Minnesota water systems hit by PLC cyberattacks

Published July 29, 2026 CVE-2021-22681

A coordinated cyberattack hit the industrial control systems at more than 30 Minnesota water utilities on July 26 and 27, 2026. Attackers changed passwords and network addresses on the controllers that run pumps and treatment equipment, locking staff out and knocking one town's water plant offline.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Not confirmedLast checked 3 days ago
Affected versions
RSLogix 5000 Versions 16 through 20; Studio 5000 Logix Designer: Versions 21 and later; CompactLogix 1768 and 1769 and 5370 and 5380 and 5480+5 more
Weakness
CWE-522Insufficiently Protected Credentials
Exploit likelihood
64% in 30 daysEPSS, higher than 99% of known flaws
Affects
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Mar 5, 2026
Federal fix deadline
Mar 26, 2026

How it works

The attackers reached programmable logic controllers, the industrial computers that run pumps, valves, and treatment equipment, directly over the internet, often through default logins or undocumented remote-access modems installed by contractors, then changed the controllers' passwords and IP addresses so plant staff lost access to their own equipment.

What to do

Water and wastewater utilities should check whether any programmable logic controllers, remote-access gateways, or cellular modems installed by operators, vendors, or integrators are reachable directly from the internet, since CISA says this activity has hit utilities in at least seven states.

Update Minnesota through its normal update channel, then confirm the installed version matches the newest vendor release.

Technical details

Affected software: Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

CISA's alert centers on CVE-2021-22681, a critical (outdated CVSS versions) authentication-bypass flaw in Rockwell Automation MicroLogix 1400 controllers that had no patch for years because industrial systems are hard to take offline for updates. Since March 2026, Iranian-affiliated actors have actively exploited it, and CISA has since observed the same internet-exposed-PLC targeting expand beyond Rockwell to Schneider Electric and Siemens devices, including theft of PLC project files that reveal a plant's programmed logic. The Minnesota incident, hitting 30-plus utilities in one weekend, is the clearest public example of this campaign against small and mid-size water systems.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator