Posted in

Iran-Linked CyberAv3ngers Targets More Than 30 Minnesota Water Systems

More than 30 municipal water systems across Minnesota were targeted in a coordinated cyberattack that security officials believe shares characteristics with previous operations attributed to the CyberAv3ngers water system attack campaign.

The incident, which began on July 26, has been described by state officials as one of the largest cyberattacks against local water infrastructure in Minnesota’s history. While drinking water supplies remain safe and no municipalities have instructed residents to alter water consumption habits, the attack disrupted operational technology systems and forced some facilities to transition into manual operations.

The campaign emerged just days after federal authorities expanded warnings regarding Iran-linked attempts to compromise internet-connected industrial control systems throughout U.S. critical infrastructure.

Key Details

Minnesota IT Services (MNIT), the state’s central technology agency, activated its cyber incident response capabilities after identifying coordinated attacks affecting municipal water infrastructure.

State officials reported that cybersecurity teams immediately began:

  • Sharing threat intelligence
  • Coordinating incident response
  • Assisting utility operators
  • Supporting investigation and remediation efforts
  • Collaborating with federal authorities

MNIT stated it is working closely with:

  • The FBI
  • Minnesota Department of Public Safety
  • State cybersecurity teams
  • Federal security partners

Several affected municipalities have already been publicly identified, including:

  • Plymouth
  • South St. Paul
  • Maple Plain
  • Braham

According to public reports, some facilities experienced temporary operational outages, communication disruptions, and failures affecting automated control systems.

One municipality reported that attackers successfully interfered with operational controls, temporarily forcing a municipal well and water treatment facility offline. Utility personnel restored operations after switching to manual control procedures.

Officials have emphasized that no evidence currently suggests contamination of drinking water supplies.

Technical Analysis

Attackers Targeted Industrial Control Systems

Early analysis suggests the attackers focused on industrial control systems (ICS) and operational technology (OT) environments rather than traditional IT infrastructure.

Researchers and investigators observed similarities with previous CyberAv3ngers campaigns that targeted:

  • Programmable Logic Controllers (PLCs)
  • Water treatment systems
  • Human Machine Interfaces (HMIs)
  • SCADA environments
  • Utility operational networks

PLCs serve as the automation backbone of water treatment facilities, controlling pumps, valves, water distribution processes, and numerous treatment operations.

By gaining access to these environments, attackers can potentially:

  • Disable equipment
  • Interrupt treatment operations
  • Manipulate control processes
  • Cause operational outages
  • Force facilities into manual operations

Minnesota officials indicated that the methods used during the attacks align closely with previous incidents involving internet-connected PLC devices.

Why PLCs Remain Attractive Targets

The attack highlights a growing concern within critical infrastructure security.

Many industrial environments continue operating legacy operational technology systems that were originally designed for reliability and availability rather than cybersecurity.

Common weaknesses include:

  • Internet-exposed devices
  • Weak authentication controls
  • Default credentials
  • Inadequate network segmentation
  • Remote management services
  • Insufficient monitoring visibility

Federal agencies recently warned that attackers are increasingly exploiting operational weaknesses rather than software vulnerabilities.

In many cases, threat actors do not require sophisticated zero-day exploits. Misconfigurations, unsecured remote access, and poor segmentation often provide sufficient access to critical environments.

Impact and Risks

Although water safety has not been affected, the operational impact demonstrates how cyberattacks can directly influence public services.

Operational Disruption

Several affected municipalities reportedly lost automated functionality and were forced to rely on manual procedures while systems were restored.

When operational technology becomes unavailable, utilities often require additional staffing and emergency procedures to maintain service continuity.

Service Interruption Risk

Attackers demonstrated the ability to interfere with critical control functions, including systems responsible for directing water flow and treatment processes.

Even short disruptions can create significant operational challenges for municipal utilities.

Escalating Critical Infrastructure Threat

The attack also reflects a broader trend: nation-state-linked groups increasingly targeting operational technology environments rather than traditional enterprise networks.

Utilities, energy providers, transportation systems, and government services continue to face heightened risk due to the convergence of IT and OT systems.

Public Confidence Concerns

Even when no contamination occurs, cyberattacks against water systems can undermine public confidence and require significant resources to investigate and remediate.

CyberAv3ngers and Previous Water Infrastructure Attacks

CyberAv3ngers has emerged as one of the most visible groups targeting operational technology systems tied to water and wastewater infrastructure.

The group, which U.S. authorities have previously linked to Iranian interests, gained international attention in 2023 after targeting Unitronics PLC devices deployed in water facilities.

One of the most widely publicized incidents involved a Pennsylvania municipal water authority where internet-exposed Unitronics PLC equipment was compromised through default credentials.

Attackers defaced the system and publicly claimed responsibility for the intrusion.

The U.S. government’s Rewards for Justice program later offered rewards of up to $10 million for information related to individuals associated with CyberAv3ngers activities.

While Minnesota officials have not formally attributed the latest incident to the group, investigators stated the attack demonstrates characteristics consistent with prior CyberAv3ngers operations targeting industrial environments.

Industry Context

The attack occurred shortly after federal agencies expanded an advisory regarding Iran-linked efforts to target industrial control systems across critical infrastructure sectors.

Recent federal guidance warns that threat actors are actively targeting internet-connected operational technology devices in:

  • Water and wastewater systems
  • Energy infrastructure
  • Government facilities
  • Critical manufacturing
  • Municipal services

Researchers note that attackers have increasingly focused on operational impact rather than data theft.

In these scenarios, the objective may include:

  • Service disruption
  • Public messaging
  • Infrastructure influence
  • Operational degradation
  • Psychological impact

The advisory also indicates that attackers have expanded targeting beyond a single PLC vendor to include equipment from multiple industrial automation manufacturers.

This demonstrates a broader strategic focus on industrial operations rather than isolated products.

Expert Recommendations

Organizations operating critical infrastructure should prioritize operational technology security improvements immediately.

Disconnect Unnecessary Internet Exposure

PLCs and industrial control devices should not be directly accessible from the public internet whenever possible.

Strengthen Authentication

Utilities should:

  • Eliminate default credentials
  • Deploy multifactor authentication
  • Restrict remote access
  • Review privileged accounts

Improve Network Segmentation

Operational technology environments should remain isolated from internet-facing and corporate IT systems using strict segmentation controls.

Monitor PLC Activity

Security teams should monitor for:

  • Unauthorized configuration changes
  • Unexpected PLC communications
  • HMI modifications
  • Suspicious remote access attempts
  • Changes to SCADA environments

Develop Manual Contingency Procedures

The Minnesota incident demonstrates the importance of maintaining tested manual operating procedures that can sustain critical services during cyber incidents.

Conduct OT Security Assessments

Organizations should regularly assess exposed industrial assets and identify misconfigurations, insecure remote access mechanisms, and unsupported devices.

Conclusion

The coordinated attack against more than 30 Minnesota water systems underscores the growing threat facing operational technology environments and critical infrastructure operators.

While utility personnel successfully maintained safe drinking water and restored affected services, the incident demonstrates how attackers can disrupt public infrastructure by targeting industrial control systems and PLC equipment rather than traditional IT assets.

As Iran-linked threat activity continues to focus on operational technology, utilities and critical infrastructure operators face increasing pressure to strengthen asset visibility, eliminate internet-exposed control systems, and improve resilience against attacks designed to disrupt essential public services.

FAQ SECTION

What is CyberAv3ngers?

CyberAv3ngers is a hacktivist group that U.S. authorities have previously linked to Iranian interests and past attacks targeting operational technology and water infrastructure systems.

How many Minnesota water systems were affected?

Officials reported that more than 30 municipal water systems were targeted during the coordinated cyberattack.

Was drinking water contaminated?

State officials reported that drinking water remains safe and no municipalities requested residents change their water usage habits.

What systems were targeted?

The attackers reportedly targeted industrial control systems, including PLC-based infrastructure responsible for automating water treatment and distribution operations.

Why are PLCs frequently targeted?

PLCs control critical industrial processes and are often deployed in environments where legacy technology, internet exposure, and weak authentication controls create attractive attack opportunities.

Leave a Reply

Your email address will not be published. Required fields are marked *