Recent attacks on water and wastewater systems in Minnesota, Michigan, Canada, and elsewhere show that exposed PLCs, HMIs, cellular modems, and weak remote-access setups can allow attackers to disrupt physical operations without advanced malware. The incidents are technically similar to an Iranian-affiliated PLC campaign, while separate claims by NoName057(16) and Z-Pentest show that hacktivists are also targeting water infrastructure. #MicroLogix1100 #MicroLogix1400 #NoName05716 #ZPentest #CyberAv3ngers #Unitronics
Keypoints
- More than 30 Minnesota community water systems were targeted in coordinated attacks on July 26â27, 2026.
- Related activity was reported in at least seven U.S. states, with Michigan identifying nine affected water systems.
- Attackers remotely accessed exposed PLCs, changed IP addresses and passwords, and in some cases modified project files or ladder logic.
- Observed impacts included loss of pressure, flooding, communications outages, boil-water notices, and temporary manual operations.
- The Minnesota incidents share similarities with an Iranian-affiliated PLC campaign documented in Joint Cybersecurity Advisory AA26-097A, but attribution remains unconfirmed.
- Publicly confirmed and claimed incidents in Ontario and Quebec show that pro-Russian hacktivists are also probing water-sector OT systems.
- The report stresses that insecure exposure, legacy equipment, and weak third-party remote access can be enough to disrupt water operations without custom ICS malware.
MITRE Techniques
- [T1190 ] Exploit Public-Facing Application â Attackers abused internet-facing PLCs and remote-access paths to reach OT devices (âinternet-facing PLCsâ and âexposed controllersâ).
- [T1021 ] Remote Services â The actors used remote access to connect to controllers and infrastructure over exposed services (âremote-access servicesâ and âremotely accessed exposed PLCsâ).
- [T1078 ] Valid Accounts â Attackers changed passwords and likely leveraged credentials or weak authentication to maintain access (âchanged their IP addresses and passwordsâ).
- [T1606 ] Forge Web Credentials / Password Manipulation â Credential and access settings on PLCs were altered to block operator access (âchanged their IP addresses and passwordsâ).
- [T0831 ] Manipulation of Control â The campaign modified PLC logic and control behavior to affect physical processes (âmodified control logicâ and âchanged ladder logicâ).
- [T0829 ] Remote System Discovery â Operators identified malicious interaction across multiple sites and devices, indicating reconnaissance of exposed OT assets (âmultiple victimsâ and âsimilar hardware and remote-access architecturesâ).
- [T0883 ] Establish Accounts / Persistence via Configuration Change â Attackers used configuration changes on controllers and modems to preserve access or disrupt recovery (âmodified PLC project filesâ and âDropbear SSH on a victim modemâ).
- [T0868 ] Alarm Suppression â The advisory notes changes that disabled critical alarms and shutdown logic (âdisabled critical alarms and shutdown logicâ).
- [T0886 ] Remote Services: SSH â Dropbear SSH was used on a victim modem to establish remote access (âDropbear SSH on a victim modemâ).
Indicators of Compromise
- [IP addresses ] PLC access and configuration changes were made on exposed controllers â changed IP addresses, public IP addresses
- [File names / project files ] Controller logic and engineering project artifacts were modified or reviewed â PLC project files, ladder logic files
- [Device / product names ] Affected and targeted OT equipment families â Rockwell Automation MicroLogix 1100, MicroLogix 1400, CompactLogix, Micro850, Schneider Electric Modicon M340, Siemens S7-1200
- [Software names ] Legitimate engineering tools used in the activity â Studio 5000 Logix Designer, EcoStruxure Control Expert, Siemens TIA Portal, RSLogix 500, RSLogix 5000, LogixPro 500
- [Network ports ] OT protocols and remote-access ports observed in the campaign â TCP 44818, 2222, 102, 502, and port 22 (SSH)
- [Organizations / infrastructure names ] Entities and infrastructure cited in the incidents â Minnesota IT Services, CISA, FBI, EPA, Braham, Plymouth, South St. Paul, Maple Plain, Saint-NoĂŤl
- [Domains / hosting / infrastructure ] Remote-access and third-party infrastructure were discussed as attack paths â vendor-maintenance interfaces, cellular modem services, third-party network configurations