Minnesota water systems hit by PLC cyberattacks
A coordinated cyberattack hit the industrial control systems at more than 30 Minnesota water utilities on July 26 and 27, 2026. Attackers changed passwords and network addresses on the controllers that run pumps and treatment equipment, locking staff out and knocking one town's water plant offline.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Not confirmedLast checked 3 days ago
- Affected versions
- RSLogix 5000 Versions 16 through 20; Studio 5000 Logix Designer: Versions 21 and later; CompactLogix 1768 and 1769 and 5370 and 5380 and 5480+5 more
- Weakness
- CWE-522Insufficiently Protected Credentials
- Exploit likelihood
- 64% in 30 daysEPSS, higher than 99% of known flaws
- Affects
- Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Mar 5, 2026
- Federal fix deadline
- Mar 26, 2026
How it works
The attackers reached programmable logic controllers, the industrial computers that run pumps, valves, and treatment equipment, directly over the internet, often through default logins or undocumented remote-access modems installed by contractors, then changed the controllers' passwords and IP addresses so plant staff lost access to their own equipment.
What to do
Water and wastewater utilities should check whether any programmable logic controllers, remote-access gateways, or cellular modems installed by operators, vendors, or integrators are reachable directly from the internet, since CISA says this activity has hit utilities in at least seven states.
Update Minnesota through its normal update channel, then confirm the installed version matches the newest vendor release.
Technical details
Affected software: Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers
CISA's alert centers on CVE-2021-22681, a critical (outdated CVSS versions) authentication-bypass flaw in Rockwell Automation MicroLogix 1400 controllers that had no patch for years because industrial systems are hard to take offline for updates. Since March 2026, Iranian-affiliated actors have actively exploited it, and CISA has since observed the same internet-exposed-PLC targeting expand beyond Rockwell to Schneider Electric and Siemens devices, including theft of PLC project files that reveal a plant's programmed logic. The Minnesota incident, hitting 30-plus utilities in one weekend, is the clearest public example of this campaign against small and mid-size water systems.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- us-cert.cisa.gov · icsa-21-056-03 Third Party Advisory US Government Resource
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource
- mn.gov · blog SecurityAffairs
- brahammn.gov · index.asp SecurityAffairs
- mapleplainmn.gov · press-release-cyber-security-incident SecurityAffairs
- plymouthmn.gov · 542 SecurityAffairs
- southstpaulmn.gov · 900 SecurityAffairs
- tenable.com · coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know SecurityAffairs
- cisa.gov · cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs SecurityAffairs
- fbi.gov · malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions SecurityAffairs
- rockwellautomation.com · advisory.SD1790.html SecurityAffairs
- infosec.exchange · @securityaffairs SecurityAffairs
- securityaffairs.co · wordpress SecurityAffairs
- thehackernews.com · openai-agent-used-exposed-credentials.html TheHackerNews
- bleepingcomputer.com · amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info BleepingComputer
- wid.cert-bund.de · securityadvisory CERT-Bund Advisories