Minnesota water system suffers a breach due to exposed access keys

, , ,

Last Updated: 2026-07-30T15:57:44Z

What’s Happening

On July 27, 2026, threat actors exploited a known vulnerability on a Rockwell Automation device and disrupted water treatment facilities in four counties in Minnesota, US.

Shieldworkz has a detailed writeup:

Tenable also has a decent writeup, providing broader threat context.

This activity is consistent with prior activity with Iran-aligned actors under the guise of “CyberAv3ngers,” although no direct evidence has yet emerged tying this activity to that group or any other.

Actions

The CVE used for initial access is CVE-2021-22681. This is a CWE-522 Insufficiently Protected Credentials vulnerability. Effectively it allows an unauthenticated attacker the ability to use an unprotected key to access the underlying logic processor.

It is unlikely your organization has a Rockwell Automation driven system. However, it is very likely you have some industrial control system or Internet of Things device with a hardware-encoded vulnerability like CVE-2021-22681.

Actions in cases like these are straightforward. You must reduce the attack surface. No user of any kind should have access to the device without network level protection. Strict tunneling and firewall rules are no fun, but there is absolutely no other protection that will do the job. Rockwell Automation confirmed this in their advisory, stating that there is no patch for mitigation and defense in depth is the only solution.

Notes

Rockwell Automation’s writeup requires an account to access, but WNE Security has a very nice writeup.

CISA updated an earlier advisory with new information from these attacks.

DysruptionHub has detailed writeups on select municpalities’ incidents:

2 Likes

And an FBI notification, which says that it wasn’t just Minnesota but water facilities in seven states:

https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions

1 Like

I think an important aspect to consider with this

April 2026 identified 5,219 internet-exposed hosts globally that responded to industrial protocols and self-identified as Rockwell Automation/Allen-Bradley devices. The United States accounts for 74.6% of global exposure, with 3,891 hosts.

-tenable

The observed exposure reflects weaknesses in governance, asset inventory, network architecture, and security policy enforcement rather than an inherent vulnerability in the devices themselves.

Coupling a device with a vulnerability that is also exposed creates a surefire method for actors to take action on an opportunity.

This scale of exposure is a clear indicator that organizational efforts across utilities are fragmented and incoherent at best, with one thing in common an inconsistent application of fundamental security practices.

I’m partial to this ICS dashboard to get a more comprehensive understanding of how appliances and services are operating.

1 Like

Whelp, if the NYT is covering it you know it’s real. :wrapped_gift: Article.

1 Like