Last Updated: 2026-07-30T15:57:44Z
What’s Happening
On July 27, 2026, threat actors exploited a known vulnerability on a Rockwell Automation device and disrupted water treatment facilities in four counties in Minnesota, US.
Shieldworkz has a detailed writeup:
Tenable also has a decent writeup, providing broader threat context.
This activity is consistent with prior activity with Iran-aligned actors under the guise of “CyberAv3ngers,” although no direct evidence has yet emerged tying this activity to that group or any other.
Actions
The CVE used for initial access is CVE-2021-22681. This is a CWE-522 Insufficiently Protected Credentials vulnerability. Effectively it allows an unauthenticated attacker the ability to use an unprotected key to access the underlying logic processor.
It is unlikely your organization has a Rockwell Automation driven system. However, it is very likely you have some industrial control system or Internet of Things device with a hardware-encoded vulnerability like CVE-2021-22681.
Actions in cases like these are straightforward. You must reduce the attack surface. No user of any kind should have access to the device without network level protection. Strict tunneling and firewall rules are no fun, but there is absolutely no other protection that will do the job. Rockwell Automation confirmed this in their advisory, stating that there is no patch for mitigation and defense in depth is the only solution.
Notes
Rockwell Automation’s writeup requires an account to access, but WNE Security has a very nice writeup.
CISA updated an earlier advisory with new information from these attacks.
DysruptionHub has detailed writeups on select municpalities’ incidents:
