More than 30 community water and wastewater systems across Minnesota were disrupted in a coordinated cyberattack on July 26–27, 2026, targeting operational technology systems at small and rural utilities. Tenable researchers suspect Iran-linked CyberAv3ngers, also tracked as IRGC-CEC, based on operational patterns consistent with the group’s history of raids against programmable logic controllers and small water utilities. Minnesota’s state CISO confirmed a coordinated whole-of-government response, and CISA, the FBI, and the Minnesota Department of Health are investigating. No water quality disruptions have been reported.
What Happened at the Affected Minnesota Utilities
The attack struck multiple communities in a coordinated sequence on July 26–27. Braham, one of the affected communities, reported limited water reserves and issued a lawn-watering ban. Maple Plain declared a state of emergency. Plymouth and South St. Paul were among the other communities affected. Minnesota IT Services confirmed the state Department of Health is working directly with the affected facilities.
At no point were residents asked to modify their drinking water consumption, and officials have not indicated that water quality was compromised. The disruptions appear to have affected operational systems — the controls that manage water treatment and distribution processes — rather than the water itself.
Why Small and Rural Water Utilities Are Repeatedly Targeted
Tenable noted a characteristic of the affected facilities that runs throughout prior CyberAv3ngers targeting patterns: many small and rural utilities lack dedicated cybersecurity resources. Some operators manage OT systems through remote-access software such as TeamViewer and AnyDesk. In some cases, PLCs are exposed directly to the internet without protective controls. These conditions — remote access software on OT networks, internet-facing control systems, limited security staffing — create a target profile that requires minimal sophistication to exploit.
The pattern is not new. Security practitioners have documented for years that water and wastewater utilities serving small communities operate under resource constraints that prevent them from meeting the baseline security controls available to larger municipal systems. The recurring targeting of small utilities by CyberAv3ngers suggests the group has identified this population as a reliable high-volume target where operational disruption is achievable at scale.
CyberAv3ngers and the IRGC-CEC Attribution
CyberAv3ngers is a threat group attributed to the Iranian Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC). The group has been active since at least 2020 and has previously targeted US critical infrastructure through attacks on Rockwell Automation/Allen-Bradley PLCs and Unitronics Vision Series PLCs. The group developed the IOCONTROL malware kit, purpose-built for attacks on OT and IoT devices.
CISA’s July 22 Advisory and the Four-Day Window Before the Attacks
The timing of the Minnesota attacks is significant in context: CISA updated an advisory specifically addressing Iran-linked attackers targeting programmable logic controllers on July 22 — four days before the Minnesota attacks began on July 26. The advisory’s publication before the incidents does not indicate foreknowledge, but it establishes that the threat from this actor class against water utility PLCs was already sufficiently documented to warrant a federal advisory update in the days before the coordinated disruption materialized.
What the Coordinated Attack Reveals About Water Sector OT Exposure
The simultaneous disruption of more than 30 separate utilities is not consistent with opportunistic targeting. A coordinated attack at that scale — across multiple communities in a compressed timeframe — requires advance reconnaissance and either simultaneous action against multiple targets or a common vulnerability in shared infrastructure or software used across the affected utilities.
Water utilities often use common off-the-shelf OT software and PLCs from a limited set of vendors. A single exploitable condition in widely deployed equipment can scale across many facilities without requiring individual reconnaissance of each target. The breadth of the July 26–27 disruption suggests the attackers either identified a common exploitable condition across the target population, coordinated simultaneous action against individually identified targets, or both.
Minnesota CISO John Israel confirmed the state’s whole-of-government response structure, with coordination between state agencies, CISA, the FBI, and local entities. Affected utilities are working to restore operations and strengthen defenses. The absence of reported water quality impacts suggests the attack’s effect was on operational control continuity rather than treatment processes, but investigations are ongoing. For small utilities throughout the US operating OT systems accessible via remote-access software or internet-facing PLCs, the Minnesota attacks represent the most concrete recent illustration of why CISA’s guidance on isolating OT networks from public internet access remains relevant.
