>samit_hota
Back to security news
SN-2026-247HighMitigated

Iran-Backed Actors Target Over 30 Minnesota Water Utilities

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Minnesota community water systems, OT/ICS infrastructure
#news#vulnerability-disclosure#minnesota

An aggressive cyber campaign involving Minnesota water utility attacks has impacted more than 30 community water systems across the state. Attributed to likely Iran-backed threat actors, the incidents serve as a sobering reminder of the growing risks facing US critical infrastructure. The targeting primarily focuses on small municipal facilities that manage essential water treatment and distribution operations.

Mechanics of Water Sector Targeting

Iranian state-sponsored groups—most notably nexus actors like CyberAv3ngers—frequently target Industrial Control System (ICS) and Operational Technology (OT) assets using opportunistic, high-volume scanning rather than complex zero-day exploits. These actors systematically search for exposed Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), and Remote Terminal Units (RTUs) reachable via the public internet.

Attacks against this sector typically succeed because targeted environments expose control software or remote management protocols directly to the web using default manufacturer credentials. Once access is established, attackers often deface control panels, disrupt telemetry feeds, or alter controller configurations, forcing operators to take automated systems offline.

Operational Impact and Blast Radius

While individual community water systems serve limited populations, widespread targeting across dozens of facilities creates significant aggregate strain. In water treatment facilities, PLCs regulate chemical dosing, water flow, and pressure monitoring.

When an HMI or controller is compromised, the primary operational impact is a loss of real-time visibility and automated control. Operators are forced to switch to manual overrides to maintain water quality and distribution. The realistic blast radius involves operational downtime, localized boil-water notices out of an abundance of caution, and severe resource strain on small municipal teams, rather than immediate physical destruction of infrastructure.

Securing Exposed OT Systems

Defending municipal water systems requires closing basic operational security gaps that leave control networks exposed to public scanning. Utilities must audit all public-facing IP spaces to ensure PLCs, HMIs, and SCADA control panels are strictly disconnected from the public internet. Any required remote administrative access should be routed through a secure VPN protected by multi-factor authentication, and default manufacturer passwords on all OT devices must be changed immediately.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call