US Water Attacks Hit 12 States, NY Funds Defense
Water attacks in the U.S. affected at least 12 states. New York is funding 153 systems as Latin America exposes energy gaps.
Between July 26 and 27, 2026, a coordinated campaign hit more than 30 community water systems in Minnesota, disrupting operational technology, SCADA communications, cellular telemetry, and visibility into valves, pumps, and remote controls. The wave later spread to other states and triggered federal alerts from CISA, the FBI and the EPA, which warned about rising activity against internet-exposed PLCs and other OT assets in the water and wastewater sector. Public evidence compiled in the source points to intrusions centered on industrial devices reachable from the public internet, with password changes, IP address manipulation, blocked remote access and, in some cases, forced manual operation. The material also documents boil-water notices in some areas, low pressure and temporary shutdowns of wells or plants, although there is no public evidence of deliberate contamination or a broader service collapse.
The case remains unresolved on attribution. Several news reports cited investigators who linked the activity to Iran-backed actors, especially CyberAv3ngers, but that connection is presented in multiple items as a theory or suspicion, not an official conclusion. Technical analysis in the source also agrees that the observed method did not rely on a unique zero-day. Instead, it abused direct internet exposure, weak credentials, insecure remote services and legitimate PLC engineering software. CISA’s July 22 update to advisory AA26-097A expanded the focus to Unitronics, Schneider Electric, Siemens and Rockwell Automation PLCs, while its July 30 alert urged operators to remove PLCs from public exposure, use gateways or VPNs, change default passwords and review unauthorized configurations.
In parallel, New York responded with a concrete budget decision. Governor Kathy Hochul announced more than $9 million in SECURE program funding for 153 drinking water and wastewater systems, covering cybersecurity assessments, technical upgrades and free assistance from the Environmental Facilities Corporation. The state had already imposed minimum standards in March, including mandatory training, incident reporting, risk-based protections and a designated cybersecurity lead for large systems. The move points to a regulatory response that combines funding, compliance and technical support, in contrast to the regulatory lag the source identifies in Latin America.
The Oldelval case in Argentina serves as a regional mirror. The operator of the country’s main oil transportation system reported an incident in its administrative systems, described by several reports as ransomware or as a claim associated with groups such as TheGentlemen and Incransom. The company said crude transport was not interrupted, SCADA systems were not reached and the episode came under control. Even so, the source uses the case to show a governance gap: Argentina lacks a comprehensive cybersecurity framework specific to critical energy infrastructure, and its current rules do not match Chile’s, which already has a law, notification deadlines, vital operator designations and a formal list of critical sectors that includes water and sanitation.
Executive Summary
Between July 26 and 27, 2026, a coordinated campaign hit more than 30 community water systems in Minnesota. According to the consolidated material, it affected operational technology, interrupted automated SCADA communications, disabled cellular telemetry controllers, and compromised remote access to valves, pumps and treatment equipment. The activity did not stay confined to one state. In the days that followed, the compiled coverage from CBS News, BBC News, Reuters, CNN, Associated Press, NBC News, The Guardian, Al Jazeera and others expanded the reported scope to at least seven states, and later to at least a dozen, with recurring mentions of Michigan, Minnesota, Georgia, New Jersey and South Dakota.
The public evidence in the research points to a fairly consistent operational pattern. There are no signs that ransomware was the main vector in the U.S. water campaign. There is also no public indication of custom malware or a specific zero-day exploit as the dominant mechanism. What repeats instead is abuse of internet-exposed OT devices, access to PLCs and industrial components through publicly reachable interfaces, remote password changes, IP address changes and blocking of operator access, with direct consequences for visibility, monitoring degradation and the need to switch to manual operation. CISA summarized that pattern in its July 30 alert, recommending that operators remove exposed PLCs and other OT equipment from the internet, use secure gateways or VPNs, change default credentials and review unauthorized configurations.
On July 22, CISA had already updated advisory AA26-097A to warn about cyber actors linked to Iran exploiting Unitronics PLCs with HMI, then broadened the scope to Schneider Electric, Siemens and Rockwell Automation equipment. According to the source, that update also added exfiltration of PLC project files and detection guidance for manipulation of reusable code modules. Several media outlets also reported suspicion that the campaign could be tied to Iran-backed hackers or the bogus CyberAv3ngers group. That attribution, however, remains in the realm of hypothesis or journalistic inference. No source in the package presents a definitive official attribution.
The operational impact was real, but contained. Some wells and treatment plants were temporarily offline, pressure dropped, boil-water notices were issued, and in certain cases operators moved immediately to manual control. At the same time, the sources agree there is no public evidence of deliberate contamination of drinking water or a broad service outage. The clearest reading is that this was a sabotage and disruption campaign against the OT layer, not an intrusion aimed at mass data theft or a traditional ransomware event.
The institutional response was also fast. Minnesota activated a state cybersecurity response with support from MNIT, the state health department and federal agencies. New York, by contrast, turned the threat into policy and budget. On August 3, Governor Kathy Hochul announced more than $9 million in SECURE grants for 153 drinking water and wastewater systems, aimed at cybersecurity assessments, technical upgrades and free assistance from the Environmental Facilities Corporation. The decision builds on minimum standards introduced in March, including mandatory training, incident notification, risk-based protections and a cybersecurity lead for large systems.
From a regional perspective, the Oldelval case in Argentina is the most useful contrast. The company reported an incident in its administrative systems, with crude transport continuing uninterrupted and systems later restored. But the source also notes that Argentina lacks a comprehensive cybersecurity law for critical energy infrastructure, and that the region shows uneven governance, with sector frameworks that are incomplete or fragmented. Chile stands at the other end of the spectrum, with a specific law, strict notification deadlines to the National CSIRT, designated vital operators and an explicit list of critical sectors that includes drinking water and sanitation.
Context and Background
The campaign against water systems in the United States did not emerge in a vacuum. The source shows a chain of prior alerts that helps explain why the attack surface was already well understood. On July 22, 2026, CISA updated advisory AA26-097A to warn that actors linked to Iran were exploiting PLCs across multiple critical infrastructure sectors, including water, wastewater and energy. That update already described activity against internet-exposed PLCs, with traffic observed on common industrial ports such as 22, 102, 502, 2222 and 44818. It also included concrete mitigations: keep PLCs off the internet, route remote access through secure gateways or VPNs, require MFA on access paths and segment OT communications tightly.
Shortly afterward, on July 30, CISA issued a sector-specific alert for water and wastewater. The agency said threat actors were significantly increasing activity against PLCs and other OT assets, and noted tactics such as password changes to lock out operators, IP address changes to disconnect PLCs from the network and manipulation of systems that forced some utilities into manual operation. The warning was no longer abstractly preventive. It was responding to incidents that had already occurred in the prior days and, according to the FBI, EPA and CISA, had affected at least seven states.
The source also places a key technical precedent outside the water sector. Tenable’s analysis notes that CISA added CVE-2021-22681 to the Known Exploited Vulnerabilities catalog in March 2026 after confirming use by Iran-linked actors. The flaw affects Rockwell Automation Logix controllers and allows an attacker to impersonate Studio 5000 Logix Designer engineering software to send malicious commands. CastleRockSky connects that issue to the Rockwell Automation and Allen-Bradley ecosystem that appears in the July campaign. That is not proof of authorship, but it does point to technical continuity between earlier campaigns and the Minnesota episode.
There are also direct operational precedents. Jim Guckin’s blog recalls that between late 2023 and early 2024, a group attributed to the same environment compromised at least 75 Unitronics Vision Series PLCs with HMI in critical infrastructure in the United States, Israel, the United Kingdom and Ireland, taking advantage of default passwords and direct internet exposure. The important point in that precedent is not the group name, but the persistence of the same pattern: industrial devices reachable from the public internet, weak credentials and a disruptive capability that does not require first entering traditional IT.
At the same time, technical notes from LevelBlue, Rescana and Shieldworkz converge on a similar reading. The focus was not phishing or desktop ransomware, but the OT layer: PLCs, HMIs, cellular modems, industrial routers, telemetry gateways and poorly protected remote access services. Rescana classifies the initial vector as Internet Accessible Device, MITRE ATT&CK for ICS T0883. LevelBlue adds that the public evidence does not point to a specific zero-day as the main entry point, but rather to the use of legitimate engineering software and standard industrial protocols on insecure controllers. Shieldworkz, meanwhile, argues that the synchronized outages across more than 30 systems would fit better with a shared dependency, such as an MSP, a centralized remote access platform or cellular gateways, than with separate intrusions against each utility.
This is why the state response in the United States did not stop at the single incident. New York, although not listed as affected in the campaign, chose to invest in the sector with preventive resilience in mind. The state had already introduced minimum cybersecurity standards for water utilities in March, and the August 3, 2026 announcement is aimed precisely at implementing those requirements. The contrast with Latin America is stark. The material on Argentina and Chile shows two different regulatory paths, one with robust frameworks and reporting obligations, the other with a more fragmented architecture that can help define crimes or create committees, but is still too weak to impose minimum controls on private operators of critical infrastructure.
Key Facts Table
| Date | Fact | Source | Confidence |
|---|---|---|---|
| 2026-07-22 | CISA updated advisory AA26-097A and warned that Iran-linked actors were exploiting PLCs in critical infrastructure, including water and wastewater. | CISA | Confirmed |
| 2026-07-22 | The advisory documented traffic to PLCs on common industrial ports and recommended removing PLCs from the internet and using secure gateways with MFA. | Cyberpress | Confirmed |
| 2026-07-23 | Oldelval appeared in ransomware listings associated with TheGentlemen. | Dexpose, Darkfield, Ransomware.live | Source attribution, unconfirmed |
| 2026-07-26 | More than 30 community water systems in Minnesota were attacked between July 26 and 27. | Minnesota IT Services, Reuters, USA Today | Confirmed |
| 2026-07-26 | Shieldworkz described disruptions to SCADA communications, cellular telemetry and OT control in several Minnesota municipalities. | Shieldworkz | Confirmed |
| 2026-07-27 | Rescana identified T0883, Internet Accessible Device, as the initial vector consistent with the campaign. | Rescana | Confirmed |
| 2026-07-28 | MNIT activated a state cybersecurity response to support more than 30 affected systems. | MNIT | Confirmed |
| 2026-07-30 | The FBI, EPA and CISA issued a joint alert for the water and wastewater sector. | CBS News, ABC News, NBC News | Confirmed |
| 2026-07-30 | CISA published a sector-specific alert about activity against PLCs in the water sector. | CISA | Confirmed |
| 2026-07-31 | NBC News reported the operation had all the signs of an Iranian campaign, though without official attribution. | NBC News | Unconfirmed attribution |
| 2026-08-01 | AP reported new cases in Michigan and said systems were operating safely. | Associated Press | Confirmed |
| 2026-08-03 | New York announced more than $9 million in SECURE grants for 153 water and wastewater systems. | Governor’s Office, CBS6 Albany | Confirmed |
| 2026-08-04 | BBC News, The Guardian and others expanded the reported scope to at least seven states and then a dozen. | BBC News, The Guardian, CBS News | Confirmed |
| 2026-08-05 | CBS News reported incidents in at least 12 states, with suspected links to Iran-backed hackers. | CBS News | Unconfirmed attribution |
| 2026-08-06 | Datatrends Latam described the Oldelval case as RaaS ransomware and used it to discuss regional governance gaps. | Datatrends Latam | Confirmed |
Timeline of the Operation
| Date | Event | Actor / Vector | Verified Source |
|---|---|---|---|
| 2026-07-22 | AA26-097A advisory updated on exposed PLCs and Iran-linked actors. | CISA, Unitronics PLCs, internet-exposed OT | CISA |
| 2026-07-26 | Visible start of the campaign in Minnesota against more than 30 community water systems. | Exposed OT devices, remote SCADA access | Reuters, Minnesota IT Services, USA Today |
| 2026-07-26 | SCADA communications, cellular telemetry and wellhead and treatment controls are disrupted in several municipalities. | SCADA, cellular controllers, valves and pumps | Shieldworkz |
| 2026-07-27 | Rescana describes T0883 and says there are no public signs of phishing or ransomware in the water campaign. | Internet Accessible Device, exposed OT | Rescana |
| 2026-07-28 | MNIT activates a state response with health and federal agencies. | State and federal coordination | MNIT |
| 2026-07-29 | Governing and other outlets report that public attribution remains open. | Ongoing investigation | Governing |
| 2026-07-30 | FBI, EPA and CISA issue a joint alert about remote access to water infrastructure in seven states. | FBI, EPA, CISA | CBS News |
| 2026-07-30 | CISA issues a sector-specific alert and asks operators to remove exposed PLCs from the internet. | PLCs, OT, public exposure | CISA |
| 2026-07-31 | NBC News and ABC News detail attackers changing passwords, changing IPs and forcing manual operation. | Credential changes, operator lockout | NBC News, ABC News |
| 2026-08-01 | AP reports expansion to Michigan and confirms systems are operating safely. | Additional affected states | Associated Press |
| 2026-08-03 | New York announces more than $9 million for 153 water and wastewater systems. | SECURE program | Governor’s Office |
| 2026-08-04 | BBC News and The Guardian confirm there is no reported evidence of water contamination. | Contained operational outcome | BBC News, The Guardian |
| 2026-08-05 | CBS News raises the state count to at least 12 and mentions a possible link to Iran-backed hackers. | Preliminary attribution | CBS News |
| 2026-08-06 | Datatrends Latam connects the Oldelval case to governance gaps in Latin American energy infrastructure. | Ransomware, governance, administrative systems | Datatrends Latam |
Attack Chain and TTPs
The Minnesota campaign, based on the available material, followed a relatively simple but effective sequence: internet-exposed access, credential or network parameter changes, loss of operator visibility and degradation of OT control. There is no sign of a long espionage intrusion or complex lateral movement inside office networks. The center of gravity is industrial operations technology.
The most consistent initial vector, according to Rescana, is T0883, Internet Accessible Device. That classification fits several details in the package. Shieldworkz referred to industrial cellular modems and routers, including Sierra Wireless, Cradlepoint and Moxa equipment, with default credentials, unauthenticated remote execution issues or weak VPN tunnels. LevelBlue, along the same lines, said the public evidence points to PLCs, HMI interfaces, cellular modems, poorly protected remote access services and third-party configurations in OT environments. CISA, for its part, described cases in which attackers changed passwords to block operators and altered IP addresses to isolate PLCs from the network.
That pattern suggests operational denial more than immediate physical destruction. When an attacker can change credentials, force disconnects or disable alarms, the practical result is to blind the operator. ES News, citing the FBI, said exactly that attackers can leave operators without visibility by changing passwords or disabling alarms. That explains why several utilities had to return to manual control. It also explains why boil-water notices were issued in some cases even though there was no evidence of contamination. The operational problem was not chemical. It was uncertainty about process status and the reliability of remote monitoring.
Cellular telemetry appears as a recurring support point. Shieldworkz said cellular telemetry controllers and automated SCADA communications were compromised. That kind of infrastructure typically sits between the plant floor and the central operator. If that layer is cut, the system still exists, but operations become degraded. Technicians lose telemetry, alarms and the ability to act quickly. That drives the move to manual operation and the need for local physical inspection, which is also reflected in Quadratín, NBC News and ABC News.
As for equipment families, the material points to a clear line. CISA first spoke about Unitronics PLCs with HMI. Then Tenable and CastleRockSky broadened the focus to Schneider Electric, Siemens and Rockwell Automation, and CastleRockSky emphasized CVE-2021-22681 in Rockwell Automation Logix controllers. DeNexus, more specifically, identified the publicly affected devices as Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400. That convergence suggests the campaign was not limited to a single brand, but rather to an ecosystem of exposed OT assets with similar exploitation and operational handling.
At the TTP level, the case can be reconstructed as follows: reconnaissance of exposed assets, access through internet-reachable devices, interference with authentication and addressing, loss of remote control, disruption of OT communications and a shift to manual operation. The material contains no public indicators of data exfiltration in the U.S. water campaign. There are also no ransom payments or ransomware notes. That distinction matters because it keeps this episode separate from the Oldelval case, where there are references to ransomware or leak sites, although the exact attribution is not closed and the company said physical pipeline operations were not affected.
Technical TTP Matrix
| TTP / Technique | Description | Source |
|---|---|---|
| T0883 | Exploitation of internet-exposed OT devices as a consistent initial vector | Rescana |
| Public PLC exposure | PLCs and other OT equipment directly connected to the internet | CISA, Cloudlink Tech |
| Default or weak credentials | Password changes or abuse to block operator access | CISA, IndianWeb2, Jim Guckin |
| IP manipulation | Changing IP addresses to disconnect PLCs from the network | CISA |
| Alarm suppression | Disabling alarms to leave operators without visibility | ES News |
| Forced manual operation | Temporary switch of utilities to manual mode | Quadratín, El Comercio, ABC News |
| SCADA compromise | Disruption of automated supervision and control communications | Shieldworkz, TechRadar |
| Compromised cellular telemetry | Disabling telemetry controllers and industrial cellular links | Shieldworkz |
| Use of legitimate engineering software | Interaction with PLCs through standard tools and protocols | LevelBlue |
| Exfiltration of PLC project files | Detection added by CISA and Tenable in the advisory update | Tenable, CISA |
| CVE-2021-22681 | Authentication bypass in Rockwell Automation Logix controllers | CastleRockSky, Tenable |
| Common industrial ports | 22, 102, 502, 2222 and 44818 observed in malicious traffic | Cyberpress |
Regional Impact
Regional Overview
The material is not limited to isolated incidents. It also shows how the U.S. campaign reshaped regulatory and investment conversations across the region. The American case works as a concrete demonstration of a very specific OT threat, while the Latin American cases serve to measure institutional capacity to absorb similar incidents. In that contrast, Chile appears to have the strongest regulatory maturity, Argentina still shows visible governance gaps, Uruguay has a monitoring ecosystem and national response teams, and Peru, Colombia and Brazil appear as markets that echoed the coverage without adding local evidence of physical impact on their own water infrastructure.
In the United States, the combination of a federal alert, debate over attribution and New York’s budget response shows that the impact was not only technical. It was also regulatory. A state that was not attacked decided to fund 153 utilities to close operational security gaps, with caps of $50,000 for assessments and $100,000 for improvements, plus technical assistance from the EFC. That grant structure rests on minimum standards already in force. The practical effect is twofold. It strengthens basic hygiene, and it institutionalizes a compliance process that forces asset inventory, configuration fixes and incident reporting.
The technical details matter because the attack hit the layer that moves water, not just the administrative perimeter. The material insists that water quality was not compromised. That does not reduce the seriousness. A system can keep delivering safe water and still lose telemetry, remote control and fast response capability. The business impact, operational pressure and recovery cost are real. On top of that, switching to manual operation for hours or days increases staffing burden and raises the risk of human error.
Argentina
The Oldelval case is the most useful Argentine example because it mixes a verified incident, corporate response and a regulatory gap. Oldelval informed the CNV of a cybersecurity incident in its administrative systems. The company said crude transport was not affected, that it activated its internal protocol, recovered systems and returned to normal operations. Several reports repeat that line and note that the SCADA controlling pumping and transport was not reached.
Even so, the way the source treats the case is revealing. Datatrends Latam classifies it as RaaS ransomware and uses it as an example of weak governance in energy infrastructure. Ransomware.live, Dexpose, Darkfield and other trackers list Oldelval on leak sites associated with TheGentlemen or Incransom, but those entries do not amount to an official confirmation of attribution. What remains firm is that Argentina does not have a comprehensive cybersecurity law specific to critical energy infrastructure. Law 26,388 criminalizes cyber offenses, but it does not set protection, notification or minimum-standard obligations for private operators. Administrative Decision 641/2021 creates a committee and guidelines for the public sector, but it does not solve the private critical infrastructure layer.
That gap matters beyond Oldelval. Masindustrias describes a highly uneven OT maturity level, with legacy technologies and limited real-time visibility. LACNIC, by contrast, shows that Argentina does have multiple CSIRTs and CERTs, including specialized capacity for critical sectors. The problem is not a total absence of response. It is the fragmentation of responsibilities and the lack of a binding sector framework that forces prevention, reporting and remediation under common criteria.
Chile
Chile is the most orderly counterexample in the source. The Library of Congress and Zynap summarize a cybersecurity law that covers electricity, fuels, drinking water and sanitation, as well as telecommunications and digital infrastructure. The definition of a vital operator explicitly includes institutions that provide drinking water and sanitation services. Exempt Resolution 187 reinforces that reading and ties the designation to the functional dependence of the service and the possible impact on physical operations or critical information.
The operational center is timing. Early warning to the National CSIRT must be issued within three hours. The initial update is due within 72 hours, or within 24 hours if the operator is vital and essential services are compromised. The final report must be filed within 15 calendar days. Ley21663.info adds that the criterion of significant effect, which triggers the notification duty, covers continuity of essential service, physical integrity or health of people, and personal data processing. In other words, Chile already has a reporting mechanism that fits the pace of OT incidents, where every hour matters.
Growmktech and Mister-IT Tech round out the picture with technical measures. OT segmentation into security zones, logical separation, anomaly monitoring in SCADA and PLCs, documented risk management, continuity and recovery. In Chile, the issue is not left at the level of principle. There is a framework, a classification of operators and a notification path already described in technical and legal materials.
Uruguay
Uruguay appears in the research less as an incident case and more as an institutional architecture. CERTuy is listed as the national incident response team, with public statistics on information security incidents. TIUruguay presents water treatment plants as part of the set of high-priority infrastructures under constant monitoring, alongside energy, telecommunications, transportation, finance and health. Convergint, meanwhile, describes specific services for water and wastewater, including secure access, environmental monitoring and cyber-physical threat detection.
That does not mean immunity. It means there is an institutional and market conversation around critical infrastructure. Visibility is better than in other countries in the bloc, but the source does not include a Uruguayan incident comparable to Minnesota or Oldelval in this investigation. What it does include is structure, a national CERT, semiannual statistics and a market that already sells monitoring for water and wastewater services.
Brazil
Brazil appears not through a domestic case, but as a regional amplifier of the U.S. story. Tecmundo and CNN Brasil carried the Minnesota campaign as a coordinated attack on more than 30 water systems. O Globo added that there were no signs of water alteration or risk to consumption. The value of these reports is contextual. They show that the incident was read in the region as an OT event of international scope, not just another U.S. news item.
Colombia
In Colombia, the source uses two layers. First, coverage of the U.S. attack by El Colombiano and other outlets, with emphasis that there are no signs of altered water or public risk. Second, the regulatory reading from Datatrends Latam, which notes Law 1581 on personal data protection and the SIC as data authority, but no specific cybersecurity regulation for energy infrastructure comparable to NIS2. The contrast is useful because it shows that even with personal data regulation, a country can still lack a dedicated framework for protecting critical OT infrastructure.
Peru
Peru appears as another country where the case circulated through media. El Comercio picked up the joint FBI and EPA alert and reported that some plants switched to manual operations without service interruption. WWWhatsNew, MarketScreener, Reuters and other outlets cited in the research reinforced the same framing. Peru’s contribution to the dossier is not a local incident, but the way regional coverage conveyed the scale of the event.
United States
This is the operational core. Minnesota was the initial epicenter and the state with the most public visibility. Reports later surfaced in Michigan, New Jersey, South Dakota, Georgia and others, with CBS News putting the total at at least a dozen states. Documented effects include pressure drops, boil-water notices, temporary shutdowns of wells and plants, loss of monitoring and control functionality, and the need for manual operation. Water quality was not compromised, but the infrastructure was degraded.
Georgia, according to CBS News, saw a pressure drop in Clayton County and a boil-water notice for roughly 300,000 customers in the Atlanta area. Michigan reported a small number of affected communities. New Jersey had at least two affected communities. South Dakota suffered an attack on a wastewater plant in Rapid City. Wisconsin appears as a possible affected state in some coverage, though without state confirmation. The geography confirms that the problem is not local, but sector-wide.
Technical Indicators
The consolidated material did not publish classic IOCs such as hashes, malicious infrastructure domains, IP addresses, certificates or specific malware names. It did include technical references that function as exploitation and hardening indicators. They are listed below because they may help with defensive prioritization, even if they are not traditional IOCs.
| Type | Value | Source |
|---|---|---|
| MITRE technique | T0883, Internet Accessible Device | Rescana |
| PLC brand and family | Unitronics with HMI | CISA |
| PLC brand and family | Rockwell Automation, Allen-Bradley, MicroLogix 1100 and 1400 | DeNexus, CastleRockSky |
| Other brands cited | Schneider Electric, Siemens | Tenable |
| Industrial ports observed | 22, 102, 502, 2222, 44818 | Cyberpress |
| Behavior | Password changes to block operators | CISA, ABC News |
| Behavior | IP address changes to disconnect PLCs | CISA |
| Behavior | Alarm suppression and loss of visibility | ES News |
| Affected environment | SCADA, cellular telemetry, wellheads, treatment, pumps, water towers | Shieldworkz, TechRadar |
| Operational result | Forced manual operation, boil-water notices, pressure loss | Quadratín, The Guardian, CBS News |
Analysis for Security Teams
The clearest operational lesson is that direct OT exposure to the internet remains the cheapest failure point for an attacker and the most expensive one for an operator. The material shows that the attacker did not need a sophisticated exploitation chain or a long intrusion. It was enough to find PLCs, cellular modems, remote gateways or HMI interfaces that were exposed or poorly protected. When that happens, the impact may not show up as a full service outage, but it can still mean lost monitoring, lost remote control and slower response.
For security and OT teams, the first priority is to inventory all public exposure. CISA and Nozomi Networks said that explicitly. PLCs, HMIs, industrial routers, cellular modems, VPNs and gateways reachable from the internet should be identified, and anything without a documented operational need should be removed. A device having a web or telemetry interface does not mean it should be public. If remote access is necessary, it should go through a secure gateway, MFA and IP allowlists, with logging and monitoring.
The second priority is to review default credentials and factory configurations. The campaign showed abuse of default passwords, attacker-driven credential changes and loss of operational visibility. In plants where PLCs still use static or shared passwords, the line between a minor incident and a service disruption becomes very thin. Clean PLC image backups, also recommended by CISA, are not a luxury. They are the difference between recovery and rebuilding under pressure.
The third priority is OT/IT segmentation. Growmktech proposes it for Chile, but the recommendation applies anywhere. The industrial control layer should not be tied to administrative networks, external integrator access and monitoring platforms without strict controls. The Minnesota case also suggests that shared dependencies, such as an MSP or a centralized remote access platform, can amplify the reach of an intrusion. That means third parties, support agreements, VPN tunnels and cellular gateways need the same scrutiny as internal assets.
The fourth priority is detection of unauthorized OT configuration changes. The CISA advisory and Tenable’s analysis mention manipulation of reusable modules, exfiltration of PLC project files and configuration changes. Defenders should look for anomalies in PLC programs, differences between baseline and active configuration, IP changes, alarm changes, failed logins, telemetry shutdown and any unexpected shift to manual operation. Visibility has to reach the process layer, not stop at the network.
The fifth priority is incident governance. A water utility cannot improvise what it reports, to whom and within what timeframe. Chile offers a clear model of deadlines and templates, and New York is using budget to turn minimum standards and technical assistance into practice. Weak frameworks, by contrast, end up relying on operator goodwill or media pressure. For critical infrastructure, notification time is part of control. It is not useful if the regulator hears about the incident only after it has already been resolved or after the operator has already gone back to manual mode without traceability.
At the tactical level, the case suggests reviewing five points immediately:
- Public exposure of PLCs, HMIs, gateways and cellular modems.
- Default or shared passwords.
- Third-party and MSP remote access without strong MFA.
- Configuration baselines to detect changes in PLCs and SCADA.
- The ability to switch to manual mode with documented procedures and periodic testing.
The Oldelval case adds a different lesson. Even though transport operations were not interrupted, the impact on administrative systems was enough to trigger protocols, notification to the CNV and later recovery. For energy, water and sanitation companies, that means the separation between administration and operations must be real, not declarative. If an administrative incident can grow to reach SCADA or telemetry, the problem is no longer just IT. It becomes a service continuity issue.
Material Limitations
The source consolidates a large number of news reports and technical analyses, but it does not contain a definitive official attribution for the campaign against U.S. water systems. Several sources mention suspicions or probabilities involving Iran or CyberAv3ngers, but those references are framed as hypotheses or preliminary assessments, not as a closed conclusion.
The package also does not include classic IOCs such as hashes, malicious domains, IP addresses, certificates or a specific malware name for the Minnesota campaign. The technical research relies on behavior, PLC families, industrial ports and observed operational patterns. That limits the ability to produce a traditional threat-hunting indicator list.
The exact scope of the affected states also varies by source and publication date. The material moves from seven states to at least a dozen. That difference is not necessarily contradictory, but it does reflect an evolving campaign with staggered reports and partial confirmations. Some mentions of Wisconsin appear as possible impacts without state confirmation.
In the Oldelval case, the confirmation of ransomware and the attribution to groups such as TheGentlemen or Incransom are not uniformly closed. The company confirmed a computer incident that affected administrative systems and not pipeline transport operations, but the ransomware readings come in part from leak sites and incident trackers. For that reason, the episode is better used as a governance and regional exposure case than as a definitive technical attribution.
Finally, regional coverage of Chile, Uruguay, Colombia, Brazil and Peru has uneven depth. Chile provides strong legal and technical material. Uruguay adds institutional structure. Colombia, Brazil and Peru appear mostly as coverage markets and receivers of the U.S. story, with less local evidence in the research. Countries without additional verifiable facts were not included because the package did not provide enough material to develop them without speculation.
Sources
- Al menos 12 estados reportan ciberataques a sistemas de agua ...laopinion.com· La Opinión
- Did Iran hack water systems in at least seven US states?bbc.com· BBC News
- Minnesota IT officials disclose 'coordinated cyberattack' at more than 30 local water systemsreuters.com· ReutersUnverified URL
- What the FBI/EPA PLC Warning Means for Water Utilitiesnozominetworks.com· Nozomi Networks
- U.S. investigating if Iran was behind cyberattack on water systems in Minnesotacbsnews.com· CBS News
- US water facilities targeted by 'malicious cyber actors'theguardian.com· The Guardian
- TheGentlemen Ransomware Group Strikes Oldelval Oleoductos del Valledexpose.io· Dexpose
- Ciberseguridad industrial: cuando el riesgo ya no está en la planta, sino en la redmasindustrias.com.ar· Masindustrias
- Ley 21.663: Chile's Cybersecurity Framework Law Explainedzynap.com· Zynap
- Alerta en Nueva Jersey: ciberataques afectan sistemas de agua potable y el FBI advierte sobre nuevas amenazaselcomercio.pe· El Comercio
- US cyber defense agency warns hackers are increasingly targeting water utilitiesreuters.com· ReutersUnverified URL
- Victim: Oleoductos del Valle – incransomransomware.live· ransomware.live
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept Moving.riotimesonline.com· Riotimesonline
- Oldelval Oleoductos del Valle Listed by thegentlemengalaxywarden.com· Galaxy Warden
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A)cisa.gov· Cybersecurity and Infrastructure Security Agency (CISA)
- NH water utilities increase security after cyberattacks in other stateskeenesentinel.com· The Keene SentinelUnverified URL
- UY Infraestructura críticaconvergint.com· Convergint
- Sufren sistemas de agua en EU ciberataques vinculados a Iránquadratin.com· Quadratín
- El FBI alerta de un ciberataque contra sistemas de agua en siete estados de EE.UU.moncloa.com· Moncloa.com
- MNIT activates statewide cybersecurity response to support affected community water systemsmn.gov· Minnesota IT Services (MNIT)
- Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities – Incident Analysis and Response Recommendationsrescana.com· Rescana
- CISA urges water utilities to utilize advisory on Iran-affiliated OT activity following Minnesota attackinsidecybersecurity.com· Inside Cybersecurity
- La operadora del oleoducto por el que circula el 75% del petróleo de Vaca Muerta sufrió un ciberataque en sus sistemasinfobae.com· Infobae
- Oldelval Oleoductos del Valle data breach — Thegentlemen ransomware leak (2026)darkfield.orizon.one· Darkfield
- Victim: Oldelval Oleoductos del Valleransomware.live· Ransomware.live
- Ley 21719: Checklist técnico para gerentes TI en infraestructura crítica en Chilemister-it.tech· Mister-IT Tech
- Hackers atacan instalaciones de agua en 7 estados de EEUUwwwhatsnew.com· WWWhatsNew
- Hackers ampliam ataques contra sistemas de água nos EUA, diz agênciacnnbrasil.com.br· CNN Brasil
- Ataques hackers a sistemas de água dos EUA se espalham por ao menos sete estados, e suspeitas recaem sobre o Irãoglobo.globo.com· O Globo
- What we know about the cyberattacks on water systems in 7 statespbs.org· PBS NewsHour
- Infraestructura Crítica bajo Fuego: La escalada de ciberataques en Uruguay enciende las alarmas de la ciberdefensa nacionaltiuruguay.com· TIUruguay
- Estadísticas de incidentes de seguridad de la información – primer semestregub.uy· Gobierno de Uruguay / CERTuy
- At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources saycbsnews.com· CBS News
- Нью-Йорк выделил $9 млн на защиту 153 водоканалов от кибератакixbt.com· iXBT
- New York Hands $9 Million to 153 Water Utilities to Plug Cyber Gapsthreatvectr.com· ThreatVectr
- Deciphering the coordinated multi-facility Operational Technology incident targeting Minnesota community water systemsshieldworkz.com· Shieldworkz
- Hackers Manipulate PLC Logic and Operator Displays Across U.S. Critical Infrastructurecyberpress.org· Cyberpress
- 'Coordinated cyberattack' targets over 30 water systems in Minnesotausatoday.com· USA Today
- Iranian hackers likely behind cyberattack on Minnesota water systemsfoxnews.com· Fox News
- Oldelval sufrió un ciberataque pero no se afectó el transporte de crudonoticiasnet.com.ar· NoticiasNet
- Ciberseguridad de los organismos del Estado e infraestructura crítica de la informaciónbcn.cl· Biblioteca del Congreso Nacional de Chile
- Resolución 187 Exenta (24-jul-2026) M. de Interior y Seguridad Públicabcn.cl· Ministerio del Interior y Seguridad Pública / Biblioteca del Congreso Nacional de Chile
- EE. UU. sufre hackeos al suministro de agua en varios estadosnytimes.com· The New York Times (edición en español)Unverified URL
- Ataque cibernético em Minnesota expõe risco a sistemas de água: o que se sabe, o que falta confirmar e como reduzir danosinfoalfasa.com.br· InfoAlfasa
- At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources saycbsnews.com· CBS News
- Minnesota & other US Water Cyber Attacks, CISA AA26-097Atenable.com· Tenable
- New York sends $9 million+ in cybersecurity grants to municipalities for water systemscbs6albany.com· CBS6 Albany
- US cybersecurity agency warns of rising cyberattacks targeting water systemscaliber.az· Caliber.az
- Governor Hochul Announces More Than $9 Million in ...governor.ny.gov· New York State Governor's Office
- Nueva York destina USD $9 millones para blindar 153 sistemas de agua contra ciberataquesdiariobitcoin.com· DiarioBitcoin
- New York Water Cybersecurity Grants Shield 153 Utilitiesxoomar.com· Xoomar
- Hackers targeted municipal water systems in 7 states this week, FBI saysnbcnews.com· NBC News
- Critical Infrastructure Under Attack: What the July 2026 Water System Breaches Mean for OT Securitycastlerocksky.com· CastleRockSky
- US authorities probe cyberattack on water systems in Minnesotaaljazeera.com· Al Jazeera
- Ciberataque a Oldelval: cuál es la empresa clave del sistema energético que sufrió el hackeodefonline.com.ar· Defonline
- Ransomware Alert: Oldelval reportedly fallen victim to INC RANSOMx.com· FalconFeeds (X)
- Reporte de incidentes a la ANCI: plazos de 3, 24, 72 horas y 15 díasley21663.info· Ley21663.info
- El FBI investiga ciberataques a los sistemas de agua de Minnesota y Michiganapnews.com· Associated Press
- EUA: Agentes culpam Irã por ataques hackers a sistema de água; Trump negacnnbrasil.com.br· CNN Brasil
- Oleoductos del Valle — INCRANSOM Ransomware Attackbreach.house· Breach House
- Water Sector OT Incidents: The Confirmed Recorddenexus.io· DeNexus
- New York Awards $9M SECURE Grants to Secure 153 Water Systemscloudlinktech.com· Cloudlink Tech
- Oldelval confirmó un ciberataque sin impacto en la operación de sus oleoductosneuquenconvos.com· NeuquenConVos
- Qué hay detrás de los ciberataques contra sistemas de agua en 7 estados de EEUU y que muchos apuntan a Iránelobservador.com.uy· El Observador
- Sistemas de agua en todo Estados Unidos fueron afectados por ciberataques: ABC News - ES Newses.head-post.com· ES News
- Reportan que ciberataques a sistemas de agua alcanzaron al menos 12 los estados de EEUU - NIVEL4 Labsblog.nivel4.com· NIVEL4 Labs
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systemstheregister.com· The Register
- Cyberattack Hits Oldelval, Argentina's Top Oil Pipelineriotimesonline.com· The Rio Times
- Hackers are going after our water now – over 30 Minnesota utilities hit in coordinated cyberattack by apparent Iranian attackerstechradar.com· TechRadar
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCscisa.gov· CISA
- CSIRTs de la regióncsirt.lacnic.net· LACNIC
- Ciberseguridad Industrial e Infraestructura Crítica en Chile y LATAMgrowmktech.com· Growmktech
- EE. UU. investiga ciberataques contra sistemas de agua en al menos siete estados; sospechas apuntan a Iránelcolombiano.com· El Colombiano
- Oleoductos del Valle Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· Recentbreaches.com
- Feds issue warning to local water systems over increased cyber threatsabcnews.com· ABC News
- Cyber Strikes on U.S. Water Supply Linked to Iranindianweb2.com· IndianWeb2
- Centro Nacional de Respuesta a Incidentes de Seguridad Informáticagub.uy· Gobierno de Uruguay / CERTuy
- New York stellt 9 Millionen Dollar für Cybersicherheit in 153 Wasser- und Abwassersystemen bereitcyberdeutsch.news· CyberDeutsch
- Ransomware a Oldelval: la gobernanza que le falta a Vaca Muertadatatrendslatam.com· DataTrends Latam
- Troubled Waters: Minnesota Cities Weather Cyber Attackgoverning.com· Governing
- Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systemslevelblue.com· LevelBlue
- New York Awards $9M SECURE Grants to Secure 153 Water Systemscloudlinktech.com· Cloudlink Tech
- Oldelval sufrió un ciberataque, pero el transporte del petróleo de Vaca Muerta continuó sin interrupcionesneuquenalinstante.com.ar· Neuquén al Instante
- Advierten que América Latina es vulnerable en materia de ciberseguridadnoticiasargentinas.com· Noticias Argentinas
- ANCI aprueba la nómina definitiva de Operadores de Importancia Vital de la segunda etapa del primer procedimiento de calificacióncarey.cl· Carey
- La agencia de ciberdefensa de EE. UU. advierte de un aumento de los ataques contra los sistemas de aguaes.marketscreener.com· MarketScreener
- Sweeping cyberattack on water systems in multiple statescnn.com· CNN
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefatecmundo.com.br· Tecmundo
- America's water systems are getting hacked amid security gapsyahoo.com· Yahoo News
- The Faucet, the PLC, and the Nation-State That Turned It Offjimguckin.com· Jim Guckin
- New York Awards $9 Million for Water Security After Nationwide Cyberattackswsj.com· The Wall Street JournalUnverified URL
- Publicación sobre la atribución del ciberataque a Oldelval al grupo The Gentlemenx.com· X (Twitter)



