00:00They Just Logged In
highthreats2026-07-29 → 2026-08-033 min read

They Just Logged In

ByRucka

More than 30 Minnesota water systems were hit on 26 and 27 Jul, and nobody used an exploit. The controllers were on the internet with the defaults still on them.

Summary

Somebody hit more than 30 community water systems in Minnesota on 26 and 27 Jul 26. Braham's plant went offline. Three other cities reported outages or trouble with their automated controls, according to Minnesota IT Services, and the state is still counting.

Nobody used an exploit. The attackers found the controllers sitting on the internet, changed the passwords so the operators were locked out, and changed the IP addresses so the controllers dropped off the network. Boil water notices went out. Plants ran by hand.

Over the weekend Michigan reported attacks on nine of its own water systems. An official told the Associated Press all nine were operating safely.

Findings

CISA put out an alert on 30 Jul 26 telling owners, operators, and integrators to get publicly exposed PLCs off the internet as soon as possible. The rest of it is enable password protection and change the default passwords, then allowlist remote access so only a known engineering machine can reach the equipment. There is nothing on that list a competent integrator doesn't already do on install day.

Censys counted 4,148 hosts answering EtherNet/IP on the open internet and identifying themselves as Rockwell or Allen-Bradley, more than 70% of them here in the United States. Another 4,117 fingerprint as Siemens S7-1200, and 2,072 come back as Schneider Electric hardware.

Finding them took no exploit either. Shodan has been scanning the whole address space and indexing whatever answers since 2009, and it reads industrial protocols the same way it reads a web server. Censys and Shadowserver do the same work on different money. A free account and a filter on your own city will show you what a stranger sees when he looks at your county. That view has been public for seventeen years.

Nobody has officially named who did Minnesota. The New York Times reported on 30 Jul 26 that Iranian actors were implicated in earlier attacks on American water facilities.

The same miss turned up wearing a vendor badge this week. CISA added CVE-2026-20316 to the exploited list on 29 Jul 26, a hard-coded password in Cisco Secure Firewall Management Center. A default credential left on a water plant PLC and a default credential shipped inside a security product are the same failure at different pay.

Impact

These are small systems. A handful of operators, a part-time superintendent, and maybe one integrator holding a service contract. Nobody in that building has a security department, and the equipment gets put on the internet because somebody needed to check a tank level from his kitchen instead of driving out there, and that was the fastest way to do it.

The margin everywhere is thin right now. DOE authorized the Southwest Power Pool to run backup generation from 26 Jul 26 through 3 Aug 26 because of the heat, T&D World reports. Infrastructure already running at the edge has less room for a week of manual operations.

The fix takes a person, and the industry is short of them. EC&M reports the Independent Electrical Contractors were picked as a national partner on a Department of Labor apprenticeship expansion worth $40 million over four years. That is where the guy who changes the password comes from.

Recommendations

Go look at your own address space first, the way a stranger would look at it. Then get the controllers behind a VPN or an allowlist and change every default on them. On a small system that is a day of work. A week of running a plant by hand costs more than a day.

Watch for attribution on Minnesota, and watch whether more states start reporting. CISA and the Australians published guidance this week on isolating OT during a crisis. Read it before you need it.

Works Cited

  1. Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks (SecurityWeek)
  2. CISA urges water and wastewater systems to protect OT against activity targeting PLCs, 30 Jul 26
  3. Minnesota IT Services incident updates
  4. Weekly Recap, 3 Aug 26 (The Hacker News; Censys exposure counts and the Michigan follow-on)
  5. CISA adds CVE-2026-20316, Cisco Secure Firewall Management Center hard-coded password, to KEV, 29 Jul 26
  6. Censys analysis of exposed water-sector PLCs
  7. Shodan; the public index of internet-facing devices, industrial controls view
  8. DOE Issues Emergency Order to Bolster Southwest Power Pool Reliability Amid Extreme Heat (T&D World)
  9. IEC Partners with U.S. Department of Labor to Expand Electrician Apprenticeships (EC&M)
  10. CISA joins Australia and others to publish guidance on isolating OT
#water#ot#plc#ics#cisa#exposure#default-credentials#shodan
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.