Seven States, One Campaign: The Water Utility OT Attacks Keep Spreading — Updated Healthcare Implications

AI Security Series

Update — August 4, 2026: When we published our original analysis of the Minnesota water utility attacks on Monday, the confirmed scope was 30+ facilities across one state. As of this morning, the campaign has expanded to at least seven states. This post updates the picture with what is now known, what federal agencies have said, and what the expanded scope means for the healthcare security implications we outlined in the original post.

For the original analysis — the attack chain, the CyberAv3ngers background, the OT failure modes, and the healthcare parallel — see 30 Utilities in 48 Hours: What the Minnesota OT Attacks Mean for Healthcare Security Programs.

What Has Changed Since Monday

The campaign that began July 26 and 27 in Minnesota did not stop at Minnesota's borders. Michigan confirmed nine water systems were targeted. Georgia has been identified as affected. South Dakota has been named by SecurityWeek. The FBI advisory issued last week confirmed activity against water and wastewater utilities in at least seven states total — the bureau has not publicly named all of them.

Critically, neither Michigan nor Georgia reported operational disruption. Minnesota remains the state with the most visible impact — the Maple Plain emergency declaration, the Braham lawn-watering ban, the Plymouth network disconnection — but the pattern across the additional states is consistent with what investigators identified in Minnesota: similar timing, similar types of technology impacted.

The FBI advisory is specific about what it has observed: activity exclusively against Rockwell Automation and Allen-Bradley PLCs. The bureau warned organizations deploying other manufacturers' devices to follow the same hardening advice regardless — a signal that the campaign's confirmed scope may underrepresent its actual target set. The broader CISA Advisory AA26-097A, updated July 22, had already warned that Schneider Electric, Siemens, and potentially other PLC brands were also being targeted by Iran-affiliated actors.

CISA's acting director Nick Anderson confirmed that the agency "is currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities" and urged critical infrastructure owners and operators to remove publicly exposed PLCs and other OT from the internet as soon as possible. The FBI, CISA, and EPA are all actively engaged in response and hardening support.

Attribution: What Federal Agencies Have Said and Haven't Said

The attribution picture is messier than it was Monday. Federal investigators have been examining Iran's potential involvement since the Minnesota attacks — a WaterISAC notice shared with water utilities, reported by WIRED, described the Minnesota activity as aligning with an earlier Iran-affiliated campaign, and Tenable's analysis continues to point to CyberAv3ngers operational patterns. Several mainstream media outlets reported federal investigators were looking closely at Iran.

The FBI's public advisory did not name a culprit or mention Iran. The bureau confirmed the activity and issued hardening guidance without attribution language.

President Trump on Friday rejected the Iran connection, blaming Minnesota's Democratic governor Tim Walz instead and offering no supporting evidence. Governor Walz responded on social media, referencing CISA staffing reductions and describing the attacks as "modern warfare." The political back-and-forth is unlikely to accelerate the technical response and worth noting primarily as context for why public attribution statements have become less reliable than technical indicators as a guide for defensive action.

For healthcare security programs, attribution is secondary to the technical indicators. The FBI's confirmation that Rockwell Automation and Allen-Bradley PLCs are the confirmed attack surface — and CISA's broader warning covering Schneider Electric, Siemens, and others — is the actionable information regardless of which threat actor is behind the campaign.

The Scale Shift and What It Means

Moving from 30+ facilities in one state to 30+ facilities across at least seven states in the same campaign window changes the threat model in a specific way. Our original post noted that the coordinated multi-site pattern was the most significant aspect of the Minnesota attacks — that 30+ facilities in 48 hours implied either automation of attack execution or pre-positioned access activated simultaneously. The seven-state scope confirms the second interpretation: this was a pre-positioned, coordinated campaign, not an opportunistic single-state incident.

The security expert quoted by CNN framed it plainly: "The scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented." That assessment predates the seven-state confirmation. The actual scale is larger.

For healthcare, the pre-positioned access interpretation is the most operationally relevant detail. It means the attack window between initial access and activation may be long — weeks or months — and that detection during the access phase, before activation, is the defensive opportunity that matters most. An attacker who has gained access to OT infrastructure and is waiting for a coordinated activation signal is not generating the kind of active attack traffic that triggers most OT monitoring alerts. They look like a dormant, authorized connection until they don't.

The healthcare analog is a healthcare AI vendor's integration that has access to internal systems sitting quietly until a coordinated campaign activates it. This is not hypothetical — the ThreatDown report we covered last week documented exactly this pre-positioning pattern in the OpenClaw/ClawHub malicious agent skill campaign, and the HF forensic timeline showed a four-and-a-half-day dwell time before the attack became visible. The detection window for pre-positioned access is the gap that healthcare security programs need to close.

Federal Response and What It Signals

The scale of the federal response — CISA, FBI, EPA, and state emergency management agencies across multiple states all simultaneously engaged — is itself a signal worth reading. This is the largest coordinated activation of federal critical infrastructure cyber response since Colonial Pipeline. The water sector has been flagged as persistently under-resourced for cybersecurity for years. The federal response is not closing that resource gap in real time; it is providing incident response support to facilities that lack the internal capability to respond on their own.

For healthcare, the federal response infrastructure parallel is HC3 — the Health-ISAC Threat Operations Center and CISA's healthcare-specific engagement resources. The lesson from the water sector response is that having the federal coordination pathway established before an incident is not optional. HC3 and CISA's healthcare sector team can provide the same kind of response support to healthcare facilities that CISA and the FBI are providing to water utilities right now — but only if the notification and coordination procedures are in place before the incident forces the question.

Updated Healthcare Implications

The original post identified five healthcare security priorities from the Minnesota attacks: commensurate test environment controls, remote access software inventory, cellular-connected device coverage, pod deletion versus containment planning, and the coordinated multi-site threat model. The seven-state confirmation sharpens two of those priorities specifically.

The remote access and internet-exposed OT problem is endemic, not isolated

The consistent finding across all affected states is the same finding documented in every federal advisory about the water sector for the past three years: internet-exposed PLCs and consumer-grade remote access software on OT systems. Seven states, dozens of facilities, the same vulnerabilities. Healthcare's equivalent — biomedical devices and building automation systems reachable via TeamViewer, AnyDesk, or direct internet exposure — has the same endemic quality. One advisory, one incident, one state doesn't change the exposure. The persistence of this finding across seven states in a single campaign is the argument that the healthcare version of this exposure is not going away on its own.

Pre-positioned access requires a different detection strategy

If the seven-state scope reflects pre-positioned access activated simultaneously, detection during the access phase requires behavioral baselines and anomaly detection on OT network traffic — not just alert-based detection of active attack traffic. Healthcare security programs that have deployed OT monitoring should verify that their baselines and anomaly detection are calibrated to catch low-and-slow pre-positioning activity, not just active exploitation. Programs that have not yet deployed OT-specific monitoring on healthcare OT environments have a detection gap that the seven-state pattern makes concrete.

The Bigger Picture

The water sector attacks are still developing. Attribution will be refined. Additional states may be confirmed. Federal hardening guidance will continue to evolve. We will update coverage as the picture clarifies.

What is already clear is that this campaign represents a sustained, coordinated attack against resource-constrained OT infrastructure across a significant portion of the continental United States, executed using access methods and vulnerability classes that have been documented, warned about, and left unmitigated for years. The healthcare OT environment shares those methods and those vulnerabilities. The window to close the gap before a similar campaign targets healthcare OT is not defined — but the water sector attacks are a visible marker of where that window stands.


This post updates 30 Utilities in 48 Hours: What the Minnesota OT Attacks Mean for Healthcare Security Programs. For related coverage see Agent Skills, Shadow AI, and MCP Connections: The Attack Surface Healthcare Can't See and Inside the Kill Chain: What Hugging Face's Forensic Timeline Reveals About AI-Driven Intrusions.



Key Links