Cyber & Digital Crime · GSJ Original

Hackers Locked Utilities Out of Their Own Water Controls. CISA Says: Get Them Off the Internet.

Coordinated attacks knocked 30-plus Minnesota water systems onto manual operations. The fix CISA wants is the one the industry has dodged for years.

A water treatment plant in Redwood City, California (not the affected systems). Photo: Alfred Twu via Wikimedia Commons, CC0
A water treatment plant in Redwood City, California (not the affected systems). Photo: Alfred Twu via Wikimedia Commons, CC0

Somebody spent last week locking American water utilities out of their own control systems — and the federal government's advice boils down to something your IT guy has been saying for a decade: get that stuff off the internet.

Beginning July 26, coordinated cyberattacks disrupted more than 30 community water systems in Minnesota, according to reporting by The Record and BleepingComputer. Some utilities issued boil-water notices; others fell back to running their plants by hand. The Record reports that at least seven states have told the FBI about similar incidents involving the same class of equipment.

The equipment in question is the programmable logic controller — the PLC, the small industrial computer that actually opens the valves and runs the pumps. The attackers didn't need exotic tradecraft. According to both outlets, they found PLCs sitting exposed on the public internet, changed the passwords so operators couldn't log in, and altered the devices' IP addresses so they dropped offline. That's not a heist movie. That's walking through an unlocked door and changing the locks behind you.

On July 30, CISA issued an alert urging the water and wastewater sector to "remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," and to hunt down external connections operators may not even know they have — including undocumented cellular modems installed by vendors. Where removal isn't feasible, the agency points to VPNs or gateway devices, non-default passwords, and IP allowlisting.

Who did it? Investigators are reportedly examining whether the incidents are connected to Iran, and the industry group WaterISAC has reportedly made that link. CISA's alert names no actor, and neither will we until someone with evidence does.

Here's the operator's read: attribution is the least actionable part of this story. Whether the hands on the keyboard sit in Tehran or a teenager's bedroom, the enabling failure is the same — critical controls reachable from the open internet, often protected by default passwords. Every water utility, and frankly every small operation running industrial gear, can act on that today: inventory what's exposed, pull it behind a VPN, change the defaults, and ask your integrator the uncomfortable question about that cellular modem nobody documented.

The water still runs in Minnesota. The lesson shouldn't wait for the next state.