Pular para o conteúdo principal
Close
Security

Minnesota: 30+ Water Systems, Compromised PLCs and the 5-Year Pattern That Became a Crisis

Gabriel Ferraresi· CEO | Tech86August 2, 20264 min
securityotplcicscyberav3ngersirgcminnesotawaterrockwellcisa

Minnesota, July 26, 2026. Sunday evening. Operators of more than 30 water systems in the state lost access to their own PLCs. Passwords changed. IP addresses changed. Whoever controlled the infrastructure was no longer who should. We have been tracking this pattern for five years, and Minnesota is the point where the pattern becomes a crisis.

The scale: 30+ systems, 7 states, operator lockout

Braham, a town of 1,700 people, had its water plant offline for hours. Plymouth disconnected PLCs in 2 water towers and 14 sewage stations. Maple Plain declared a state of emergency. The attack spread to 7 states. On July 31, CISA and the FBI issued an official alert.

According to an internal WaterISAC memo obtained by WIRED, the attack points to CyberAv3ngers, a group affiliated with the Iranian IRGC. Attribution to Iran has not yet been officially confirmed. The techniques used match the pattern documented by CISA since 2023.

The vulnerability: Rockwell Allen-Bradley and the patch that doesn't exist

The attackers exploited an authentication bypass vulnerability in Rockwell Automation Allen-Bradley controllers. CVSS 9.8. Documented in CISA Advisory AA26-097A. According to Rockwell, no patch is planned for these models. The fix would require redesigning the entire authentication system.

Worse: the attackers used the manufacturers' own legitimate engineering software. Rockwell Studio 5000. Schneider EcoStruxure. Siemens TIA Portal. Connections accepted by the PLCs because they came from trusted software. After entering, they modified Add-On Instructions. The ladder logic remained apparently normal. But the malicious AOIs disabled the safety shutdown logic and the alarms. The systems operated in unsafe conditions. The operators didn't know.

The 5-year pattern: from Oldsmar to Minnesota

This is the fifth year of a clear pattern of attacks on water infrastructure in the US.

2021 — Oldsmar, Florida. Caustic soda setpoint changed from 100 to 11,100 ppm. Lethal level. An operator reverted it in time.

2023 — Aliquippa, Pennsylvania. CyberAv3ngers compromised Unitronics PLCs with default passwords. Same group, different vector — default credentials instead of an authentication bypass.

2024 — Muleshoe, Texas. Sandworm, a Russian GRU group, manipulated the HMI to cause a tank overflow for 30 minutes.

2026 — Minnesota. 30+ systems. 7 states. Operator lockout. For the first time in this pattern, sustained operational impact across multiple systems. This was not a warning. It was an operation.

The difference between 2021 and 2026 is the difference between an incident and a campaign. Oldsmar was an operator who watched the cursor move. Minnesota was 30+ systems where operators were locked out.

The structural vulnerability: 152,000 systems, 91% small, 70%+ in violation

The water sector has 152,000 public systems in the US. According to the EPA, 91% are small systems serving 10,000 people or less, and over 70% are in violation of basic requirements. Default passwords. Shared logins. Ex-employee access not revoked.

2024 sector surveys show: 71% without ICS/OT network monitoring. 39% don't know if they can operate manually during an attack. The electric sector has NERC-CIP, with mandatory standards and fines. The water sector has voluntary guidance.

The vulnerability here is structural. It is not a bug that gets fixed with a patch. It is an architecture that was never designed to resist.

What Tech86 does differently

When Tech86 audits OT infrastructure for clients in critical sectors, the first principle is simple: PLC doesn't touch the internet. Remote access only via VPN with MFA. IT/OT segmentation mandatory. Complete OT asset inventory.

Minnesota proves what we already know. The patch that doesn't exist is the architecture that wasn't designed to resist.

Conclusion

We repeat: you cannot patch an architecture that was never designed to resist. Minnesota doesn't exploit a code bug — it exploits a structural flaw that has persisted for five years. Default passwords on Unitronics PLCs in 2023. Authentication bypass on Rockwell Allen-Bradley in 2026. Legitimate engineering software used as the entry vector. Add-On Instructions modified to disable safety shutdowns. Operators locked out of their own systems.

The water sector has 152,000 public systems in the US. 91% are small systems. Over 70% are in violation of basic requirements according to the EPA. 71% have no ICS/OT network monitoring. 39% don't know if they can operate manually during an attack. The electric sector has mandatory NERC-CIP. The water sector has voluntary guidance. The difference between the two sectors is not technical — it is regulatory.

At Tech86, we help companies audit and fix exactly this kind of structural flaw in OT infrastructure — before the patch that doesn't exist becomes the crisis we already know is coming.

blog.cta_consulting_title

blog.cta_consulting_subtitle

OT Security and Critical Infrastructure Protection

Frequently Asked Questions

On July 26, 2026, a Sunday evening, operators of more than 30 water systems in the state of Minnesota lost access to their own PLCs. Passwords changed. IP addresses changed. Braham, a town of 1,700 people, had its water plant offline for hours. Plymouth disconnected PLCs in 2 water towers and 14 sewage stations. Maple Plain declared a state of emergency. The attack spread to 7 states. On July 31, CISA and the FBI issued an official alert.

According to an internal WaterISAC memo obtained by WIRED, the attack points to CyberAv3ngers, a group affiliated with the Iranian IRGC. Attribution to Iran has not yet been officially confirmed. The techniques used match the pattern documented by CISA since 2023. CyberAv3ngers had previously compromised Unitronics PLCs in Aliquippa, Pennsylvania, in 2023, using default passwords.

The attackers exploited an authentication bypass vulnerability in Rockwell Automation Allen-Bradley controllers. CVSS 9.8. Documented in CISA Advisory AA26-097A. According to Rockwell, no patch is planned for these models. The fix would require redesigning the entire authentication system. It is not a code bug — it is an architectural flaw that cannot be fixed with a hotfix.

2021: Oldsmar, Florida. Caustic soda setpoint changed from 100 to 11,100 ppm — a lethal level. An operator reverted it in time. 2023: Aliquippa, Pennsylvania. CyberAv3ngers compromised Unitronics PLCs with default passwords. 2024: Muleshoe, Texas. Sandworm, a Russian GRU group, manipulated the HMI to cause a tank overflow for 30 minutes. 2026: Minnesota. 30+ systems, 7 states, operator lockout. For the first time in this pattern, sustained operational impact across multiple systems.

The electric sector has NERC-CIP, with mandatory standards and fines. The water sector has voluntary guidance. According to the EPA, the water sector has 152,000 public systems in the US, with 91% being small systems serving 10,000 people or less, and over 70% are in violation of basic requirements — default passwords, shared logins, and ex-employee access not revoked. The vulnerability here is structural.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.