00:00→Attackers Logged Into Minnesota Water Plants With the Default Passwords
highthreats2026-07-29 → 2026-08-034 min read

Attackers Logged Into Minnesota Water Plants With the Default Passwords

BySurucka

More than 30 Minnesota water systems were hit on 26 and 27 Jul, and nobody used an exploit. The controllers were on the internet with the defaults still on them.

Summary

Somebody hit more than 30 community water systems in Minnesota on 26 and 27 Jul 26. The plant in Braham, a small Minnesota city, went offline. Three other cities reported outages or trouble with their automated controls, according to Minnesota IT Services, and the state is still counting.

Nobody broke through anything. The attackers found the plant controllers out on the open internet and simply signed in. They changed the passwords so the operators were locked out. They changed the network addresses so the controllers dropped off the network. Boil water notices went out, and plants ran by hand.

Over the weekend Michigan reported attacks on nine of its own water systems. An official told the Associated Press all nine were operating safely.

Findings

The Cybersecurity and Infrastructure Security Agency (CISA) put out an alert on 30 Jul 26. It told owners, operators, and installers to get exposed controllers off the internet as soon as possible. The equipment in question is the programmable logic controller (PLC), the small computer that runs a plant's pumps and valves. The rest of the alert is basic. Turn on password protection, change the factory default passwords, and limit remote access to a short list of known machines. Nothing on that list goes past what a competent installer already does on install day.

Censys, a security firm that scans the whole internet, counted 4,148 exposed devices speaking EtherNet/IP, a common industrial communication language. Those identified themselves as Rockwell or Allen-Bradley gear, and more than 70 percent sit here in the United States. Another 4,117 devices identify as Siemens S7-1200 controllers, and 2,072 come back as Schneider Electric hardware.

Finding them took no special skill either. Shodan, a public search engine, has been scanning every internet address and indexing whatever answers since 2009. It reads industrial equipment the same way it reads a website. Censys and a nonprofit called Shadowserver do the same work with different funding. A free account and a filter on your own city will show you what a stranger sees when he looks at your county. That view has been public for seventeen years.

Nobody has officially named who did Minnesota. The New York Times reported on 30 Jul 26 that Iranian actors were implicated in earlier attacks on American water facilities.

The same mistake showed up inside a security vendor's own product this week. CISA added a bug numbered CVE-2026-20316 to its list of flaws known to be used in attacks on 29 Jul 26. The bug is a factory-set password wired into Cisco's Secure Firewall Management Center. A default password left on a water plant controller and a default password shipped inside a security product are the same failure at different pay.

Impact

These are small systems. A handful of operators, a part-time superintendent, and maybe one controls contractor holding a service agreement. Nobody in that building has a security department. The equipment gets put on the internet because somebody needed to check a tank level from his kitchen instead of driving out there. That was the fastest way to do it.

The margin everywhere is thin right now. The Department of Energy (DOE) issued an emergency order over the heat, T&D World reports. It authorized the Southwest Power Pool, a regional electric grid operator, to run backup generation from 26 Jul 26 through 03 Aug 26. Infrastructure already running with no spare room has less room again for a week of manual operations.

The fix takes a person, and the industry is short of them. The trade magazine EC&M reports the Independent Electrical Contractors were picked as a national partner on a federal apprenticeship expansion. The Department of Labor program is worth $40 million over four years. That is where the guy who changes the password comes from.

Recommendations

Go look at your own internet addresses first, the way a stranger would. Then get the controllers behind a virtual private network (VPN), meaning a private encrypted connection, or behind an approved-machine list. Change every factory default on them. On a small system that is a day of work. A week of running a plant by hand costs more than a day.

Watch for word on who did Minnesota, and watch whether more states start reporting. CISA and its Australian counterpart published guidance this week on cutting plant controls off from the network during a crisis. Read it before you need it.

Works Cited

  1. Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks (SecurityWeek)
  2. CISA urges water and wastewater systems to protect OT against activity targeting PLCs, 30 Jul 26
  3. Minnesota IT Services incident updates
  4. Weekly Recap, 3 Aug 26 (The Hacker News; Censys exposure counts and the Michigan follow-on)
  5. CISA adds CVE-2026-20316, Cisco Secure Firewall Management Center hard-coded password, to KEV, 29 Jul 26
  6. Censys analysis of exposed water-sector PLCs
  7. Shodan; the public index of internet-facing devices, industrial controls view
  8. DOE Issues Emergency Order to Bolster Southwest Power Pool Reliability Amid Extreme Heat (T&D World)
  9. IEC Partners with U.S. Department of Labor to Expand Electrician Apprenticeships (EC&M)
  10. CISA joins Australia and others to publish guidance on isolating OT
#water#ot#plc#ics#cisa#exposure#default-credentials#shodan
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.