RSS Amplifier

Risk Factor - Dr. Andrew G. Huff · Aug 4, 2026

Attack or Accident?

0
Sign in to vote or save

Dr. Andrew G. Huff · Risk Factor - Dr. Andrew G. Huff

By Dr. Andrew G. Huff

Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science - Emerging Infectious Disease/Epidemiology, DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.

In the last week of July 2026, two stories burned into the American infrastructure picture at once. Intruders reached into the operational technology of more than thirty Minnesota community water systems, part of a campaign that touched utilities in at least seven states. Days later, a large kosher meat and poultry plant in Postville, Iowa burned to the ground. To a reader moving fast through a feed, both looked like one headline: the things that keep us watered and fed are under attack.

They were not one thing. One was an intrusion. One was an accident. Telling them apart is a discipline, and in both cases the public conversation failed at it in the same direction. Certainty ran out ahead of the evidence.

Seven judgments, each with my confidence on a 0 to 100 scale.

1. The Minnesota intrusions are real, and the control systems of dozens of water utilities were reached. High confidence, 90.

2. The actor is probably Iranian or Iranian-affiliated. Moderate confidence, 65, and lower than most coverage implies. As of 31 July neither Minnesota nor the federal government had attributed the activity to any specific actor, and investigators were still examining whether someone deliberately built the appearance of Iranian involvement.

3. What the intruders demonstrated was the exploitation of exposed industrial controllers and the lockout of operators, not the capability to poison a city. Moderate to high confidence, 75.

4. The framing that this was an act of war, a proven strike on American drinking water, is not supported by anything public. Low confidence in that framing, 25.

5. The Postville fire was an accident, as local authorities ruled, and the belief that someone is deliberately torching America’s food plants is not supported by the frequency data. High confidence, 90.

6. The exposure that made Minnesota possible is systemic, documented, and older than the attack. High confidence, 92. It has a name, SCADA, and it is the reason this series exists.

7. In November 2021, a government-derived, rank-ordered criticality list covering American food and agriculture infrastructure was stolen from a locked safe in my home. I reported the theft to the FBI, USDA, DHS, FDA, and DOE, then to the Michigan State Police and the Michigan Intelligence Operations Center, then in writing on 23 March 2025 to seven cabinet-level and agency-head officials, then on 17 September 2025 to every member of Congress and to 108 Michigan state legislators. No agency opened an investigation. That the reports were made and went nowhere: high confidence, 90, and the letters are published with this piece so you can check.

That last paragraph is the reason to read this series. Not because I am always right.

Two signals arrived inside the same news cycle, and the public mind fused them.

The first was a genuine security event. Beginning the weekend of 26 July, operators and state officials in Minnesota found evidence of malicious activity inside the operational technology of dozens of community water systems. Not the billing servers. The control systems: the programmable logic controllers and the human-machine interfaces that open valves, run pumps, dose chemicals, and tell an operator what the plant is doing. The activity was not confined to Minnesota. It reached utilities in at least six other states.

The second was a catastrophe of a very different kind. On or about 28 July, the Agri Star meat and poultry plant in Postville, Iowa caught fire and was destroyed. Roughly six hundred people lost their place of work overnight. The company said it would rebuild.

Put those two events in front of a tired reader and the brain does what brains do. It finds the pattern. Water attacked. Food destroyed. Someone is coming for the basics. That instinct is not stupid. It is the same threat-detection wiring that kept our ancestors alive. Applied to modern infrastructure without discipline, it produces exactly the wrong response, because it treats an accident and an attack as the same event and demands the same reaction to both. The first job of anyone serious about these systems is to pull the two signals back apart.

Start with the record, and label every part of it honestly.

What is known. More than thirty Minnesota community water systems showed confirmed malicious activity involving their control technology, and similar activity hit utilities in at least six other states. Minnesota IT Services was precise about what that means, and the precision matters: “impacted” meant investigators confirmed malicious activity involving a system’s technology, not that every affected community experienced a disruption to water service.

On 30 July, CISA issued an alert stating it was observing a significant increase in threat actors targeting programmable logic controllers at water utilities, that the actors were modifying passwords to lock out operators, and that this activity had resulted in boil water notices and sustained manual operations. Read that sentence carefully, because almost every account I saw got it wrong in one direction or the other. CISA was describing the national pattern. In Minnesota specifically, MNIT reported no active requests from any locality for residents to change how they use their water, and the Department of Public Safety said none of the state’s water supply had been reported compromised.

Two utilities described what the intrusion looked like from the floor. South St. Paul identified a problem early on Monday, moved public works staff to manual operations, and kept water and wastewater service running without interruption; the city reported drinking water treatment, quality, pressure, and delivery were unaffected. In Braham, a rural city north of Minneapolis, public works personnel noticed the well supplying the water tower was malfunctioning, isolated the affected system, restored a backup, and restarted the plant in about ninety minutes. Residents lost no service. The tower holds roughly two days of water. Braham has since taken the system off any public-facing network.

I flagged the Braham “plant offline” reporting as unresolved when I began this piece. It is now resolved, and the resolution is instructive: a brief pump outage caught by a human being before the automated alert fired. That is not a city losing its water. It is also not nothing. Hold both.

What is assessed. That the activity is real and coordinated, I hold at 90. That it is Iranian or Iranian-affiliated, I hold at 65, which is deliberately lower than the run of coverage. The technical playbook matches Iranian-affiliated operations documented since 2023, when IRGC-affiliated actors reached multiple US water and wastewater facilities by exploiting internet-connected controllers still carrying default passwords. Security researchers at Tenable suspect CyberAv3ngers. That is a reasonable read. It is not attribution. As of 31 July, US officials had made no formal determination, told reporters they were awaiting deeper forensics, and were separately examining whether the actor had tried to appear Iran-based in order to stir the pot during an active US conflict with Iran.

What is unknown. Whether every one of the thirty-plus Minnesota incidents shares a single author is not established; Minnesota said it had found similarities in timing and in the technology targeted but had not confirmed a common actor. Whether the actor was directed by the Iranian state, tolerated by it, or merely wearing its flag is not settled, and that distinction is load-bearing. And there is no public evidence that anyone’s drinking water in Minnesota was altered or made unsafe.

Here is where the story stops being about hackers and starts being about us.

Watch how fast the verdict moved. In the first hours, officials did the correct thing: they said the activity was under investigation and explicitly allowed for the possibility of a false flag. Then reporting firmed. The New York Times reported the Iranian line of inquiry, a leaked internal memo was said to tie the Minnesota activity to Iran, and researchers named a suspect group. That is real movement and it raises my confidence.

Notice what happened around it. The Governor of Minnesota declared, “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.” The President, asked about the same event, said, “I blame it on Minnesota because they’re grossly incompetent.” Headlines slid from “suspected” to “confirmed.” Within a few days the same set of facts had been used to prove an act of war, to prove local negligence, and to prove nothing at all. At most one of those readings can be right. Probably none of them is complete.

Two distinctions were trampled in the rush, and both carry weight.

The first is affiliated versus directed. “Iranian-affiliated” is CISA’s careful phrase and it is not a synonym for “ordered by Tehran.” It spans a spectrum: a unit taking direct orders from the Revolutionary Guard at one end, a tolerated proxy in the middle, a loosely aligned crew flying Iran’s banner at the other. The evidence we have is consistent with more than one point on that spectrum. Where the actor actually sits determines whether the right instrument is an indictment or a national security response, and collapsing the spectrum forecloses that judgment before it can be made.

The second is the act versus the effect, and it opens onto something most coverage misses. Adversaries in this space do not only want to break equipment. They want you afraid. Analysts tracking Iranian operations describe influence brands built to inflate the impact of modest intrusions for psychological effect, treating the fear itself as the deliverable. Run that logic forward. If a crew exploits a soft target, locks an operator out of a screen, and causes a disruption a public works crew can reverse in ninety minutes, and a nation of readers responds as though the water has been poisoned, then the readers have finished the operation the attacker could not finish alone. Panic is a force multiplier you hand the enemy for free. Covering the intrusion without amplifying the psyop is not softness. It is refusing to be used.

Now the other event, read with the same instruments.

What is known. The Agri Star plant burned on or about 28 July and roughly six hundred people were put out of work. Local fire authorities ruled the cause accidental. The company intends to rebuild. The first of those facts, the accidental ruling, is the one that matters most and the one most likely to be ignored.

What is assessed. There is a durable narrative, running since 2022 and pushed by accounts with large audiences, that America’s food plants are being deliberately destroyed to engineer shortages. Tested against the evidence, it fails. FactCheck.org, PolitiFact, and the Associated Press each examined the pattern and found the same thing: fires and accidents at food facilities are common, the frequency is not abnormal, and no evidence supports coordinated sabotage. I assess the coordinated-sabotage narrative as unsupported at 90, and I assess the Postville fire as what the fire marshal said it was.

What is unknown. A final forensic cause report may add detail and I will update if it does. But “we do not yet have the full report” is not evidence of a plot. It is the normal condition of the first week after any fire.

The base rate is the whole game here. The United States has a very large number of food facilities, and industrial facilities burn at a measurable, boring rate every year. When you already believe an enemy is at work, every fire looks like a battle. When you count, the battle disappears into the background noise. Counting is not naivety. It is the antidote to being manipulated by your own pattern recognition.

Everything in this series runs through one acronym, so learn it now.

SCADA stands for Supervisory Control and Data Acquisition. It is the layer that lets a handful of people operate an enormous physical process from a screen. Underneath it sit programmable logic controllers, PLCs, which are small ruggedized computers wired directly to pumps, valves, motors, breakers, and chemical dosing equipment. Above it sit human-machine interfaces, HMIs, the screens an operator watches. Alongside it sit remote terminal units, data historians, and engineering workstations that push new logic down to the controllers.

Collectively this is operational technology, OT, and it is a different world from the information technology most people picture when they hear the word “hacked.” IT protects data. OT moves matter. When IT fails you lose records. When OT fails, a pump runs dry, a valve stays open, a chlorine feed doses wrong, a pasteurizer holds at the wrong temperature, a cold chain drifts, a breaker does not trip.

Four facts about this layer explain nearly every headline in this series.

One. The protocols were designed before the internet and have no authentication. Modbus dates to 1979. DNP3 to the early 1990s. They were built for a serial cable inside a locked building, on the entirely reasonable assumption that anyone able to send a command had already been vetted by a fence, a badge, and a door. They do not ask who you are. A correctly formatted command is an authorized command. Authentication has been bolted on since, unevenly, and the installed base is old. This is not a bug anyone introduced. It is a load-bearing assumption from a vanished world.

Two. The air gap was that assumption, and it is gone. Utilities and processors connected OT to business networks for perfectly rational reasons: remote monitoring, after-hours alarming, vendor support, contract operators covering dozens of small systems from one office, regulatory reporting. Each step was defensible. The aggregate result is that the fence no longer bounds the control system. CISA named the sharpest version of this on 30 July when it warned that even organizations with mature cybersecurity should validate their external connections, because the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. Read that again. The utility does not know the modem is there. Neither does the state. Internet scanning services do.

Three. You cannot patch a plant the way you patch a laptop. Control equipment runs on fifteen to twenty-five year lifecycles. Firmware updates require vendor validation and a maintenance window, and a water plant does not have a maintenance window because people drink continuously. Most of the roughly fifty thousand community water systems in this country have no dedicated security staff at all, and many have no dedicated IT staff. So a vulnerability disclosed and patched in 2021, an authentication bypass in Rockwell Logix controllers catalogued as CVE-2021-22681, still had thousands of affected devices reachable from the open internet when this campaign began. The fix existed for five years. The exposure outlived it.

Four. It is the same layer everywhere. This is the fact that turns a water story into a national story. The same vendors, the same protocols, and the same architectural assumptions run drinking water, wastewater, the electrical grid, pipeline compression, food processing and cold chain, and the building management and medical gas systems inside hospitals. When an adversary develops a capability against one sector’s controllers, they have substantially developed it against all of them. Targeting in this campaign has already widened beyond Rockwell to Schneider Electric and Siemens equipment.

Three cases mark the boundaries of what this layer actually risks, and they should be read together because they teach opposite lessons.

Oldsmar, Florida, February 2021, is the case everyone cites and almost nobody has updated. An operator watched a cursor move across the screen and the sodium hydroxide setpoint jump from 100 to 11,100 parts per million. He changed it back within seconds. The story became the canonical example of hackers trying to poison an American city, cited in congressional hearings and used to justify a billion-dollar grant program. Then, in 2023, the FBI told CyberScoop it “was not able to confirm that this incident was initiated by a targeted cyber intrusion of Oldsmar,” and the former city manager said it was likely an employee error. The Water-ISAC had raised that possibility from the beginning, noting that a change from 100 to 11,100 is what a fat-fingered keystroke looks like. Nothing was ever conclusively established either way and the sheriff’s case remains open.

Take the right lesson from that, because there are two available and one of them is wrong. The wrong lesson is that the water threat was hype. The underlying findings held up completely: the plant ran Windows 7 past end of support, shared a remote access tool across staff, and had credentials in a public breach dump days earlier. The right lesson is narrower and more useful. The flagship case that drove five years of American water security policy may not have been an attack at all, and almost no one who cites it knows that. If your evidentiary standards are loose enough to let that happen, they are loose enough to be steered.

Aliquippa, Pennsylvania, November 2023, is the case that is not ambiguous. CyberAv3ngers, an IRGC-affiliated group, compromised a Unitronics PLC at a booster station of the Municipal Water Authority of Aliquippa and left a banner reading “You have been hacked. Down with Israel. Every equipment made in Israel is CyberAv3ngers legal target.” They got in because the device was internet-facing with a default password. The authority regained control with no interruption to service, and the chairman was clear that they had reached a pressure-regulating pump and nothing in the treatment plant. Two things are true at once: the intrusion was trivially easy, and the consequence was small. Both facts belong in the same sentence, and almost nobody puts them there.

Triton, discovered in 2017 at a Saudi petrochemical facility, is the case that should frighten you. It did not target process control. It targeted the safety instrumented system, the independent layer whose only job is to shut a plant down before it kills people. It is the first publicly known malware built to disable the mechanism that prevents catastrophic physical failure. The intrusion was detected because the malware tripped the safety system into a shutdown by accident. Triton is the proof that the ceiling on this threat is not screen manipulation. It is the deliberate removal of the last barrier between a process and a body count.

So place Minnesota correctly on that scale. It sits close to Aliquippa and nowhere near Triton. Operators locked out of screens, plants run manually by public works crews who knew what to do, service maintained. That is a real intrusion with a contained effect, and treating it as Triton is exactly the error Section III is about.

Now the sentence this section exists to deliver.

For twenty years, food and agriculture defense in this country was built on the assumption that an adversary needed physical access to reach a critical control point. Get through the fence, get past the badge reader, get to the tank or the line or the dosing station. Every criticality assessment I worked on, including my own, carried that assumption in its bones. SCADA dissolves it. The critical control points did not move. The distance to them did.

That is the whole thesis of Soft Targets. The vulnerability analysis of the American food and water system was largely done years ago, by people like me, on the premise that the hard part was getting close. The hard part is no longer getting close.

A discipline note before anything else. What follows describes the existence, provenance, and handling of a dataset. It does not describe its contents, its ranking criteria, or any facility on it, by name, category, or region, and it never will in this publication. If that is what you came for, you came to the wrong place. There is a version of this story that is a targeting aid, and I am not writing it.

Between 2007 and 2012 the federal government funded the development of the Food and Agriculture Sector Criticality Assessment Tool, FASCAT, through a DHS Center of Excellence, to determine which food and agriculture systems were most critical to the nation. I was the scientist who collected and analyzed the FASCAT data. The evaluation of the tool and the collected data was published under my name in Risk Analysis in 2015. I later expanded that work at Sandia National Laboratories in a classified environment. The derived product was a rank-ordered list of critical infrastructure and key resources in food and agriculture, with vulnerability assessments attached.

In November 2021, while I was living in Michigan, the hard drive holding my copy was taken from a locked safe in my home. I reported the theft to the FBI, USDA, DHS, FDA, and DOE, and to the Michigan State Police and the Michigan Intelligence Operations Center, the state’s homeland security fusion center. No agency opened an investigation. Not one collected the physical evidence I preserved.

On 23 March 2025 I put it in writing to seven officials: Attorney General Pam Bondi, Director of National Intelligence Tulsi Gabbard, Secretary of Homeland Security Kristi Noem, Secretary of Defense Pete Hegseth, Secretary of Agriculture Brooke Rollins, FBI Director Kash Patel, and FBI Deputy Director Dan Bongino. On 17 September 2025 I sent the same substance to every member of Congress and to 108 Michigan state legislators. All seven letters are published with this article. Read them yourself rather than taking my characterization of them.

Strip out the statistics entirely and one fact remains, dated and documented. A person with a Ph.D. from a DHS Center of Excellence, a former Sandia scientist holding a Q clearance, reported to five federal agencies and two state bodies that a government-derived critical infrastructure criticality product had been stolen from his home. Nobody investigated. Nobody collected the physical evidence. Four and a half years later, after seven letters to cabinet officials and a distribution to all of Congress, that is still true as far as I have been informed.

The word people want here is cover-up. I am not going to give it to them without earning it, so let me lay out the competing explanations and score them the way I would score anyone else’s.

A. No agency owned it. Food and agriculture sits across FDA, USDA, DHS, and FBI, with DOE involved only because of the national laboratory connection. A report that touches all of them is a report that belongs to none of them. Each agency can reasonably conclude another is the lead. Probability this is a major contributing factor: 80.

B. An inquiry exists and I was never told. For a counterintelligence matter, non-notification of the reporting party is normal practice, not neglect. I have no way to exclude this from where I sit, and neither does anyone else outside. Probability: 5. I hold this open honestly because omitting it would be the gap a critic drives through.

C. Deliberate suppression. Someone decided this specific matter should not be examined. Probability: 15. I cannot exclude it and I am not asserting it. Nothing I hold distinguishes it from the combination of A and B, and asserting it without that evidence would be the exact failure I spent Section III describing.

A cover-up is a specific act by specific people, and it can be exposed and punished. A structural seam is a permanent condition. If the reason nothing happened is that no agency owned the problem and no classification trigger fired, then the same nothing will happen the next time, and the next time may not involve me. It will involve a contractor with a laptop, or a state fusion center holding vulnerability assessments, or a consultant who assembled a criticality ranking from public data because that is now possible. There is no office whose job it is to care.

That is the finding I would put in front of the Director of National Intelligence and the Secretary of Defense, and it is the one I would ask a congressional committee to test: not whether anyone conspired, but whether there exists any mandatory reporting and investigation pathway for the theft or compromise of critical infrastructure criticality and vulnerability products held outside federal networks by academic and contractor personnel. I assess that no such pathway exists at 90, and I would very much like to be shown wrong, because being shown wrong would mean the hole is smaller than I think.

This is the part to keep. Six questions, in order, that separate an attack from an accident and a real threat from a manufactured one. They are the same questions I was trained to ask over an outbreak, where the first instinct is always to see an intentional hand and the discipline is to earn that conclusion.

One. Start with the base rate. How often does this happen with no adversary at all? Food plant fires are common, so a single fire carries almost no signal by itself. A coordinated set of intrusions across thirty water systems and seven states inside a weekend is not common, and coordination itself is signal. Before you assign a cause, know how surprised you should actually be.

Two. Separate capability from intent. What was demonstrated, and what was merely present? In Minnesota the demonstrated capability was reaching exposed controllers and locking out operators. A demonstrated intent to harm a population through the water was not shown. Do not credit an actor with an effect they did not produce.

Three. Separate affiliated from directed. Attribution is not binary. Decide on the evidence where on the spectrum from state-ordered to loosely aligned the actor sits, and say honestly how much of that is known versus assessed. The answer changes whether you are looking at a law enforcement problem or a national security confrontation.

Four. Distinguish the act from the effect. “Operators were locked out of a screen” is not “water was poisoned.” “A pump was offline for ninety minutes” is not “a city lost its water.” Hold the precise claim and refuse the inflated one until it is earned.

Five. Timestamp your certainty. Attribution firms over time and sometimes it dissolves. What was responsibly unknown on Monday can be responsibly assessed by Friday, and what looked certain in 2021 can be retracted by the FBI in 2023, as Oldsmar was. Say what you knew when, and let your confidence move with the evidence rather than with the news cycle.

Six. Ask who benefits from your fear. If overreaction serves the adversary, your composure is part of the defense. This is the question almost nobody asks and it is the one that most often keeps you from being played.

Apply the six and the two events fall cleanly apart. Minnesota: high base-rate surprise, demonstrated capability against soft targets, affiliation assessed but not confirmed, a real act whose effect was being inflated, certainty that should still be moving, and an adversary who profits from panic. Postville: low base-rate surprise, no demonstrated hostile capability, no actor, an accidental ruling already issued, and a narrative that profits from your suspicion. One is a genuine, containable intrusion. One is an accident wearing a conspiracy’s clothes.

Why spend an entire essay on how to think before spending five on what to do? Because both errors are lethal, in opposite ways.

Overreaction kills by misdirection. Call an opportunistic intrusion an act of war and you steer a national response toward escalation the facts do not warrant, while the actual vulnerability, thousands of controllers naked on the Internet and undocumented cellular modems nobody has inventoried, goes unfixed because it is less exciting than a war.

The cost of a population that cannot tell an attack from an accident is that it eventually gets both wrong, and the people who pay are never the ones who made the error. They are the six hundred in Postville looking for work, and the family in a small Minnesota town wondering, with no good way to know, whether the water is safe to give a child. Those people deserve better than a feed that alternates between panic and contempt. They deserve a straight answer about what is known, what is assessed, and what is not yet knowable.

The strongest objections to what I have argued, and my answers.

“You are downplaying a real Iranian attack on Americans’ water.” I am not. I score the intrusions real and coordinated at 90, and Part II will show exactly how exposed the water sector is. What I refuse to do is inflate operator lockouts on internet-facing controllers into a demonstrated power to poison a city, because that inflation is the effect the adversary is seeking and a serious defense cannot concede it for free.

“You dropped your Iran confidence from 85 to 65. You are hedging.” I am calibrating. When I began this piece the leaked-memo reporting was the newest input. Since then MNIT, the FBI, and CISA have all declined to attribute, officials have said they are awaiting deeper forensics, and investigators have said publicly they are examining whether the actor built a false Iranian appearance. My number should move when the evidence moves. That is the entire point of publishing numbers.

“Affiliated versus directed is hair-splitting.” It is the difference between a warrant and a war. It decides whether the right instrument is an indictment and a firewall or a national security escalation. Nations have stumbled into confrontations on looser reasoning than that.

“By the time you have finished being careful, the attack is already over.” Calibration is fast. It is panic that is slow, expensive, and hard to walk back. And the premise that caution favors the attacker is one this series will dismantle directly: governed and funded well, the defender of these systems holds advantages the attacker cannot match.

Part II, “The Utility No One Is Watching.” Minnesota was not hard to reach, and that is the scandal. Next week I take you inside the water sector: roughly fifty thousand systems, most with no security staff, running controllers that were automated for convenience and never secured. How a vulnerability disclosed and patched in 2021 was still sitting on the public internet five years later. What manipulated chemical dosing can and cannot actually do to a human being, from an epidemiologist rather than a headline writer. And the cellular modems nobody put in the inventory.

The seven letters described in Section VI are attached to this post as published. They are unedited.

[1] CBS News, “U.S. investigating whether Iran was behind cyberattack on Minnesota water systems,” 30 July 2026. https://www.cbsnews.com/news/us-investigating-iran-cyberattack-minnesota-water-systems/
[2] ABC News, “Feds issue warning to local water systems over increased cyberattacks, following Minnesota incident,” 31 July 2026. https://abc7ny.com/story/feds-issue-warning-local-water-systems-increased-cyberattacks-following-minnesota-incident/19606049/
[3] CISA Alert, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” 30 July 2026. https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
[4] CISA Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” original 7 April 2026, updated 22 July 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[5] The Register, “Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems,” 29 July 2026. https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/
[6] Fox 9, “Minnesota cyberattack on water systems: What the state knows so far.” https://www.fox9.com/news/minnesota-cyberattack-water-systems-what-state-knows-so-far
[7] KCRG, “Postville plant fire ruled accidental; community rallies for 600 people looking for work,” 29 July 2026. https://www.kcrg.com/2026/07/29/postville-plant-fire-ruled-accidental-community-rallies-600-people-looking-work/
[8] DTN Progressive Farmer, “Fire Engulfs Agri Star Plant in Postville, Iowa,” 28 July 2026. https://www.dtnpf.com/agriculture/web/ag/news/article/2026/07/28/fire-engulfs-agri-star-plant-iowa
[9] FactCheck.org, “Unfounded Claims About Frequency and Causes of Food Plant Fires.” https://www.factcheck.org/2022/05/unfounded-claims-about-frequency-and-causes-of-food-plant-fires/
[10] PolitiFact, “Fires and accidents at food plants are common, not evidence of a plot.” https://www.politifact.com/factchecks/2023/apr/26/instagram-posts/fires-and-accidents-at-food-plants-are-common-not/
[11] Associated Press, FACT FOCUS, “Food plant fires fuel conspiracy theory.” https://www.wptv.com/news/national/fact-focus-food-plant-fires-fuel-conspiracy-theory
[12] CyberScoop, “Did someone really hack into the Oldsmar, Florida, water treatment plant? New details suggest maybe not,” 10 April 2023. https://cyberscoop.com/water-oldsmar-incident-cyberattack/
[13] CISA, EPA, MS-ISAC Joint Advisory AA21-042A, “Compromise of U.S. Water Treatment Facility,” 11 February 2021. https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-042a
[14] CyberScoop, “Pennsylvania water facility hit by Iran-linked hackers,” November 2023. https://cyberscoop.com/pennsylvania-water-facility-hack-iran/
[15] WaterWorld, “Aliquippa, Pennsylvania suffers cyberattack on booster station PLC.” https://www.waterworld.com/water-utility-management/article/14302077/aliquippa-pennsylvania-suffers-cyberattack-on-booster-station-plc
[16] FBI, CISA, NSA, EPA, INCD Joint Advisory, “IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities,” 1 December 2023. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
[17] Dark Reading, “Schneider Electric: TRITON/TRISIS Attack Used 0-Day Flaw in its Safety Controller System, and a RAT.” https://www.darkreading.com/vulnerabilities-threats/schneider-electric-triton-trisis-attack-used-0-day-flaw-in-its-safety-controller-system-and-a-rat
[18] FBI, “TRITON Malware Remains Threat to Global Critical Infrastructure,” 25 March 2022. https://www.ic3.gov/CSA/2022/220325.pdf
[19] Huff AG, Hodges C, et al., “Evaluation of the Food and Agriculture Sector Criticality Assessment Tool (FASCAT) and the Collected Data,” Risk Analysis, 2015. https://onlinelibrary.wiley.com/doi/10.1111/risa.12377
[20] Recorded Future, “Iran Expands Handala Brand to Physical Threats.” https://www.recordedfuture.com/research/iran-handala-physical-threats
[21] Rockwell Automation, CVE-2021-22681, authentication bypass in Logix controllers, disclosed 2021. https://nvd.nist.gov/vuln/detail/CVE-2021-22681
[22] Letters from Dr. Andrew G. Huff to Attorney General Bondi, DNI Gabbard, Secretary Noem, Secretary Hegseth, Secretary Rollins, Director Patel, and Deputy Director Bongino, 23 March 2025. Attached to this post.

For the mathematicians:

Binomial test (the model that applies given independent draws).

General form, one-sided upper-tail p-value:

p = P(X ≥ x) = Σ (from k = x to n) [ C(n, k) · p₀^k · (1 − p₀)^(n − k) ]

where the null hit probability is:

p₀ = K / N

Fully substituted with your values (N = 2,000,000; K = 500; n = 367; x = 75; p₀ = 500/2,000,000 = 0.00025):

p = Σ (from k = 75 to 367) [ C(367, k) · (0.00025)^k · (0.99975)^(367 − k) ] ≈ 1.7 × 10⁻¹⁹¹

Expected value and dispersion under the null, for reference:

E[X] = n·p₀ = 367 × 0.00025 = 0.092
SD[X] = √(n·p₀·(1 − p₀)) = √(367 × 0.00025 × 0.99975) ≈ 0.303

Hypergeometric form (correct only if draws are without replacement, i.e., not independent; included for completeness):

p = P(X ≥ x) = Σ (from k = x to min(n,K)) [ C(K, k) · C(N − K, n − k) / C(N, n) ] ≈ 5.0 × 10⁻¹⁹⁴

No posts

Read the original on aghuff.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.