A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?

A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness.

While the affected communities reported that drinking water remained safe and disruptions were limited, security researchers say the incident marks another escalation in a months-long campaign targeting US water infrastructure amid heightened geopolitical tensions with Iran.

“This is a first-of-its-kind distributed attack on water utilities,” Markus Mueller, field CISO at Nozomi Networks, tells CSO. “Based on the publicly available information, it was clearly aimed at disruption rather than financial gain.”

What happened?

Minnesota IT Services disclosed that the water systems experienced coordinated cyber activity over a two-day period from July 26 to July 27. The city of Braham, with roughly 1,700 people in Isanti County, suffered the most visible operational impact after shutting down portions of its water system for roughly two hours while operators regained control of affected systems.

The city of Plymouth disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the intrusion and prevent the attackers from regaining access while the equipment was reconfigured. The city of South St. Paul said some automated controls were affected, and the city of Maple Plain declared a local state of emergency to expand its response.

The incident comes just days after CISA, the FBI, NSA and EPA expanded an advisory warning that Iranian-affiliated cyber actors continue targeting programmable logic controllers (PLCs) used throughout US critical infrastructure, including water systems.

“CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities,” CISA Acting Director Nick Andersen said in a statement provided to CSO. “We urge critical infrastructure owners and operators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”

“We also encourage all organizations to review the latest guidance on CISA.gov and to report suspected incidents or anomalous activity to us for further support,” Andersen said.

More than another utility hack

Experts agree that the attacks stand apart from previous incidents because they were coordinated across numerous utilities rather than focused on a single victim.

Nozomi’s Mueller believes that this coordination strongly suggests investigators will eventually identify some technical thread connecting the affected communities.

“To be this sector-specific,” he says, “my assumption would be that there is something that ties these together beyond simply being Minnesota water utilities.” He thinks investigators may ultimately discover a shared systems integrator, communications architecture or other common infrastructure that made the utilities collectively vulnerable.

Ron Fabela, an industrial control systems researcher who closely tracks attacks against operational technology, reached a similar conclusion after examining publicly available information.

“I searched Minnesota’s public IP space and didn’t find obvious exposed water infrastructure,” he says. “Many of these utilities use cellular communications, which makes them much harder to identify than internet-facing industrial systems.”

That distinction could explain why dozens of geographically clustered utilities were affected while neighboring infrastructure apparently was not.

The Rockwell connection

An additional development could prove significant as investigators continue examining the attacks.

According to a source familiar with the federal investigation, authorities are examining whether vulnerable Rockwell Automation MicroLogix 1400 PLCs served as a common enabling factor in the campaign.

Fabela ran a targeted Shodan search on Plymouth’s public IP space and found the city using at least two Rockwell Automation MicroLogix 1400 controllers.

The possibility aligns with both recent federal warnings and a July 30 Rockwell Automation security advisory addressing the MicroLogix 1400 family of controllers. Earlier federal guidance identified Rockwell Automation/Allen-Bradley PLCs among the industrial controllers being actively targeted by Iranian-affiliated threat actors before expanding the warning to additional PLC manufacturers.

On July 30, amid the investigation into the Minnesota attacks, CISA issued fresh guidance urging water and wastewater utilities to remove publicly exposed PLCs and other operational technology from the internet as quickly as possible.

Scott Caveza, senior staff research engineer at Tenable, the first security organization to issue a report on the incident, cautioned that the timing alone does not establish causation. “The timing certainly makes it suspicious,” Caveza says. “Rockwell Automation devices have routinely been targeted by these groups before, so it’s definitely plausible.”

If exposed PLCs did provide attackers with access, the implications extend beyond simple monitoring.

“Depending on configuration,” Caveza explains, “an attacker could gain monitoring capability, manipulate what operators see, or in some circumstances modify operational settings.” Fortunately, manual safety controls built into most water facilities make catastrophic consequences considerably more difficult.

The relatively quick recovery in Braham appears consistent with that assessment. Operators restored systems within roughly two hours, and no boil-water orders were issued.

CISA’s July 30 alert did not identify the equipment involved in the Minnesota incidents or address whether Rockwell controllers played a role. However, the agency’s renewed emphasis on removing internet-exposed PLCs closely mirrors both Rockwell’s own mitigation guidance and one of the questions investigators are now examining: whether exposed Rockwell controllers provided a common avenue into multiple utilities.

Attribution remains the biggest unanswered question

Federal agencies have stopped short of publicly identifying those responsible, although most experts believe Iranian-affiliated actors remain the leading suspects.

Cynthia Kaiser, former FBI cyber deputy director and now vice president of strategy and policy at Halcyon, says the attacks closely followed recent federal warnings describing an active Iranian campaign targeting operational technology.

“You have the FBI and other US government agencies putting out an urgent warning about Iran targeting operational controls,” she tells CSO. “Then this larger coordinated campaign occurs. Geopolitically, Iran has the strongest motivation to conduct this kind of chaos-driven cyberattack.”

Still, Kaiser acknowledges investigators lack a definitive technical smoking gun. Instead, she argues Iran increasingly benefits from what she calls “strategic ambiguity.”

“They thrive in people suspecting it might be them but not knowing for sure,” she says. “That ambiguity complicates response and buys them time operationally.”

That explanation may help resolve one of the attack’s biggest mysteries.

Unlike previous campaigns by CyberAv3ngers and other Iranian-aligned hacktivist groups, no convincing public victory videos or detailed Telegram posts immediately appeared following the Minnesota attacks. In an unusual delay, an Iranian state publication attributed the attack to threat group Handala only on July 29, days after the incident.

Handala itself has been silent, even though it claimed credit on X on July 26 for a cyberattack targeting the network infrastructure of SupraNet Communications, a major internet service provider based in Madison, Wisc.

That Handala claimed credit for one attack days earlier but has said nothing about Minnesota deepens the mystery of its silence here.

Fabela noted that absence stood out. “Neither Handala nor CyberAv3ngers has publicly claimed responsibility the way we’ve seen in previous campaigns,” he says. “Normally they post screenshots or proof. We haven’t seen that yet.”

Mueller also found the silence unusual.

“At the peak we were tracking more than a hundred Iranian splinter groups,” he says. “Then everything became very quiet. Even with renewed kinetic activity, we haven’t seen the same level of public boasting.”

Lessons for water utilities

Whatever the final attribution, experts say the attacks reinforce an uncomfortable reality: Attackers often do not need sophisticated zero-day exploits to disrupt operational technology.

Rather, they succeed because industrial control devices remain directly reachable from the internet, protected by weak credentials, or deployed without the network segmentation long recommended by federal agencies.

Fabela summed up the irony this way: “Tying all these pieces together, it seems the threat actors are implementing the CISA-recommended actions for PLCs — without operator permission, of course: set a password, remove them from the internet. Joking, not joking.”

“The guidance is pretty typical,” Caveza says. “Don’t connect these devices directly to the internet. These are things we hope would already be common knowledge—but unfortunately things happen.”