Minnesota, July 26, 2026. Sunday evening. Operators of more than 30 water systems in the state lost access to their own PLCs. Passwords changed. IP addresses changed. Whoever controlled the infrastructure was no longer who should. We have been tracking this pattern for five years, and Minnesota is the point where the pattern becomes a crisis.
The scale: 30+ systems, 7 states, operator lockout
Braham, a town of 1,700 people, had its water plant offline for hours. Plymouth disconnected PLCs in 2 water towers and 14 sewage stations. Maple Plain declared a state of emergency. The attack spread to 7 states. On July 31, CISA and the FBI issued an official alert.
According to an internal WaterISAC memo obtained by WIRED, the attack points to CyberAv3ngers, a group affiliated with the Iranian IRGC. Attribution to Iran has not yet been officially confirmed. The techniques used match the pattern documented by CISA since 2023.
The vulnerability: Rockwell Allen-Bradley and the patch that doesn't exist
The attackers exploited an authentication bypass vulnerability in Rockwell Automation Allen-Bradley controllers. CVSS 9.8. Documented in CISA Advisory AA26-097A. According to Rockwell, no patch is planned for these models. The fix would require redesigning the entire authentication system.
Worse: the attackers used the manufacturers' own legitimate engineering software. Rockwell Studio 5000. Schneider EcoStruxure. Siemens TIA Portal. Connections accepted by the PLCs because they came from trusted software. After entering, they modified Add-On Instructions. The ladder logic remained apparently normal. But the malicious AOIs disabled the safety shutdown logic and the alarms. The systems operated in unsafe conditions. The operators didn't know.
The 5-year pattern: from Oldsmar to Minnesota
This is the fifth year of a clear pattern of attacks on water infrastructure in the US.
2021 — Oldsmar, Florida. Caustic soda setpoint changed from 100 to 11,100 ppm. Lethal level. An operator reverted it in time.
2023 — Aliquippa, Pennsylvania. CyberAv3ngers compromised Unitronics PLCs with default passwords. Same group, different vector — default credentials instead of an authentication bypass.
2024 — Muleshoe, Texas. Sandworm, a Russian GRU group, manipulated the HMI to cause a tank overflow for 30 minutes.
2026 — Minnesota. 30+ systems. 7 states. Operator lockout. For the first time in this pattern, sustained operational impact across multiple systems. This was not a warning. It was an operation.
The difference between 2021 and 2026 is the difference between an incident and a campaign. Oldsmar was an operator who watched the cursor move. Minnesota was 30+ systems where operators were locked out.
The structural vulnerability: 152,000 systems, 91% small, 70%+ in violation
The water sector has 152,000 public systems in the US. According to the EPA, 91% are small systems serving 10,000 people or less, and over 70% are in violation of basic requirements. Default passwords. Shared logins. Ex-employee access not revoked.
2024 sector surveys show: 71% without ICS/OT network monitoring. 39% don't know if they can operate manually during an attack. The electric sector has NERC-CIP, with mandatory standards and fines. The water sector has voluntary guidance.
The vulnerability here is structural. It is not a bug that gets fixed with a patch. It is an architecture that was never designed to resist.
What Tech86 does differently
When Tech86 audits OT infrastructure for clients in critical sectors, the first principle is simple: PLC doesn't touch the internet. Remote access only via VPN with MFA. IT/OT segmentation mandatory. Complete OT asset inventory.
Minnesota proves what we already know. The patch that doesn't exist is the architecture that wasn't designed to resist.
Conclusion
We repeat: you cannot patch an architecture that was never designed to resist. Minnesota doesn't exploit a code bug — it exploits a structural flaw that has persisted for five years. Default passwords on Unitronics PLCs in 2023. Authentication bypass on Rockwell Allen-Bradley in 2026. Legitimate engineering software used as the entry vector. Add-On Instructions modified to disable safety shutdowns. Operators locked out of their own systems.
The water sector has 152,000 public systems in the US. 91% are small systems. Over 70% are in violation of basic requirements according to the EPA. 71% have no ICS/OT network monitoring. 39% don't know if they can operate manually during an attack. The electric sector has mandatory NERC-CIP. The water sector has voluntary guidance. The difference between the two sectors is not technical — it is regulatory.
At Tech86, we help companies audit and fix exactly this kind of structural flaw in OT infrastructure — before the patch that doesn't exist becomes the crisis we already know is coming.