In late July 2026, 36 municipal waste and water systems across Minnesota were targeted in a cyber attack. The attackers targeted Programmable Logic Controllers (PLCs) that were in control of pressure, pumps, and chemical dosing. When the news broke, it felt like it was everywhere. This was an attack on critical systems, systems that we require and use daily.
But cyberattacks on U.S. critical infrastructure systems like water, hospitals, sewage, gas, and electricity aren’t new. Attackers have been targeting adversarial countries’ critical infrastructure and key resources for a long time, it just doesn’t always make major headlines.
What’s changing is the number of ways attackers can gain access. Sometimes the path leads directly to operational technology (OT) or industrial control systems (ICS). Other times, it starts with something smaller, like credentials or an unpatched vulnerability in a vendor’s network. And when you introduce AI, those paths can become a whole lot more complicated.
Routine access path
Compromised vendor path
Figure 1: The critical attack surface extends beyond the control system.
The threat to critical infrastructure isn’t new, but the environment around it is changing. The concern isn't just about whether an attacker can reach a critical system, that’s always been a concern. But, what about business continuity? Getting to work? Having access to HVAC or refrigeration? It’s imperative that organizations understand the systems and dependencies that keep critical operations running, where they are exposed, and how quickly they can recover when something goes wrong.
Critical infrastructure attacks aren’t new
Ukraine’s power grid is a stark example of a cyberattack moving from an IT foothold to a physical disruption. In December 2015, attackers used spearphishing, BlackEnergy malware, stolen credentials, and legitimate remote-administration tools before opening breakers and disrupting power to about 225,000 customers. While the actors used malware to get in, the more serious impact came from what happened once they were inside, where they were able to reach the systems and credentials that controlled the grid. CISA documented the attack, and the U.S. Department of Justice later attributed the campaign to officers in Russia’s GRU Unit 74455.
The 2016 Industroyer attack was like the sophisticated evil stepbrother of the 2015 attack. The malware used in the attack could speak industrial protocols used in electric substations and send commands to switches and circuit breakers. In 2022, Ukrainian defenders stopped an attempted attack involving Industroyer2. Later that year, Sandworm used the target’s own MicroSCADA software to send unauthorized commands to substations, then deployed CaddyWiper against the IT environment.
The United States has had warnings, too:
- In 2013, an Iranian actor repeatedly accessed the SCADA system at the Bowman Avenue Dam in New York. The access could normally have operated the sluice gate, but the gate was manually disconnected for maintenance. The Department of Justice disclosed the intrusion in 2016.
- In 2021, Colonial Pipeline shut down its pipeline system in response to a ransomware attack on its business network. The attackers didn’t manipulate pipeline controls directly and they still successfully created fuel-supply disruption. The Department of Energy’s incident summary underscores how critical IT availability, billing, and operational confidence can be. In this instance, the downtime ended up costing the company more than the original ransom demand of $4.4 million USD.
- In 2023, the Iran-linked CyberAv3ngers APT compromised internet-connected Unitronics PLCs used by U.S. water utilities, including the Municipal Water Authority of Aliquippa in Pennsylvania. The campaign relied on exposed devices and default passwords, not some magical zero-day. CISA’s advisory said the activity affected multiple sectors in the United States and other countries.
- In July 2026, malicious activity targeted remote monitoring and control technology at more than 30 Minnesota community water systems. Some systems experienced disruption, but officials reported no confirmed impact to drinking-water quality. The FBI investigation had not publicly attributed the campaign to a specific actor, while some suspect Iran or CyberAv3ngers was responsible it has not been confirmed. Minnesota IT Services published the state’s response, while CISA urged water operators to remove publicly exposed PLCs and OT from the internet.
My point in sharing all of this is to show that the attacker doesn’t necessarily need sophisticated tools — one attack relied on more sophisticated tooling while the other did not. It's more important that they understand the environment they are targeting.
The threat to global critical infrastructure and key resources is not theoretical. So, who targets critical infrastructure? Threat actors are generally grouped into three buckets with different goals: financially motivated actors, including ransomware groups, politically or ideologically motivated hacktivists, and espionage or destructive activity conducted by advanced persistent threat groups and nation-state actors.
Although their goals and motivations differ, their attack pathways generally stay the same: find exposed technology, steal or bypass access, understand the environment, and reach something that will cripple or cause major outages for the intended victim(s).