CASE FILE
INC-2026-0726-WWS
JAN 2025 – JUL 2026
TLP:CLEAR
// Cyber Incident Case File — Nation-State Destructive · ICS/OT Disruption

US WATER SECTOR PLC CAMPAIGN

COMPILED: 2026-09-11  |  INCIDENT DATE: JAN 2025 – JUL 2026 (culminating 26–27 JUL 2026)  |  SOURCES: CISA/FBI/NSA/EPA/DOE/CNMF/Treasury AA26-097A · FBI WWS Alert · MNIT · CRS · GAO · Tenable · Dragos · Claroty · Censys · CSIS · Cybersecurity Dive · Washington Post · ABC News
Incident Type: NATION-STATE DESTRUCTIVE / ICS-OT DISRUPTION
Attribution: IRANIAN-AFFILIATED (IRGC-CEC) [MEDIUM]
Severity: CRITICAL
Era: 2026 Iran War
ATT&CK Framework: ICS + ENTERPRISE
Sector: WATER & WASTEWATER · ENERGY · GOVT FACILITIES
~36
Minnesota community water systems hit in 48 hours (MNIT, 28 Jul 2026)
100+
US facilities assessed as targeted (NYT, citing US investigators)
12
US states with impacted utilities (Cybersecurity Dive, Aug 2026)
9.8
CVSS — CVE-2021-22681, Rockwell Logix auth bypass, no vendor patch
00
Case File Overview
Attributed Actor → CyberAv3ngers / IRGC-CEC-affiliated (see actor card: 2026-09-02_CYBERAV3NGERS)
Incident NameUS Water Sector PLC Campaign
Date RangeJan 2025 – Jul 2026 (peak: 26–27 Jul 2026)
Incident TypeNation-state destructive · ICS/OT disruption
Primary ActorCyberAv3ngers (Bauxite / Storm-0784 / UNC5691); APT Iran co-claim
Attribution Confidence[MEDIUM] — campaign-level USG attribution; event-level assessment preliminary
Primary TargetInternet-exposed PLCs — Rockwell, Schneider, Siemens, Unitronics
Victim Count~36 MN systems confirmed; 100+ US facilities assessed targeted
Initial Discovery7 Apr 2026 (advisory AA26-097A); 26 Jul 2026 (mass disruption)
Discovered ByFBI/CISA/EPA joint reporting; MNIT and utility operators
Dwell TimeCampaign infrastructure active from Jan 2025 — ~18 months before mass effect
Primary ImpactLoss of monitoring and control; safety/alarm logic suppression; operator lockout
ATT&CK FrameworkICS (primary) + Enterprise
MITRE Campaign IDNone assigned as of 2026-09-11
Historical IOCsCurrent — incident is under 5 years old; IOCs retain operational utility
01
Situation Overview

Between 26 and 27 July 2026, roughly three dozen Minnesota community water systems lost control of their own plants within a forty-eight-hour window. In Braham, malware shut down the automated operating controls and the water tower could not be filled for more than an hour (Braham city administrator Kevin Stahl, via FOX 9). Plymouth and South St. Paul reverted to manual operation. Maple Plain's mayor declared a local emergency. Minnesota IT Services put the confirmed total at approximately 36 systems (MNIT CISO John Israel, 28 Jul 2026). It was, in the plainest terms, the first time a foreign cyber operation degraded the operation of dozens of American drinking-water utilities simultaneously.

Minnesota was where the campaign surfaced, not where it began or ended. Within days the same pattern appeared in Georgia — where the Clayton County Water Authority issued a precautionary boil-water advisory after a pump station failed around 01:00 on 27 July, dropping pressure for customers until crews restored it near 04:00 — and in Michigan, South Dakota, New Jersey and elsewhere. Reporting ultimately placed impacted utilities in at least twelve states (Cybersecurity Dive, Aug 2026), and US investigators assessed that more than 100 facilities had been targeted nationally (New York Times, 30 Jul 2026). The technical common denominator was mundane and damning: internet-facing programmable logic controllers, reachable from the public internet, many still carrying vendor default credentials.

The July events were the loud end of a quiet eighteen-month operation. Joint advisory AA26-097A — signed by FBI, CISA, NSA, EPA, DOE, US Cyber Command's Cyber National Mission Force and the Treasury on 7 April 2026 — documented Iranian-affiliated actors exploiting exposed PLCs across water, energy and government facilities, with hostile infrastructure traceable to January 2025. The advisory's 22 July 2026 update, published four days before the Minnesota attacks, did two things that matter analytically: it expanded the confirmed targeting scope beyond Rockwell Automation to Schneider Electric and Siemens controllers, and it added detection guidance for malicious modification of Add-On Instructions — reusable code modules inside Rockwell PLC programs. That second addition signalled the campaign's real escalation. The actors were no longer merely accessing controllers; they were rewriting the logic that keeps a plant inside safe operating parameters, and specifically disabling critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators (AA26-097A).

This case matters for three reasons that outlast the news cycle. First, it demonstrated that low-sophistication OT attacks scale: no zero-day, no bespoke implant, no insider — just exposure, default passwords, and the vendors' own engineering software, applied to dozens of victims at once. Second, it crossed a threshold. The 2023 Unitronics intrusions attributed to the same actor were defacement and nuisance; the 2026 campaign reached into safety instrumented logic. Third, it landed inside an active shooting war. The attacks came nineteen days after US aerial bombing of Iran resumed on 7–8 July 2026 and roughly a week after an Iranian strike on a US base in Jordan killed two American service members — and the claiming party said so out loud, describing the operation as a warning of capability and intent to retaliate against "any country that poses a threat to Iran" (APT Iran, via Telegram, reported by Check Point Research).

02
Background & Context

Geopolitical climate. The campaign's kinetic phase ran alongside the 2026 Iran war. A ceasefire agreed on 12 June 2026 and formalised in the Islamabad Memorandum of 17 June collapsed on 7 July when Iran struck three tankers in the southern Strait of Hormuz; the US resumed aerial bombardment that night and Trump declared the ceasefire over the following day. Over the weekend of 18–19 July, an Iranian strike on a US base in Jordan killed two American service members. The water-sector attacks began seven days later. Iranian cyber operations during the war had been assessed as running partly independent of the bombing campaign rather than tightly synchronised with it (Wikipedia, Cyberwarfare during the 2026 Iran war), which is consistent with what the water campaign looks like on the wire: pre-positioned access, built over eighteen months, actioned when a political moment called for a visible signal.

Organisational posture of the victims. American drinking-water utilities are the softest large target set in US critical infrastructure, and this was documented well before July. More than 70% of water systems inspected by EPA since September 2023 were found in violation of basic cybersecurity assessment requirements, and 97 systems serving roughly 26.6 million people carried critical or high-risk vulnerabilities (EPA inspection data, cited in CRS and Congressional reporting). The sector is structurally fragmented — tens of thousands of small municipal utilities, most with no dedicated security staff, many with no OT logging at all — and the governing statute, Section 2013 of America's Water Infrastructure Act, requires larger systems to assess risk but gives EPA no authority to compel remediation of what the assessment finds. An EPA attempt to close that gap via sanitary-survey guidance in 2023 was withdrawn after legal challenge from industry groups and Republican state attorneys general.

Technology landscape. The attack surface was measurable in advance. Censys reported in April 2026 that 5,219 internet-exposed hosts globally responded to industrial protocols as Rockwell Automation devices, with 3,891 — 74.6% — located in the United States, and a disproportionate share reachable over cellular networks rather than fixed broadband (Censys, Apr 2026; analysed by Tenable). That cellular detail turned out to be the operative one: Plymouth's compromised equipment sat at water towers and lift stations connected by cellular modem, precisely the architecture the advisory's Dropbear SSH observation describes. Compounding this, the single most relevant vulnerability has no fix. CVE-2021-22681 (CVSS 9.8), an authentication bypass in Rockwell Logix controllers arising from an insufficiently protected cryptographic key, has no firmware patch; Rockwell directs customers to architectural controls instead. CISA added it to the Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors — one month before AA26-097A.

Known pre-incident indicators. This was a signposted incident. The same actor compromised at least 75 Unitronics Vision-series PLC and HMI devices beginning in November 2023 — reaching them on default TCP port 20256 with the shipped default password "1111" — and replaced valid ladder logic with malicious code, prompting advisory AA23-335A. The US Treasury sanctioned IRGC-CEC-linked individuals associated with that activity in February 2024. Claroty's Team82 documented the actor's IOCONTROL implant in December 2024. AA26-097A itself was published in April 2026 with an IP block list, and updated with fresh indicators and expanded vendor scope on 22 July 2026. By the time Minnesota was hit, the warning had been issued, reissued, and sharpened — four days earlier.

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Phase 1 — Internet-Exposed Asset Discovery BLIND
The campaign required no exploitation to find its victims. Water and wastewater PLCs sit on the public internet in the thousands, advertising themselves through the industrial protocols they speak. AA26-097A names the ports the actors worked against — 44818 (EtherNet/IP, Rockwell), 2222 (EtherNet/IP implicit messaging), 102 (ISO-TSAP/S7, Siemens) and 502 (Modbus, Schneider) — the standard vocabulary of the three vendor families ultimately targeted. Independent scanning corroborates the size of the pool: Censys counted 5,219 internet-exposed hosts globally responding as Rockwell Automation devices in April 2026, 3,891 of them in the United States, with a disproportionate share on cellular rather than fixed connections (Censys via Tenable, Apr 2026). The advisory does not document the actors' own scanning activity directly, so the reconnaissance method is inferred from the exposure-driven victimology rather than observed — but the target set was enumerable by anyone with a search engine for internet-connected devices, and required no privileged access to assemble. Defender visibility was nil: internet-wide scanning of an exposed device generates no alert at a utility with no OT monitoring, which describes most of the victim population.
A publicly enumerable target list meant the actors could skip initial access entirely as a problem to be solved — the only remaining question was authentication.
Phase 2 — Direct Access to Exposed Controllers BLIND
Access was achieved by connecting to controllers that lacked, in the advisory's language, "sufficient network and/or hardening security controls." The actors used leased, third-party hosted infrastructure together with the manufacturers' own PLC programming software to reach misconfigured victim devices (AA26-097A). Two authentication failures made this work. The first was credential hygiene: the advisory's remediation guidance leads with ensuring "device passwords are changed from their default," and the same actor's 2023 Unitronics campaign had already demonstrated the pattern at scale, reaching devices on default port 20256 with the shipped default password. The second was structural — CVE-2021-22681 (CVSS 9.8), an authentication bypass in Rockwell Logix controllers caused by an insufficiently protected cryptographic key, for which no firmware patch exists and which CISA added to the Known Exploited Vulnerabilities catalog in March 2026 after confirmed exploitation by Iranian-affiliated actors (see vuln card: 2026-09-02_ROCKWELL-LOGIX-AUTH-BYPASS). A controller reachable from the internet with this flaw cannot be patched into safety; it can only be taken off the internet. Most were not. Defender visibility was nil at the great majority of victims — small municipal utilities with no OT network monitoring and, in many cases, no awareness that the device was internet-reachable at all.
With authenticated interactive access to the controller, the actors held the same privileges as the plant's own engineer — and could now establish access that survived a reboot.
Phase 3 — Modem Foothold & Persistence (Dropbear SSH) BLIND
In at least one documented case, the actors moved off the controller and onto the network device in front of it: AA26-097A records that they "utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port 22." Dropbear is a legitimate lightweight SSH implementation common in embedded Linux, which is exactly why it is useful here — it is plausible software on a cellular modem, it is small, and it is not malware any signature engine will flag. Functionally this converted an opportunistic connection to an exposed PLC into durable remote access to the site's communications path, independent of whether the controller itself was later hardened. It also sat in the worst possible place for a defender: the cellular modems serving remote assets — water towers, lift stations, pump houses — are typically vendor- or carrier-managed, rarely logged to any SIEM, and frequently outside the utility's own asset inventory. Plymouth's response, disconnecting cellular equipment at water towers and lift stations, indicates the same architecture in the Minnesota victims. Defender visibility was nil: no source describes any victim detecting the Dropbear installation contemporaneously.
Persistent access to the site's communication path allowed the actors to work at their own pace — and what they wanted next was the plant's engineering intellectual property.
Phase 4 — Project File Exfiltration via Vendor Engineering Software BLIND
The actors then did something that distinguishes this campaign from ordinary opportunistic OT meddling: they took the plant's source code. Running the vendors' own configuration software — Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert and Siemens Totally Integrated Automation (TIA) Portal — on leased third-party infrastructure, they exfiltrated device project files (AA26-097A). A project file is the controller's program: ladder logic and configuration settings, stored on Rockwell devices as an .ACD file. Possessing it means possessing a complete description of how that specific plant is instrumented, sequenced and interlocked — which pumps run in what order, which sensors trip which alarms, which conditions force a shutdown. This is the prerequisite for surgical rather than random manipulation, and it is why this phase is the analytic hinge of the whole case. Because the traffic was the legitimate vendor engineering protocol carrying a legitimate engineering operation, it is functionally indistinguishable from an integrator doing routine work — and defender visibility was nil at victims with no baseline of who is authorised to upload a program and when.
Holding the plant's logic and knowing its interlocks, the actors could now author modifications that would run correctly, look correct, and still be unsafe.
Phase 5 — Safety Logic Suppression & Weaponized Project Files BLIND
This is the escalation that prompted the 22 July 2026 advisory update, and it is the most serious conduct in the case file. The actors conducted "modification and deletion of project file logic, to include Add-On Instructions (AOIs), and data manipulation on HMI and SCADA displays" (AA26-097A). AOIs are reusable, user-authored code modules inside a Rockwell program — the natural hiding place for logic tampering, because engineers treat them as trusted library components and rarely diff them line by line. The malicious project files retained functional ladder logic but carried "added logic that overrode specific instruction sets responsible for maintaining safe operating parameters." In the advisory's own words, those changes "disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators." Two properties make this qualitatively worse than the actor's 2023 defacement activity. The plant still appears to work — the program runs, the HMI renders, the operator sees a normal screen. And the specific functions removed are the ones that exist to catch the failure: the automatic trip and the alarm that would summon a human. Manipulating the HMI and SCADA display layer alongside the controller logic closes the loop, ensuring the operator's view agrees with the sabotaged process rather than with physical reality. Defender visibility was nil: detecting this requires comparing running PLC logic against a known-good baseline, which the advisory had to introduce as new guidance in July precisely because it was not standard practice.
With weaponized logic resident on controllers across multiple states and vendors, the campaign held a coordinated disruption capability it could trigger at a time of political choosing.
Phase 6 — Coordinated Disruption & Operator Lockout (26–27 Jul 2026) DETECTED
On 26–27 July 2026 the campaign went loud across roughly 36 Minnesota community water systems and, within days, utilities in at least twelve states. The observed actions were blunt: remote password changes that locked legitimate operators out of their own controllers, IP address modifications that severed devices from monitoring systems, and the previously staged logic modifications disabling safety and alarm functions (Tenable; FBI water-sector alert, 30 Jul 2026). The FBI summarised the effect as a "loss of monitoring and control functionality." Impacts were real but bounded: in Braham, plant controls went down and the tower could not be filled for over an hour, restored in roughly two hours via manual procedures; Plymouth and South St. Paul ran manually; Maple Plain declared a local emergency; in Clayton County, Georgia, a pump station failed around 01:00 on 27 July, dropping pressure and triggering a precautionary boil-water advisory that was lifted on 28 July after testing confirmed the water safe. New Jersey's Office of Homeland Security reported two utilities where "staff shifted quickly to manual operations, and there was no disruption to service." No degradation of drinking water quality was confirmed at any victim, and no related illness was reported. Detection occurred at the moment of effect, by plant operators — not by security tooling — and the reason it was survivable is that water operators are trained and equipped to run their plants by hand.
Operational detection triggered a state and federal response — but by then the only remaining question was who had done it, and why they wanted it seen.
Phase 7 — Claim, Signaling & Response DETECTED
Minnesota IT Services activated a statewide response immediately on learning of the attack and issued a public statement on 28 July 2026, coordinating with CISA, EPA, FBI, the Minnesota Department of Public Safety's Bureau of Criminal Apprehension and Fusion Center, the Minnesota Department of Health and the Minnesota Pollution Control Agency, and pushing threat intelligence and indicators to affected utilities (MNIT; CISO John Israel: "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response"). On 30 July the FBI and EPA issued a sector-wide alert on malicious actors targeting internet-facing WWS PLCs, and the New York Times reported that US investigators had preliminarily assessed Iranian hackers were "probably responsible," with the caveat that the assessment could change. The claiming came from the adversary side: a group posting as APT Iran stated on Telegram that "the attack on Minnesota was the work of the CyberAv3ngers group and us, and we take direct responsibility for it," later adding that "our intention in attacking Minnesota was only to warn" of its capability and its intent to retaliate against "any country that poses a threat to Iran" (reported by Check Point Research). The signal was also aimed domestically: Trump publicly downplayed the incidents and disputed Iranian responsibility while criticising Minnesota's governor, who countered that the administration was concealing the responsible party — a public disagreement over attribution between a president and a state governor that is itself part of the case record.
04
TTPs — MITRE ATT&CK Mapping ICS primary, Enterprise supporting · post-2013 incident, no retrospective mapping required · confidence per cell
ENTERPRISE
Reconnaissance
T1595 — [MEDIUM]
Active Scanning
Victimology is entirely exposure-driven across four vendor families, implying internet-wide enumeration of OT protocol ports. AA26-097A does not document the actors' scanning directly — inferred from targeting pattern and Censys exposure data (3,891 US Rockwell hosts, Apr 2026).
ICS
Initial Access
T0883 — [HIGH]
Internet Accessible Device
Named explicitly in AA26-097A: actors "accessed and interacted with publicly exposed, internet-accessible PLCs." The single defining precondition of every confirmed compromise in this campaign.
ICS
Initial Access
T0822 — [HIGH]
External Remote Services
Remote access reached controllers and cellular modems serving water towers and lift stations. Plymouth's remediation — physically disconnecting cellular equipment at remote assets — confirms the vector at a named victim.
ENTERPRISE
Initial Access / Credential
T1078 — [MEDIUM]
Valid Accounts (Default Credentials)
AA26-097A leads its remediation with changing device passwords "from their default." Same-actor precedent is direct: the Nov 2023 Unitronics campaign used the shipped default password on the vendor default port. Rated MEDIUM as the advisory does not confirm default-credential use at every 2026 victim.
ENTERPRISE
Initial Access
T1190 — [HIGH]
Exploit Public-Facing Application
CVE-2021-22681 (CVSS 9.8) authentication bypass in Rockwell Logix controllers — no vendor patch available. Added to CISA KEV in March 2026 after confirmed exploitation by Iranian-affiliated actors. See vuln card: 2026-09-02_ROCKWELL-LOGIX-AUTH-BYPASS.
ENTERPRISE
Persistence
T1219 — [HIGH]
Remote Access Tools
Dropbear SSH deployed on victim cellular modems to enable remote access via port 22 (AA26-097A). Legitimate embedded SSH software — no malware signature to detect, and modems typically fall outside utility asset inventory and logging.
ICS
Defense Evasion / Impair Process Control
T0878 — [HIGH]
Alarm Suppression
Modified project logic "disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators" (AA26-097A, 22 Jul 2026 update). The defining escalation of this campaign over prior Iranian OT activity.
ICS
Defense Evasion
T0851 — [MEDIUM]
Rootkit / Logic Concealment
Weaponized project files preserved functional ladder logic while overriding safe-operating instruction sets, so a running plant appeared normal. Mapped as concealment by design rather than a discrete rootkit artifact; no rootkit binary is documented.
ICS
Command & Control
T0885 — [HIGH]
Commonly Used Port
Operations conducted over standard OT ports 44818 (EtherNet/IP), 2222, 102 (ISO-TSAP/S7) and 502 (Modbus), plus 22 for modem SSH — traffic indistinguishable from legitimate engineering activity absent an access baseline.
ICS
Collection
T0845 — [HIGH]
Program Upload
Device project files (.ACD on Rockwell) uploaded from controllers using vendor engineering software — Studio 5000 Logix Designer, EcoStruxure Control Expert, TIA Portal — run on leased third-party infrastructure.
ENTERPRISE
Exfiltration
T1041 — [HIGH]
Exfiltration Over C2 Channel
AA26-097A: actors used "remote, third-party hosted infrastructure as a C2 channel to transfer device project files." Stolen logic is the prerequisite for the targeted safety-function modification in Phase 5.
ICS
Impact / Inhibit Response Function
T0889 — [HIGH]
Modify Program
"Modification and deletion of project file logic, to include Add-On Instructions (AOIs)" (AA26-097A). AOIs are reusable trusted code modules engineers rarely diff — the July advisory update added detection guidance specifically for anomalous AOI modification.
ICS
Impact
T0880 — [HIGH]
Loss of Safety
Disabling automatic shutdown logic removed the plant's independent protective layer, leaving unsafe process conditions dependent on human noticing. No physical harm resulted at any confirmed victim — the capability, not the outcome, is what is evidenced.
ICS
Impact
T0832 — [HIGH]
Manipulation of View
"Data manipulation on HMI and SCADA displays" (AA26-097A) — falsifying the operator's picture so it agrees with the sabotaged process rather than physical reality. Enterprise equivalent T1565 (Data Manipulation) is the advisory's own mapping.
ICS
Impact
T0892 — [HIGH]
Change Credential
Remote PLC password changes locked legitimate operators out of their own controllers during the 26–27 July disruption (Tenable; FBI WWS alert). Directly forced the reversion to manual operation at multiple Minnesota utilities.
ICS
Impact
T0829 / T0827 — [HIGH]
Loss of View / Loss of Control
FBI characterised the campaign's effect as "loss of monitoring and control functionality." IP address modification severed controllers from monitoring systems; Braham lost automated plant control for roughly two hours.
05
Defender Post-Mortem What was missed, when, and why
PHASE 1–2
MISSED
Utilities did not know their own controllers were internet-reachable. The exposure was measurable from outside — Censys counted 3,891 US hosts responding as Rockwell devices in April 2026 — while the asset owners, in many cases, held no inventory recording that the device had a public route at all. The campaign required no exploit chain at the majority of victims because the front door was both open and unlisted. This is an asset-management failure before it is a detection failure: you cannot monitor a device you do not know you operate.
ADVISORY-TO-ACTION
MISSED — MOST CONSEQUENTIAL
The warning arrived four days early and most utilities could not act on it in time. AA26-097A was published 7 April 2026 and updated 22 July — four days before the Minnesota attacks. Reporting indicates utilities that had disconnected their internet-facing PLCs before 26 July were unaffected, while those that had not were hit (FOX 9; SecureWorld). The mitigation was known, published, free and effective; the binding constraint was organisational capacity to execute it in a sector where most operators have no dedicated security staff. This is the sharpest finding in the case file: advisory efficacy is bounded not by the quality of the advisory but by the recipient's ability to act, and a four-day window is a test most small municipal utilities will fail.
PHASE 3
MISSED
Cellular modems at remote assets were an unmonitored blind spot. Dropbear SSH on victim modems gave persistence on equipment that is typically carrier- or vendor-managed, rarely forwards logs anywhere, and often sits outside the utility's inventory entirely. No source records any victim detecting the installation contemporaneously. The architecture that made remote water towers and lift stations economically supervisable is the same architecture that made them invisible.
PHASE 4–5
MISSED
No baseline existed to diff running PLC logic against known-good. Project file upload and modification used the vendors' legitimate engineering software over legitimate engineering protocols, which is indistinguishable from an integrator doing routine work unless the defender knows who is authorised to upload a program and when. That AA26-097A had to introduce AOI-modification detection guidance in its July update is itself the evidence: comparing running logic to a trusted baseline was not standard practice in this sector before this campaign.
PHASE 6
PARTIALLY DETECTED
Detection happened at the moment of effect, by operators, not by security tooling. Plant staff noticed because controls stopped responding and they were locked out — the last possible point of discovery. The mitigating factor was operational rather than cyber: water operators are trained to run plants manually, so Plymouth, South St. Paul and the two New Jersey utilities absorbed the disruption without service loss. That resilience is real and worth crediting, but it caught the campaign at Phase 6 of 7, after eighteen months of access and after safety logic had already been modified.
REGULATORY LAYER
MISSED
The sector's governing statute could not compel the fix. Section 2013 of America's Water Infrastructure Act requires larger systems to assess risk but gives EPA no authority to require remediation of what is found. More than 70% of systems EPA inspected since September 2023 violated basic assessment requirements, and 97 systems serving ~26.6 million people carried critical or high-risk vulnerabilities. EPA's 2023 attempt to close the gap through sanitary-survey guidance was withdrawn after industry and state legal challenge. The vulnerability data existed in government hands before the campaign; the authority to act on it did not.
POST-INCIDENT
LESSON ADOPTED
Detection guidance, coordination doctrine and a live legislative response. AA26-097A's July update added the first authoritative federal guidance on detecting malicious AOI and project-file modification, directing defenders to vendor integrity-checking tools and visual comparison of running programs against known-good logic. MNIT's whole-of-government activation — pushing IOCs and response guidance across state health, environmental, law-enforcement and fusion-centre channels within 24–48 hours — is being treated as a template for state-level OT incident coordination. In Congress, the Water Cyber Shield Act of 2026 (Klobuchar/Schiff) would grant EPA explicit authority to assess sector cyber threats, require utilities to remediate identified vulnerabilities, and direct tiered standards developed with CISA and NIST; the Water Resources Development Act of 2026 (S. 4949) carries wastewater cyber and digital infrastructure grant provisions. Whether these pass is unresolved as of this compile.
06
Technical Artifacts Malware, tools, CVEs, IOCs
CVE-2021-22681 — Rockwell Logix Authentication Bypass
CVE CVSS 9.8 NO VENDOR PATCH CISA KEV
Authentication bypass in Rockwell Automation Logix controllers arising from an insufficiently protected cryptographic key shared between Studio 5000 Logix Designer and the controller. An attacker who extracts the key can authenticate as a legitimate engineering workstation and alter controller configuration and logic. No firmware patch exists — Rockwell directs customers to architectural controls (network segmentation, removing internet exposure, physical mode-switch discipline). Added to CISA's Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploitation by Iranian-affiliated actors, one month before AA26-097A. (see vuln card: 2026-09-02_ROCKWELL-LOGIX-AUTH-BYPASS)
Dropbear SSH
LEGITIMATE SOFTWARE PERSISTENCE T1219
Lightweight open-source SSH server and client designed for embedded Linux environments. Deployed by the actors on victim cellular modems to establish remote access via port 22 (AA26-097A). Its value to the operation is precisely that it is not malware: it is plausible, common embedded software that generates no signature-based detection, running on network equipment that most water utilities neither inventory nor log. Detection requires noticing an SSH listener that should not exist on a modem, not scanning for a malicious file.
Weaponized PLC Project Files (.ACD and vendor equivalents)
CUSTOM LOGIC SAFETY SUPPRESSION T0889 / T0878
The campaign's primary offensive payload was not a binary but the plant's own program, rewritten. A project file contains a controller's ladder logic and configuration settings — stored as an .ACD file on Rockwell devices. The actors exfiltrated genuine project files, modified them, and redeployed them. Modified files retained functional ladder logic but carried added logic overriding "specific instruction sets responsible for maintaining safe operating parameters," which "disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators" (AA26-097A). Modification concentrated in Add-On Instructions (AOIs) — reusable user-authored code modules that engineers treat as trusted library components and rarely inspect line by line. Detection artifact: divergence between running controller logic and a known-good baseline; the July 2026 advisory update directs defenders to vendor integrity-checking tools and visual program comparison, with specific attention to anomalous AOI modification.
Vendor Engineering Software (dual-use)
LOTL / DUAL-USE COLLECTION T0845
Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert and Siemens Totally Integrated Automation (TIA) Portal, run by the actors on leased third-party hosted infrastructure to connect to victim controllers and exfiltrate device project files (AA26-097A). This is living-off-the-land applied to OT: the traffic is the legitimate vendor engineering protocol carrying a legitimate engineering operation, and is indistinguishable from authorised integrator work absent an access baseline recording who may upload or download a program and when.
Targeted Controller Hardware
TARGET SET 4 VENDOR FAMILIES
Rockwell Automation / Allen-Bradley: MicroLogix 1100 and 1400 series (named by FBI in the July 2026 water-sector activity), CompactLogix, Micro850. Schneider Electric: BMX P34 / Modicon M340. Siemens: S7-1200 series. Unitronics: Vision series PLC/HMI (same actor, Nov 2023 precedent campaign, default port 20256). The 22 July 2026 advisory update expanded confirmed scope beyond Rockwell to Schneider, Siemens "and potentially other branded/manufactured PLCs" — vendor-agnostic targeting driven by internet exposure rather than by any one product's flaws. Vendor security contacts per the advisory: Rockwell PSIRT (advisory SD1771), Schneider CPCERT, Siemens ProductCERT.
IOCONTROL
CONTEXTUAL — NOT CONFIRMED IN THIS CAMPAIGN MODULAR LINUX IMPLANT
Custom modular Linux implant attributed to the same actor and documented by Claroty Team82 in December 2024, using MQTT over TLS (port 8883) and DNS-over-HTTPS for C2, targeting fuel dispensing systems, Unitronics and Rockwell controllers, and consumer network and camera devices. Included for actor-capability context only — no public source places IOCONTROL at any confirmed victim of the 2026 PLC campaign. Its relevance is that the actor holds a purpose-built OT implant capability it apparently did not need to use here, because exposure and default credentials sufficed. Full technical treatment lives in the companion actor card.
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
⚠ CURRENT IOCs — This incident is under five years old and infrastructure indicators retain operational detection utility. Note however that AA26-097A Table 2 addresses were published 7 Apr 2026 and may have rotated; Table 1 addresses were published 22 Jul 2026. Treat port and behavioral indicators as the more durable detection surface.
TypeValue / DescriptionSourceDate Observed
IPV4185.82.73[.]175CISA AA26-097A Table 1Sep 2025 – Feb 2026
IPV4141.11.164[.]153CISA AA26-097A Table 1Jan 2026 – Jun 2026
IPV4175.110.121[.]39CISA AA26-097A Table 1Feb 2026 – Mar 2026
IPV4175.110.121[.]41CISA AA26-097A Table 1Feb 2026 – Mar 2026
IPV4175.110.121[.]42CISA AA26-097A Table 1Feb 2026 – Mar 2026
IPV4175.110.121[.]107CISA AA26-097A Table 1Feb 2026
IPV4192.142.54[.]79CISA AA26-097A Table 1May 2026 – Jun 2026
IPV484.200.205[.]165CISA AA26-097A Table 1May 2026 – Jun 2026
IPV4185.225.17[.]225CISA AA26-097A Table 1Jun 2026 – Jul 2026
IPV479.133.46[.]209CISA AA26-097A Table 1Jul 2026
IPV488.80.150[.]199CISA AA26-097A Table 1Jul 2026
IPV488.80.150[.]200CISA AA26-097A Table 1Jul 2026
IPV488.80.150[.]202CISA AA26-097A Table 1Jul 2026
IPV4185.82.73[.]162CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]164CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]165CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]167CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]168CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]170CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4185.82.73[.]171CISA AA26-097A Table 2Jan 2025 – Mar 2026
IPV4135.136.1[.]133CISA AA26-097A Table 2Mar 2026
INFRALeased, third-party hosted infrastructure used to run vendor PLC programming software and serve as C2 for project-file transfer — not actor-owned bulletproof hosting in the classic senseCISA AA26-097AJan 2025 – Jul 2026
PORTTCP 44818 — EtherNet/IP explicit messaging (Rockwell); primary targeted OT portCISA AA26-097A2026
PORTTCP/UDP 2222 — EtherNet/IP implicit (I/O) messagingCISA AA26-097A2026
PORTTCP 102 — ISO-TSAP / S7 protocol (Siemens S7-1200)CISA AA26-097A2026
PORTTCP 502 — Modbus (Schneider Modicon M340 / BMX P34)CISA AA26-097A2026
PORTTCP 22 — SSH on victim cellular modems via actor-deployed Dropbear; anomalous on a water-utility modem and a high-value detection pointCISA AA26-097A2026
PORTTCP 20256 — Unitronics Vision series default remote-access port; precursor campaign (Nov 2023), retained as exposure indicatorCISA AA23-335ANov 2023
BEHAVIORUnauthorized PLC program upload or download outside a change window — vendor engineering protocol traffic from an IP that is not a known integrator or engineering workstationCISA AA26-097A detection guidanceJul 2026
BEHAVIORDivergence between running PLC logic and known-good baseline, with specific attention to modified or added Add-On Instructions (AOIs) on Rockwell controllersCISA AA26-097A (22 Jul 2026 update)Jul 2026
BEHAVIORController mode-switch state change to PROGRAM or REMOTE outside maintenance; ICS management protocol functions that change an asset's operating mode or modify programsCISA AA26-097A detection guidanceJul 2026
BEHAVIORUnexplained PLC credential change or device IP address reassignment resulting in operator lockout or loss of monitoringTenable; FBI WWS alertJul 2026
NOTENo file hashes, malware samples, C2 domains or YARA signatures have been published for this campaign as of 2026-09-11. This is consistent with the tradecraft: the operation used legitimate vendor engineering software, legitimate embedded SSH, and the victims' own project files rather than distributable malware. Detection must be behavioral and baseline-driven, not signature-driven.Analyst assessment2026-09-11
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
The campaign converted American municipal water utilities into an instrument of state signalling during an active war. Timing is the argument: US bombing of Iran resumed 7–8 July 2026 after the Islamabad Memorandum ceasefire collapsed; an Iranian strike on a US base in Jordan killed two American service members over 18–19 July; the coordinated water-sector disruption followed on 26–27 July. The claiming party made the intent explicit — "our intention in attacking Minnesota was only to warn" of capability and willingness to retaliate against "any country that poses a threat to Iran" (APT Iran via Telegram, reported by Check Point Research). That is coercive signalling against civilian infrastructure, calibrated to demonstrate reach without causing casualties. A second-order consequence was domestic: attribution itself became contested political ground, with the President publicly downplaying Iranian responsibility and criticising Minnesota's governor, who countered that the administration was concealing the responsible party. CSIS assessed the administration would respond privately notwithstanding the public downplaying. The precedent set is that an adversary can impose visible domestic political cost on the US through low-sophistication attacks on small municipal utilities.
⬡ Technical / Capability
Three capability thresholds were crossed. First, scale without sophistication. Dozens of simultaneous OT compromises across four vendor families were achieved with no zero-day, no bespoke implant and no insider — only internet exposure, weak or default credentials, an unpatchable auth bypass, and the vendors' own engineering software. This overturns the working assumption that multi-victim OT effects require Stuxnet-class investment. Second, escalation from access to safety. The same actor's 2023 Unitronics activity was defacement and nuisance; the 2026 campaign reached into safety instrumented logic, disabling automatic shutdown and alarm functions while leaving the plant superficially normal — the actual object of OT attack, not a symbolic proxy for it. Third, project-file theft as a targeting prerequisite. Exfiltrating .ACD and equivalent files gave the actors a complete description of each plant's interlocks, enabling surgical rather than indiscriminate manipulation. Defensively, the campaign exposed the cellular-modem tier at remote assets as a systemic blind spot and forced the first authoritative federal guidance on detecting malicious Add-On Instruction modification.
⬡ Legal / Regulatory
The campaign reopened the water-sector regulatory fight that EPA lost in 2023. The Water Cyber Shield Act of 2026, introduced by Senators Klobuchar and Schiff in August 2026, would give EPA explicit authority to assess sector cyber threats, require utilities to remediate vulnerabilities EPA identifies, mandate cyber risk assessment within existing risk and resilience planning for large systems, and direct tiered cybersecurity standards developed with CISA, NIST, states and sector stakeholders — substantially the approach EPA attempted via sanitary-survey guidance in 2023 before withdrawing it under industry and state legal challenge. The Water Resources Development Act of 2026 (S. 4949) carries wastewater cybersecurity and digital infrastructure grant provisions; Congress separately enacted a temporary extension of expiring cyber authorities and EPA issued new guidance. CRS produced July 2026 Water System Cyber Incidents: Considerations for Congress (IF13298) and GAO published Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector (GAO-26-109159). No indictments, sanctions or other legal actions specific to this campaign had been announced as of 2026-09-11 — the Treasury sanctions against IRGC-CEC-linked individuals date to February 2024 and address the precursor Unitronics activity.
08
Attribution
ATTRIBUTION CONFIDENCE: [MEDIUM]
Attributed ToCyberAv3ngers (IRGC-CEC-affiliated); APT Iran co-claim
SponsorIran — IRGC Cyber Electronic Command (assessed)
Vendor DesignationsBauxite (Dragos) · Storm-0784 (Microsoft) · UNC5691 (Mandiant) · Hydro Kitten · Shahid Kaveh Group
Formal AttributionCampaign-level: YES — AA26-097A, 7 Apr 2026, seven USG agencies. Event-level (26–27 Jul): preliminary only
IndictmentsNone for this campaign. Treasury sanctions Feb 2024 address the Nov 2023 Unitronics precursor
Companion Actor Cardoutput/actors/2026-09-02_CYBERAV3NGERS.html
Primary EvidenceSeven-agency USG advisory naming Iranian-affiliated actors; TTP and victimology continuity with the Nov 2023 Unitronics campaign; adversary self-claim on Telegram; WaterISAC member communication; US investigator assessment reported by NYT
Competing Hypotheses(1) Opportunistic third parties exploiting the same exposed devices after public advisory; (2) multiple uncoordinated actors rather than one campaign; (3) hacktivist false claim of credit
What Would Change AssessmentA formal, event-level USG attribution statement for 26–27 Jul; indictment or sanctions naming individuals; forensic linkage of the Jul 2026 victim set to the AA26-097A infrastructure; or contrary evidence that the disruption was independent of the advisory-documented campaign

The assessment holds at [MEDIUM] because the campaign and the event are attributed to different standards, and conflating them would overstate the case. The eighteen-month PLC exploitation campaign carries a genuine formal attribution: AA26-097A was signed on 7 April 2026 by the FBI, CISA, NSA, EPA, DOE, US Cyber Command's Cyber National Mission Force and the Department of the Treasury, and names Iranian-affiliated, IRGC-CEC-linked actors operating as CyberAv3ngers. That is a seven-agency government statement backed by infrastructure indicators, and it is strong. The 26–27 July coordinated disruption is a weaker case: as of early August 2026 federal attribution for that specific event remained pending, with the New York Times reporting on 30 July that investigators assessed Iranian hackers were "probably responsible" while explicitly noting the assessment could change. A leaked WaterISAC member communication indicated Iranian-linked responsibility, and Minnesota officials — while calling the attacks coordinated — stated it was not clear whether all of them were carried out by the same actor.

The adversary self-claim is corroborating but is not, on its own, evidence. A group posting as APT Iran stated on Telegram that "the attack on Minnesota was the work of the CyberAv3ngers group and us, and we take direct responsibility for it" (via Check Point Research). Claims of credit in this space are cheap, frequently opportunistic, and routinely made by groups with no involvement; APT Iran's subsequent framing — that the attack was "only to warn" — reads as narrative construction as much as confession. Its evidentiary weight here comes from consistency with the independently documented campaign, not from the claim itself.

What genuinely supports the linkage is behavioral continuity. The July victim set matches the AA26-097A campaign's targeting logic precisely — internet-exposed PLCs, water sector priority, vendor-agnostic selection driven by exposure, Rockwell MicroLogix 1100/1400 named by the FBI, the same credential-abuse and logic-modification pattern documented four days earlier in the advisory update. The 2023 Unitronics precursor establishes that this actor specifically attacks US water utilities via exposed controllers with default credentials, and the February 2024 Treasury sanctions establish USG willingness to attribute that activity to IRGC-CEC-linked individuals by name. Dragos, which tracks the overlapping activity as BAUXITE, explicitly does not perform political attribution and states only that BAUXITE shows technical overlap with activity the US government assesses as aligned with CyberAv3ngers and IRGC-CEC — a caution worth preserving. The defensible conclusion is that AA26-097A activity is consistent with a CyberAv3ngers/BAUXITE-overlapping capability set, not that every vendor label maps one-to-one to a single organisational identity.

The competing hypotheses are not merely formal. The most credible alternative is contamination of the victim set: AA26-097A published a detailed description of exploitable, internet-exposed PLCs on 7 April and updated it on 22 July, and any capable opportunist could have acted on that public roadmap in the following days. Distinguishing state-directed action from copycat exploitation of a published advisory requires per-victim forensics tying intrusions to the advisory's IP infrastructure, which is not public. A secondary alternative — that "coordinated" overstates what was in fact several loosely related actor sets hitting the same soft target simultaneously — is supported by Minnesota officials' own hedging. Finally, the domestic political dispute over attribution should be excluded from the analytic picture entirely. The President's public rejection of Iranian responsibility and the Governor's counter-claim are political statements, not intelligence judgments, and neither constitutes evidence for or against the technical assessment. They are recorded here as part of the incident's history, not as inputs to it.

09
Historical Significance

This is the case that ended the "too fragmented to attack at scale" assumption about the US water sector. The sector's own defence had long been implicit in its structure: roughly fifty thousand community water systems, no common vendor, no common architecture, no central chokepoint, and therefore — the reasoning went — no way for an adversary to achieve broad simultaneous effect. July 2026 disproved it by attacking not a chokepoint but a shared condition. Internet exposure plus weak authentication is common to thousands of small utilities regardless of vendor, and it turned out to be as good as a monoculture. Any future assessment of sector resilience has to reason about shared configuration failure modes, not just shared technology.

It established safety-function suppression as live adversary practice against civilian infrastructure, not a theoretical worst case. Before this campaign, the canonical example of an adversary attacking safety systems was TRITON/TRISIS at a Saudi petrochemical plant in 2017 — a single, elaborately resourced operation against one industrial facility. AA26-097A documents disabling "critical shutdown and alarm logic" across a distributed victim set in American municipalities, achieved by editing the plant's own Add-On Instructions after stealing its project file. The distinction that will be taught is between attacking the process and attacking the protections on the process: one causes an incident, the other removes the layer designed to stop an incident from becoming a catastrophe. That the campaign produced no casualties is a fact about restraint and operator competence, not about capability.

It is the clearest available case study in advisory efficacy — and its limits. The full mitigation was published on 7 April 2026, sharpened on 22 July, cost nothing, and worked: utilities that disconnected internet-facing PLCs before 26 July were spared. Utilities that had not were disrupted. The four-day gap between the updated advisory and the attack is an almost experimental measurement of the distance between federal warning and municipal capacity to act, in a sector where EPA had already found more than 70% of inspected systems non-compliant with basic assessment requirements and possessed no authority to compel remediation. The enduring lesson is uncomfortable for the warning-based model of critical infrastructure defence: a perfect advisory delivered to an organisation without staff to read or act on it is not a control. Whether the Water Cyber Shield Act converts that lesson into authority remains unresolved as of this compile, and is the single most consequential open question the campaign leaves behind.

Finally, it is a data point in how cyber operations function inside a shooting war. Access built quietly over eighteen months was actioned within days of a lethal exchange, then publicly claimed as a warning rather than denied. That sequence — pre-position early, hold, trigger for political effect, claim for deterrent value — is a recognisable playbook, and its target selection tells defenders something durable: the adversary chose the infrastructure that maximises civilian salience and minimises escalation risk. Municipal water is visible enough to frighten a population and small enough to attack without crossing a threshold that compels a kinetic response. That calculation will not be unique to Iran, and it will not be unique to 2026.

10
References URLs are NOT defanged — navigate directly
CISA / FBI / NSA / EPA / DOE / CNMF / TREASURY
Accessed: 2026-09-11
PRIMARY SOURCE — Published 7 Apr 2026, updated 22 Jul 2026
MINNESOTA IT SERVICES
Accessed: 2026-09-11
CONTEMPORANEOUS — 28 Jul 2026
WATERISAC
Accessed: 2026-09-11
Source explicitly marked TLP:CLEAR by originator
TENABLE
Accessed: 2026-09-11
Includes Censys Apr 2026 exposure analysis (5,219 global / 3,891 US Rockwell hosts)
CYBERSECURITY DIVE
Accessed: 2026-09-11
CONTEMPORANEOUS — 20 Aug 2026; source for 12-state scope and APT Iran claim via Check Point Research
THE HACKER NEWS
Accessed: 2026-09-11
CONTEMPORANEOUS — Jul 2026
SECURITYWEEK
Accessed: 2026-09-11
CONTEMPORANEOUS — Jul 2026
FOX 9 MINNEAPOLIS
Accessed: 2026-09-11
CONTEMPORANEOUS — Jul 2026; Braham city administrator Kevin Stahl account
AL JAZEERA
Accessed: 2026-09-11
CONTEMPORANEOUS — 30 Jul 2026
THREAT BEAT
Accessed: 2026-09-11
Source for APT Iran Telegram claim language
GEORGIA RECORDER
Accessed: 2026-09-11
CONTEMPORANEOUS — 4 Aug 2026
ATLANTA NEWS FIRST
Accessed: 2026-09-11
CONTEMPORANEOUS — 4 Aug 2026
WASHINGTON POST
Accessed: 2026-09-11
CONTEMPORANEOUS — 10 Aug 2026
CSIS
Accessed: 2026-09-11
Source for 100+ targeted facilities figure and comparative impact assessment
CONGRESSIONAL RESEARCH SERVICE
Accessed: 2026-09-11
WIKIPEDIA
Accessed: 2026-09-11
TERTIARY — used for timeline corroboration and named officials only; primary claims sourced independently
WIKIPEDIA
Accessed: 2026-09-11
TERTIARY — geopolitical context framing only
WIKIPEDIA
Accessed: 2026-09-11
TERTIARY — conflict timeline corroboration (ceasefire collapse 7–8 Jul 2026)