Between 26 and 27 July 2026, a coordinated attack disrupted water and wastewater operations across more than 30 Minnesota communities. One plant was shut down. Others were forced to manual operation, which means people physically operating equipment that is normally controlled remotely.
The FBI has since reported that utilities in at least seven states have described incidents involving operational technology devices, including Rockwell Automation and Allen-Bradley programmable logic controllers exposed directly to the internet.
The Vulnerability Is Five Years Old And Cannot Be Patched Out
CVE-2021-22681 was added to the US Known Exploited Vulnerabilities catalogue in March 2026 following documented in-the-wild exploitation. The identifier tells you the year it was published. It has been available for exploitation for the whole of that interval.
The reason it persists is not negligence in the ordinary sense. Industrial controllers are not laptops. Applying firmware to a PLC that regulates a treatment process requires taking the process offline, and a small municipal utility may have one maintenance window a year, no test environment, and nobody on staff whose job is patching.
Manual Operation Is The Good Outcome
It is worth being clear about what "forced to manual operation" means, because it reads as failure and is closer to the opposite. It means the plant retained people who know the process, physical controls that still work without the automation layer, and procedures for running that way.
Utilities that have automated more aggressively, or lost the staff who remember manual operation, do not have that fallback. The Minnesota outcome — disruption rather than contamination or sustained outage — depended on capability that is expensive to keep and invisible until the day it is needed.
Why These Devices Are Reachable At All
A controller ends up on the public internet because somebody needed to see it from home at two in the morning, and the alternative — a maintained remote access path with authentication — costs money a water district does not have.
That is the honest version of this story. The technical fix is well understood and has been published repeatedly. It is not being done because the sector is composed largely of small public utilities with rate-capped budgets, no security staff, and a regulator that does not fund what it asks for.
Compiled from the FBI alert, CISA catalogue material and public reporting, listed below. Attribution for the Minnesota activity is described in some reporting as Iranian-affiliated; we reproduce that as reported and do not assert it independently. We have not reviewed utility telemetry. Corrections: corrections@forensicpost.com.
- Malicious cyber actors targeting water and wastewater sector internet-facing programmable logic controllers, causing operational disruptionsFBI
- Coordinated attacks on Minnesota water utilities highlight risks from internet-exposed industrial control systemsField Effect
- CISA urges water sector to protect OT after coordinated attacks on PLCsSecurityWeek