More than 30 Minnesota community water systems reportedly suffered a coordinated intrusion into their operational-technology environments, disrupting remote monitoring and forcing some utilities to operate manually. Attackers reportedly reached internet-exposed programmable logic controllers (PLCs) through cellular gateways, changed controller IP addresses and passwords, and deprived operators of visibility into affected equipment.
Authorities have not confirmed the vulnerability or equipment involved at most affected utilities. The incident nonetheless highlights the risk from publicly reachable OT assets, including exposed Rockwell Logix controllers affected by the actively exploited, unpatched authentication-bypass vulnerability CVE-2021-22681; utilities should remove public OT exposure, segment networks, harden remote access, monitor configuration changes, and maintain tested manual fallback procedures.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2021-22681, a CVSS 9.8 authentication-bypass vulnerability affecting Rockwell Automation Logix controller families, was disclosed. The weakness stems from insufficient protection of a cryptographic key that can allow a client posing as Studio 5000 Logix Designer to be treated as trusted.
Senators Schiff and Klobuchar introduced the proposed Water Cyber Shield Act. The bill would authorize EPA cybersecurity assessments and corrective actions for water and wastewater systems, with proposed authorization of $300 million annually, but it has not become law.
The National Rural Water Association and DEFCON Franklin announced the Water Watch Center, formalizing a two-year pilot that placed roughly 450 volunteer security researchers with small utilities in seven states. The initiative also includes managed detection and response threat-intelligence sharing and a Vanderbilt/DARPA CASTLE digital-twin research partnership.
A coordinated intrusion reportedly affected operational-technology environments at more than 30 Minnesota community water systems. Some utilities lost remote communications with water towers and lift stations, switched to manual operations, and one utility temporarily took its water-treatment plant offline; four utilities publicly disclosed effects, including one that declared a local emergency.
CISA added CVE-2021-22681 to its Known Exploited Vulnerabilities Catalog. Rockwell Automation reportedly has no complete patch because the issue is rooted in the protocol's authentication design.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.