CISA warns Minnesota water cyberattackers likely hold only control logic backups
This digest was compiled by AI from multiple sources — links to the originals are below.

More than 30 Minnesota community water systems lost remote control and had critical control logic stolen during coordinated cyberattacks on July 26–27, a new CISA advisory reveals. Attackers exfiltrated PLC project files from Rockwell MicroLogix 1400 controllers, potentially holding the only current backups of plant operations for utilities that lack offline copies.
Exfiltrated Control Logic
CISA advisory AA26-097A documents exfiltration of project files from Rockwell Automation MicroLogix 1400 controllers, which were targeted across more than 30 water utilities in Minnesota. Rockwell’s July 30 recovery notice SD1790 requires a current offline project file to restore locked‑out controllers, but many small water systems do not maintain such backups. Consequently, the attackers may possess the only functional copy of the plant’s control program. Recovery involves erasing the controller’s memory and redownloading the project file—a step impossible without a reliable backup.
Cellular Connectivity Blind Spot
Unlike typical internet‑facing infrastructure, the affected utilities connect over cellular networks, making them invisible to public scanning tools such as Shodan. This same obscurity hinders defenders’ own asset inventories: operators cannot detect exposed SIM‑equipped OT devices through network scans and must instead audit carrier invoices. Cellular connections allowed the attackers to access controllers without leaving a public‑facing footprint, complicating both detection and assessment of the exposure.
Integrator Supply Chain Risk
Investigators suspect a shared systems integrator or communications architecture linked the victims, indicating that the unit of compromise was not individual utilities but the integrator’s customer fleet. Utilities are urged to demand that integrators disclose which other customers share remote‑access designs. The attack did not exploit any software vulnerability; instead, the hackers used administrative functions—changing IP addresses and setting passwords—that are legitimate controller operations, making the intrusion harder to distinguish from routine management.
What's Next
CISA and Rockwell Automation continue to investigate the scope of the intrusion, urging all water utilities to immediately secure their MicroLogix 1400 installations. It remains unclear how many other small utilities may be compromised through similar integrator supply chains, and whether the attackers will leverage the stolen control logic for future disruptions.
1 source
CISA warns Minnesota water cyberattackers likely hold only control logic backups



