Blog - swIDch

What 30 Hacked Water Utilities Tell Us About OT Security

Written by Admin | Aug 03 2026

 

On the morning of 27th July 2026, officials in Braham, Minnesota — a town of roughly 1,700 people — discovered they had been locked out of their own water treatment plant. Someone had remotely changed the PLC administrator password overnight. The well and treatment plant shut down. Residents were asked to minimise water use whilst crews worked to restore operations. Within two hours, the plant was back online.

 

Braham was not alone. Between 26th and 27th July, a coordinated cyberattack disrupted automated controls at more than 30 municipal water and wastewater systems across Minnesota. Plymouth, South St. Paul, and Maple Plain were among the cities that publicly confirmed they had been targeted. Plymouth disconnected cellular-connected equipment at two water towers and multiple wastewater lift stations to stop the attack from spreading. South St. Paul switched to manual operations entirely. Maple Plain's mayor declared a local state of emergency.

Minnesota IT Services described it as the most widespread cyberattack on water infrastructure in US history. American intelligence agencies have assessed that Iran-linked hackers are the most likely perpetrators, though the attribution has not been formally confirmed and investigators have not ruled out the possibility of a false-flag operation.

A Minnesota law enforcement memo, later reported by Wired and the New York Times, stated that the goal of the attack was to cause loss of system pressure — and the potential contamination of the water supply that would follow. This time, it did not get that far.

 

The Attack Was Not Sophisticated. That Is the Point.

There were no zero-day exploits. No months-long intrusion campaign. No custom malware burrowing through layered defences.

The attackers accessed internet-exposed PLCs directly, changed administrator passwords to lock out operators, and modified IP address settings to disconnect devices from their networks. CISA, in its urgent alert published on 30th July, described exactly this pattern: threat actors targeting exposed PLCs, modifying passwords to lock out operators, and disconnecting devices by changing their IP addresses.

CISA's core message to the sector was unambiguous: remove publicly exposed PLCs and other operational technology from the internet as soon as possible.\

What makes this particularly uncomfortable is the line that followed in CISA's alert — that the targeting spans water entities of all sizes, and that even organisations with mature cybersecurity programmes should validate their external connections. In other words, a firewall and a network monitoring tool are not enough if there is no mechanism to verify who is actually connecting to a PLC and whether they are authorised to do so.

 

A Structural Problem the Industry Has Known About for Years

OT environments — the PLCs, RTUs, HMIs, and SCADA systems that run water treatment, energy grids, and manufacturing lines — were designed for a world that no longer exists. When these devices were built, the assumption was air-gapped operation. Security meant physical access control, not cryptographic authentication.

That assumption has not held for some time. Remote maintenance, supply chain integration, and the push towards smart infrastructure have quietly dissolved the air gap. What has not kept pace is the authentication layer sitting in front of these devices.

Shared accounts. Static passwords. Credentials issued to contractors and never revoked. These are not exotic vulnerabilities — they are routine conditions in OT environments worldwide, and they were the entry point in Minnesota.

CISA's alert specifically flagged cellular modems installed by operators, vendors, or system integrators as a common blind spot — devices that may not appear in routine attack surface scans, but which provide a direct path to field-deployed PLCs. Plymouth's incident confirmed this precisely: the attack was limited to equipment connected via cellular communications.

 

The Threat Is Not Standing Still

What raises the stakes further is the trajectory of the threat itself.

This year has produced a series of documented cases in which AI agents have demonstrated the ability to autonomously identify vulnerabilities and map attack paths. Security researchers in South Korea successfully used an AI tool to gain control of an Active Directory server in under 30 minutes. The primary vectors were absent authentication controls and excessive privilege — the same conditions present across much of the OT landscape.

When attacks that once required skilled human operators can be automated, the speed and scale of what is possible changes materially. OT environments that have tolerated weak authentication as an acceptable operational trade-off may find that tolerance increasingly difficult to justify.

 

The Question That Still Does Not Have a Good Answer

CISA's three immediate recommendations — disconnect exposed PLCs, replace default passwords, restrict remote access to trusted devices — are reasonable and necessary. But they describe a floor, not a ceiling.

The deeper question is one the industry has been slow to answer: at the moment someone attempts to connect to a PLC, an RTU, or an HMI, is there a reliable mechanism to verify who they are and whether that access is legitimate?

Static passwords, once compromised, remain valid indefinitely. Shared credentials make audit trails meaningless. An authentication approach that generates a unique, non-reusable code for each access attempt addresses this structurally — even if a code is intercepted, it has already expired by the time it could be reused.

The water in Minnesota remained safe. Whether that holds next time depends, in part, on whether the industry treats authentication at the OT endpoint as an operational necessity rather than an afterthought.

 

 

--------------------

 

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.