Between 26 and 27 July 2026, roughly three dozen Minnesota community water systems lost control of their own plants within a forty-eight-hour window. In Braham, malware shut down the automated operating controls and the water tower could not be filled for more than an hour (Braham city administrator Kevin Stahl, via FOX 9). Plymouth and South St. Paul reverted to manual operation. Maple Plain's mayor declared a local emergency. Minnesota IT Services put the confirmed total at approximately 36 systems (MNIT CISO John Israel, 28 Jul 2026). It was, in the plainest terms, the first time a foreign cyber operation degraded the operation of dozens of American drinking-water utilities simultaneously.
Minnesota was where the campaign surfaced, not where it began or ended. Within days the same pattern appeared in Georgia — where the Clayton County Water Authority issued a precautionary boil-water advisory after a pump station failed around 01:00 on 27 July, dropping pressure for customers until crews restored it near 04:00 — and in Michigan, South Dakota, New Jersey and elsewhere. Reporting ultimately placed impacted utilities in at least twelve states (Cybersecurity Dive, Aug 2026), and US investigators assessed that more than 100 facilities had been targeted nationally (New York Times, 30 Jul 2026). The technical common denominator was mundane and damning: internet-facing programmable logic controllers, reachable from the public internet, many still carrying vendor default credentials.
The July events were the loud end of a quiet eighteen-month operation. Joint advisory AA26-097A — signed by FBI, CISA, NSA, EPA, DOE, US Cyber Command's Cyber National Mission Force and the Treasury on 7 April 2026 — documented Iranian-affiliated actors exploiting exposed PLCs across water, energy and government facilities, with hostile infrastructure traceable to January 2025. The advisory's 22 July 2026 update, published four days before the Minnesota attacks, did two things that matter analytically: it expanded the confirmed targeting scope beyond Rockwell Automation to Schneider Electric and Siemens controllers, and it added detection guidance for malicious modification of Add-On Instructions — reusable code modules inside Rockwell PLC programs. That second addition signalled the campaign's real escalation. The actors were no longer merely accessing controllers; they were rewriting the logic that keeps a plant inside safe operating parameters, and specifically disabling critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators (AA26-097A).
This case matters for three reasons that outlast the news cycle. First, it demonstrated that low-sophistication OT attacks scale: no zero-day, no bespoke implant, no insider — just exposure, default passwords, and the vendors' own engineering software, applied to dozens of victims at once. Second, it crossed a threshold. The 2023 Unitronics intrusions attributed to the same actor were defacement and nuisance; the 2026 campaign reached into safety instrumented logic. Third, it landed inside an active shooting war. The attacks came nineteen days after US aerial bombing of Iran resumed on 7–8 July 2026 and roughly a week after an Iranian strike on a US base in Jordan killed two American service members — and the claiming party said so out loud, describing the operation as a warning of capability and intent to retaliate against "any country that poses a threat to Iran" (APT Iran, via Telegram, reported by Check Point Research).
Geopolitical climate. The campaign's kinetic phase ran alongside the 2026 Iran war. A ceasefire agreed on 12 June 2026 and formalised in the Islamabad Memorandum of 17 June collapsed on 7 July when Iran struck three tankers in the southern Strait of Hormuz; the US resumed aerial bombardment that night and Trump declared the ceasefire over the following day. Over the weekend of 18–19 July, an Iranian strike on a US base in Jordan killed two American service members. The water-sector attacks began seven days later. Iranian cyber operations during the war had been assessed as running partly independent of the bombing campaign rather than tightly synchronised with it (Wikipedia, Cyberwarfare during the 2026 Iran war), which is consistent with what the water campaign looks like on the wire: pre-positioned access, built over eighteen months, actioned when a political moment called for a visible signal.
Organisational posture of the victims. American drinking-water utilities are the softest large target set in US critical infrastructure, and this was documented well before July. More than 70% of water systems inspected by EPA since September 2023 were found in violation of basic cybersecurity assessment requirements, and 97 systems serving roughly 26.6 million people carried critical or high-risk vulnerabilities (EPA inspection data, cited in CRS and Congressional reporting). The sector is structurally fragmented — tens of thousands of small municipal utilities, most with no dedicated security staff, many with no OT logging at all — and the governing statute, Section 2013 of America's Water Infrastructure Act, requires larger systems to assess risk but gives EPA no authority to compel remediation of what the assessment finds. An EPA attempt to close that gap via sanitary-survey guidance in 2023 was withdrawn after legal challenge from industry groups and Republican state attorneys general.
Technology landscape. The attack surface was measurable in advance. Censys reported in April 2026 that 5,219 internet-exposed hosts globally responded to industrial protocols as Rockwell Automation devices, with 3,891 — 74.6% — located in the United States, and a disproportionate share reachable over cellular networks rather than fixed broadband (Censys, Apr 2026; analysed by Tenable). That cellular detail turned out to be the operative one: Plymouth's compromised equipment sat at water towers and lift stations connected by cellular modem, precisely the architecture the advisory's Dropbear SSH observation describes. Compounding this, the single most relevant vulnerability has no fix. CVE-2021-22681 (CVSS 9.8), an authentication bypass in Rockwell Logix controllers arising from an insufficiently protected cryptographic key, has no firmware patch; Rockwell directs customers to architectural controls instead. CISA added it to the Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors — one month before AA26-097A.
Known pre-incident indicators. This was a signposted incident. The same actor compromised at least 75 Unitronics Vision-series PLC and HMI devices beginning in November 2023 — reaching them on default TCP port 20256 with the shipped default password "1111" — and replaced valid ladder logic with malicious code, prompting advisory AA23-335A. The US Treasury sanctioned IRGC-CEC-linked individuals associated with that activity in February 2024. Claroty's Team82 documented the actor's IOCONTROL implant in December 2024. AA26-097A itself was published in April 2026 with an IP block list, and updated with fresh indicators and expanded vendor scope on 22 July 2026. By the time Minnesota was hit, the warning had been issued, reissued, and sharpened — four days earlier.
| Type | Value / Description | Source | Date Observed |
|---|---|---|---|
| IPV4 | 185.82.73[.]175 | CISA AA26-097A Table 1 | Sep 2025 – Feb 2026 |
| IPV4 | 141.11.164[.]153 | CISA AA26-097A Table 1 | Jan 2026 – Jun 2026 |
| IPV4 | 175.110.121[.]39 | CISA AA26-097A Table 1 | Feb 2026 – Mar 2026 |
| IPV4 | 175.110.121[.]41 | CISA AA26-097A Table 1 | Feb 2026 – Mar 2026 |
| IPV4 | 175.110.121[.]42 | CISA AA26-097A Table 1 | Feb 2026 – Mar 2026 |
| IPV4 | 175.110.121[.]107 | CISA AA26-097A Table 1 | Feb 2026 |
| IPV4 | 192.142.54[.]79 | CISA AA26-097A Table 1 | May 2026 – Jun 2026 |
| IPV4 | 84.200.205[.]165 | CISA AA26-097A Table 1 | May 2026 – Jun 2026 |
| IPV4 | 185.225.17[.]225 | CISA AA26-097A Table 1 | Jun 2026 – Jul 2026 |
| IPV4 | 79.133.46[.]209 | CISA AA26-097A Table 1 | Jul 2026 |
| IPV4 | 88.80.150[.]199 | CISA AA26-097A Table 1 | Jul 2026 |
| IPV4 | 88.80.150[.]200 | CISA AA26-097A Table 1 | Jul 2026 |
| IPV4 | 88.80.150[.]202 | CISA AA26-097A Table 1 | Jul 2026 |
| IPV4 | 185.82.73[.]162 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]164 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]165 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]167 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]168 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]170 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 185.82.73[.]171 | CISA AA26-097A Table 2 | Jan 2025 – Mar 2026 |
| IPV4 | 135.136.1[.]133 | CISA AA26-097A Table 2 | Mar 2026 |
| INFRA | Leased, third-party hosted infrastructure used to run vendor PLC programming software and serve as C2 for project-file transfer — not actor-owned bulletproof hosting in the classic sense | CISA AA26-097A | Jan 2025 – Jul 2026 |
| PORT | TCP 44818 — EtherNet/IP explicit messaging (Rockwell); primary targeted OT port | CISA AA26-097A | 2026 |
| PORT | TCP/UDP 2222 — EtherNet/IP implicit (I/O) messaging | CISA AA26-097A | 2026 |
| PORT | TCP 102 — ISO-TSAP / S7 protocol (Siemens S7-1200) | CISA AA26-097A | 2026 |
| PORT | TCP 502 — Modbus (Schneider Modicon M340 / BMX P34) | CISA AA26-097A | 2026 |
| PORT | TCP 22 — SSH on victim cellular modems via actor-deployed Dropbear; anomalous on a water-utility modem and a high-value detection point | CISA AA26-097A | 2026 |
| PORT | TCP 20256 — Unitronics Vision series default remote-access port; precursor campaign (Nov 2023), retained as exposure indicator | CISA AA23-335A | Nov 2023 |
| BEHAVIOR | Unauthorized PLC program upload or download outside a change window — vendor engineering protocol traffic from an IP that is not a known integrator or engineering workstation | CISA AA26-097A detection guidance | Jul 2026 |
| BEHAVIOR | Divergence between running PLC logic and known-good baseline, with specific attention to modified or added Add-On Instructions (AOIs) on Rockwell controllers | CISA AA26-097A (22 Jul 2026 update) | Jul 2026 |
| BEHAVIOR | Controller mode-switch state change to PROGRAM or REMOTE outside maintenance; ICS management protocol functions that change an asset's operating mode or modify programs | CISA AA26-097A detection guidance | Jul 2026 |
| BEHAVIOR | Unexplained PLC credential change or device IP address reassignment resulting in operator lockout or loss of monitoring | Tenable; FBI WWS alert | Jul 2026 |
| NOTE | No file hashes, malware samples, C2 domains or YARA signatures have been published for this campaign as of 2026-09-11. This is consistent with the tradecraft: the operation used legitimate vendor engineering software, legitimate embedded SSH, and the victims' own project files rather than distributable malware. Detection must be behavioral and baseline-driven, not signature-driven. | Analyst assessment | 2026-09-11 |
The assessment holds at [MEDIUM] because the campaign and the event are attributed to different standards, and conflating them would overstate the case. The eighteen-month PLC exploitation campaign carries a genuine formal attribution: AA26-097A was signed on 7 April 2026 by the FBI, CISA, NSA, EPA, DOE, US Cyber Command's Cyber National Mission Force and the Department of the Treasury, and names Iranian-affiliated, IRGC-CEC-linked actors operating as CyberAv3ngers. That is a seven-agency government statement backed by infrastructure indicators, and it is strong. The 26–27 July coordinated disruption is a weaker case: as of early August 2026 federal attribution for that specific event remained pending, with the New York Times reporting on 30 July that investigators assessed Iranian hackers were "probably responsible" while explicitly noting the assessment could change. A leaked WaterISAC member communication indicated Iranian-linked responsibility, and Minnesota officials — while calling the attacks coordinated — stated it was not clear whether all of them were carried out by the same actor.
The adversary self-claim is corroborating but is not, on its own, evidence. A group posting as APT Iran stated on Telegram that "the attack on Minnesota was the work of the CyberAv3ngers group and us, and we take direct responsibility for it" (via Check Point Research). Claims of credit in this space are cheap, frequently opportunistic, and routinely made by groups with no involvement; APT Iran's subsequent framing — that the attack was "only to warn" — reads as narrative construction as much as confession. Its evidentiary weight here comes from consistency with the independently documented campaign, not from the claim itself.
What genuinely supports the linkage is behavioral continuity. The July victim set matches the AA26-097A campaign's targeting logic precisely — internet-exposed PLCs, water sector priority, vendor-agnostic selection driven by exposure, Rockwell MicroLogix 1100/1400 named by the FBI, the same credential-abuse and logic-modification pattern documented four days earlier in the advisory update. The 2023 Unitronics precursor establishes that this actor specifically attacks US water utilities via exposed controllers with default credentials, and the February 2024 Treasury sanctions establish USG willingness to attribute that activity to IRGC-CEC-linked individuals by name. Dragos, which tracks the overlapping activity as BAUXITE, explicitly does not perform political attribution and states only that BAUXITE shows technical overlap with activity the US government assesses as aligned with CyberAv3ngers and IRGC-CEC — a caution worth preserving. The defensible conclusion is that AA26-097A activity is consistent with a CyberAv3ngers/BAUXITE-overlapping capability set, not that every vendor label maps one-to-one to a single organisational identity.
The competing hypotheses are not merely formal. The most credible alternative is contamination of the victim set: AA26-097A published a detailed description of exploitable, internet-exposed PLCs on 7 April and updated it on 22 July, and any capable opportunist could have acted on that public roadmap in the following days. Distinguishing state-directed action from copycat exploitation of a published advisory requires per-victim forensics tying intrusions to the advisory's IP infrastructure, which is not public. A secondary alternative — that "coordinated" overstates what was in fact several loosely related actor sets hitting the same soft target simultaneously — is supported by Minnesota officials' own hedging. Finally, the domestic political dispute over attribution should be excluded from the analytic picture entirely. The President's public rejection of Iranian responsibility and the Governor's counter-claim are political statements, not intelligence judgments, and neither constitutes evidence for or against the technical assessment. They are recorded here as part of the incident's history, not as inputs to it.
This is the case that ended the "too fragmented to attack at scale" assumption about the US water sector. The sector's own defence had long been implicit in its structure: roughly fifty thousand community water systems, no common vendor, no common architecture, no central chokepoint, and therefore — the reasoning went — no way for an adversary to achieve broad simultaneous effect. July 2026 disproved it by attacking not a chokepoint but a shared condition. Internet exposure plus weak authentication is common to thousands of small utilities regardless of vendor, and it turned out to be as good as a monoculture. Any future assessment of sector resilience has to reason about shared configuration failure modes, not just shared technology.
It established safety-function suppression as live adversary practice against civilian infrastructure, not a theoretical worst case. Before this campaign, the canonical example of an adversary attacking safety systems was TRITON/TRISIS at a Saudi petrochemical plant in 2017 — a single, elaborately resourced operation against one industrial facility. AA26-097A documents disabling "critical shutdown and alarm logic" across a distributed victim set in American municipalities, achieved by editing the plant's own Add-On Instructions after stealing its project file. The distinction that will be taught is between attacking the process and attacking the protections on the process: one causes an incident, the other removes the layer designed to stop an incident from becoming a catastrophe. That the campaign produced no casualties is a fact about restraint and operator competence, not about capability.
It is the clearest available case study in advisory efficacy — and its limits. The full mitigation was published on 7 April 2026, sharpened on 22 July, cost nothing, and worked: utilities that disconnected internet-facing PLCs before 26 July were spared. Utilities that had not were disrupted. The four-day gap between the updated advisory and the attack is an almost experimental measurement of the distance between federal warning and municipal capacity to act, in a sector where EPA had already found more than 70% of inspected systems non-compliant with basic assessment requirements and possessed no authority to compel remediation. The enduring lesson is uncomfortable for the warning-based model of critical infrastructure defence: a perfect advisory delivered to an organisation without staff to read or act on it is not a control. Whether the Water Cyber Shield Act converts that lesson into authority remains unresolved as of this compile, and is the single most consequential open question the campaign leaves behind.
Finally, it is a data point in how cyber operations function inside a shooting war. Access built quietly over eighteen months was actioned within days of a lethal exchange, then publicly claimed as a warning rather than denied. That sequence — pre-position early, hold, trigger for political effect, claim for deterrent value — is a recognisable playbook, and its target selection tells defenders something durable: the adversary chose the infrastructure that maximises civilian salience and minimises escalation risk. Municipal water is visible enough to frighten a population and small enough to attack without crossing a threshold that compels a kinetic response. That calculation will not be unique to Iran, and it will not be unique to 2026.