependency.”
The Susceptibility of the Water Industry
The water industry, Tufts says, is susceptible to opportunistic attacks because of its relative lack of cybersecurity preparedness. Compared to their nearest vertical peer, electric utilities, which are required to implement nearly 50 federally mandated preventive controls, America’s Water Infrastructure Act (AWIA) only requires its members to conduct a risk assessment. “In water, cyber preparedness is uneven, and that is the problem,” he notes. There are well-run utilities that act on the risk assessment, but many community systems have only a handful of employees and no dedicated cyber team. “They are being asked to defend industrial technology with municipal budgets while keeping water running around the clock.”
Another exacerbating factor, according to experts, is exposing critical OT to the Internet. Denis Calderone, CTO of Suzu Labs, points to examples like PLCs connected through cellular modems, enabling remote access via TeamViewer or AnyDesk and HMI Web interfaces exposed without any authentication. “The devices are on the Internet, the operators either aren’t considering the risks, or just don’t realize it because the connection goes through a cellular gateway that was installed by an integrator years ago and never showed up on any network diagram or security assessment,” Calderone says.
Another factor to consider is that OT is often treated as someone else’s problem. “A town of 1,800 people doesn’t have a cybersecurity team,” Calderone says. “They have a public works crew that keeps the water running. The gap between what these communities need for security and what they have the resources to do is enormous.”
The US has more than 148,000 public drinking-water systems and when publicly owned wastewater treatment systems are included, that number goes up to between 165,000 and 170,000, points out Patrick Gillespie, OT practice director at GuidePoint Security. Many of these organizations are small, rural, or municipally operated and have limited cybersecurity personnel, funding, procurement capacity, and access to specialized OT expertise. “While large investor-owned utilities may be able to fund preventative measures like security monitoring, incident-response retainers, and dedicated security teams, many small community systems cannot,” Gillespie says. “This is what makes the water sector a really attractive target for bad actors.”


