This week’s Weird Week in Water, recorded with Chris Sabbarese, breaks down the coordinated cyberattack on more than 30 Minnesota water systems. Watch or listen to the full episode above, or read the recap below.
Late July. More than 30 municipal water systems across Minnesota got hit with what officials are calling a coordinated cyberattack. Plymouth, South St. Paul, Maple Plain, and Braham have all confirmed they were targeted. Within days, similar incidents turned up in at least six other states, Michigan among them.
That’s the headline. Here’s why it matters more than the ticker-tape treatment it got on the evening news.
Attackers got into internet-facing PLCs (programmable logic controllers) at water and wastewater facilities, the small industrial computers that run pumps, valves, and treatment processes. Once in, they reportedly changed IP addresses and passwords, locking operators out of their own systems and forcing several utilities into manual operation. Some communities issued boil water notices as a precaution.
Back in 2021, a plant operator in Oldsmar, Florida, watched his cursor move on its own as someone remotely tried to push sodium hydroxide levels to dangerous concentrations. In late 2023, an Iran-linked group called CyberAv3ngers broke into Unitronics PLCs at water utilities across the country, including the Municipal Water Authority of Aliquippa, Pennsylvania. The exploit there wasn’t sophisticated. The devices were sitting on the open internet with the manufacturer’s default password: 1111.
Three different incidents, three different years, one common thread. Basic industrial controllers, reachable from anywhere, protected by weak or default credentials.
California alone has more than 450 separate water agencies. Multiply that across the country, and you get a system built almost entirely on small and mid-sized operators, not a handful of giants. A utility the size of San Diego’s has a cybersecurity team, incident response plans, and budget for it. A utility supplying 10,000 people usually doesn’t. It has people working hard to keep water flowing 24/7, and historically that hasn’t included a dedicated IT security function.
That mismatch is exactly what shows up in these attacks, and it echoes a pattern I’ve seen in agriculture too: during earlier waves of ransomware activity, attackers gravitated toward smaller agricultural operations precisely because they assumed less protection. Thinking you’re too small to be a target is what makes you a target.
The scariest scenario isn’t a shutdown. It’s contamination. If an attacker gets deep enough into a treatment process, the theoretical worst case includes cross-connecting raw sewage into a drinking water line. Even setting aside the acute public health risk, there’s a slower cost: trust. Once a community stops believing its water is safe, boiling water “just in case” for weeks, that confidence takes years to rebuild, regardless of whether real harm occurred.
Civilian water infrastructure carries a kind of protected status even in the context of armed conflict. Deliberately targeting it crosses a line that most nation-states, even hostile ones, have historically avoided. Seeing it happen anyway, however preliminary the attribution, is the part of this story that deserves more attention than it got.
Nobody, structurally. There’s no single agency with operational authority over the country’s 150,000-plus public water systems. CISA and the EPA issue advisories. Responsibility for implementation sits with each individual utility. That’s the honest answer to “who’s in charge,” and it’s also the core vulnerability.
The fix, per CISA’s guidance after both the 2023 Unitronics incidents and this latest round, isn’t complicated:
Get PLCs and HMIs off the open internet entirely
Route any remote access through a VPN or firewall gateway, not a direct connection
Replace every default or shared password with something an attacker can’t guess
Require multi-factor authentication on remote access
Make sure staff can still run the plant manually if the network goes dark
None of that requires new technology. It requires utilities, especially the small ones without a dedicated security budget, treating password hygiene and network segmentation as operational necessities, not optional upgrades.
This is the third unusual water story we’ve covered in three weeks: a sinkhole swallowing infrastructure, Glen Canyon Dam’s cavitation problem threatening hydropower and water delivery to Southern California, and now a coordinated hack across seven states. I don’t think that’s a coincidence of the news cycle. Water systems, built for a century of quiet, incremental operation, are now facing physical, mechanical, and digital stress all at once, and most of them were never resourced for any one of those, let alone all three.
If you work in the water sector, in irrigation, in agtech, or anywhere near a controller that’s reachable from the internet, this is worth forwarding to whoever owns that password. It won’t cost anything to fix. It costs everything not to.
Catch the full conversation with Chris Sabbarese in this week’s Weird Week in Water episode above. New episodes every Friday, with the deep-dive newsletter every Tuesday on H2O Trends.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.