Minnesota Reports Coordinated Cyberattack on 30+ Water Utilities
TL;DR
- More than 30 Minnesota community water utilities were disrupted on July 26-27 in what state officials called a coordinated cyberattack on operational technology.
- Tenable researchers suspect Iran-linked CyberAv3ngers, coming four days after CISA updated its advisory on Iranian actors targeting critical-infrastructure PLCs.
- Four cities have publicly acknowledged involvement: Braham, Plymouth, South St. Paul, and Maple Plain, with no reported disruption to drinking water service.
More than 30 community water utilities across Minnesota were hit over July 26 and 27 in what state officials are calling a coordinated cyberattack on operational technology, according to Help Net Security. Four cities have publicly acknowledged involvement so far: Braham, Plymouth, South St. Paul, and Maple Plain, with Maple Plain stating there has been "no disruption to water or wastewater service."
The attribution the security industry is circling, without formal confirmation from state or federal officials, is CyberAv3ngers, the Iran-linked group The Register described as a "faux hacktivist outfit." The timing helps that case: CISA updated its advisory on Iran-linked actors targeting programmable logic controllers on July 22, four days before the Minnesota disruptions began. Tenable's writeup points to internet-exposed PLCs from vendors including Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens, and notes that small utilities often lean on consumer remote-access tools like TeamViewer and AnyDesk without dedicated OT security staff.
The exposure pattern here is boringly common, which is why it matters well beyond one state. Small municipal water systems across the country run the same kinds of PLCs, plug them into the internet, and expose the same remote-access surface, usually because their budgets do not stretch to a real OT security program. If the Iran attribution firms up, the story becomes less about Minnesota and more about how long and how accessible that target list still is.
The honest caveats are worth flagging. No US agency has publicly named a perpetrator, and the specific initial access vector for the Minnesota incidents is not in the reporting. Neither is a clear answer to why 30+ utilities lit up at once, whether that reflects a shared vendor, a shared exposure, or parallel intrusion campaigns hitting whatever answered on the internet. MNIT Assistant Commissioner and state CISO John Israel said Minnesota's "response worked as intended," and no city has asked residents to change water use, but the operational-detail picture is still thin.
The upside, such as it is, sits with state cyber coordination bodies and OT security vendors. MNIT gets to point at a case where a statewide shared-services model absorbed an incident that could have flattened individual towns, and CISA's CI Fortify guidance on isolating essential OT from broader networks gets a fresh real-world argument. For the many US states without a MNIT-style backbone, this is a reasonable week to notice.
Originally reported by helpnetsecurity.com
Read the original article →Original headline: Coordinated Cyberattack Hits 30+ Minnesota Water Utilities; Tenable Ties TTPs to Iran-Linked CyberAv3ngers