# Thirty Minnesota Water Systems Got Locked Out. The Attack Method Is Embarrassingly Simple.
Last Sunday, someone started working through a list of water utility control systems in Minnesota. By Monday, they'd disrupted more than 30 community water systems — not through sophisticated zero-days or nation-state malware, but by logging into programmable logic controllers that were sitting on the public internet and changing their passwords.
That's it. Find device. Log in. Change password. Lock out the operators. Repeat.
CISA issued an urgent advisory Thursday, and the language is as close to alarm as the agency gets in writing. Operators are urged to "remove publicly exposed PLCs and other operational technology from the internet as soon as possible." The bulletin covers all sizes of water and wastewater organizations — explicitly noting that even those with mature cybersecurity programs are in the target set. That's a pointed remark. Maturity in enterprise IT does not automatically translate to OT environments, and this attack is proving it.
## What the Attackers Actually Did
The tactics reported are not subtle. Threat actors targeted internet-exposed PLCs, changed admin passwords to lock legitimate operators out, modified IP addresses to disconnect devices from remote monitoring, and forced multiple utilities to fall back to manual operations — a contingency that works fine for a few hours but degrades quickly as an extended response.
CISA specifically called out Rockwell Automation MicroLogix 1400 controllers and pointed organizations toward vendor recovery documentation if passwords had been changed. That guidance exists because recovering access to a locked PLC without the password is not a simple process; in some configurations it requires a physical site visit and a factory reset, which means a utility operating blind while someone drives to a remote pump station.
The Minnesota IT Services agency activated the state's cybersecurity incident response plan, described it publicly as "a coordinated cyberattack targeting operational technology," and began sharing threat intelligence with affected systems. The word "coordinated" is doing real work here. Thirty utilities hit in under 48 hours is not opportunistic scanning — it's a target list being worked systematically.
## The Cellular Modem Problem Nobody Documented
Censys put numbers on the exposure landscape, and they're worse than most people assume: more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, another 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts currently reachable on the public internet. These are devices that control physical infrastructure — pumps, valves, chemical dosing systems, filtration — not web servers.
The detail buried in Censys's analysis that deserves more attention: nearly half of the exposed Rockwell devices are reachable through consumer and commercial cellular networks. Verizon Business, AT&T, T-Mobile, Comcast, Charter, Starlink — these are the ASNs hosting internet-accessible industrial controllers at American water utilities. That means a large portion of this exposure didn't come from a deliberate architectural decision to put OT on the internet. It came from a cellular modem someone installed for remote access that never made it onto the asset inventory.
CISA flagged this explicitly: "exposed operational technology may include undocumented cellular modems installed by operators, vendors, or system integrators." *Undocumented.* The utility doesn't know the device is there. The security team can't see it. The incident response plan doesn't account for it. And it's providing a path directly to a device that controls water treatment for a municipality.
## Water Has Been a Recurring Target — and Defenders Keep Learning the Wrong Lessons
This isn't the first time water infrastructure has been in the news for exactly this kind of exposure. In 2021, someone accessed the Oldsmar, Florida water treatment plant remotely and briefly increased the sodium hydroxide concentration to dangerous levels — using TeamViewer on a system visible to the internet. In late 2023, Iranian-affiliated actors hit the Municipal Water Authority of Aliquippa, Pennsylvania, targeting an Israeli-made Unitronics PLC that was reachable on a default port with a default password.
The pattern is nearly identical each time: remote access is convenient, so someone enables it; nobody documents it or puts it through a security review; the device runs with weak or default credentials; an attacker finds it through Shodan, Censys, or similar tools; and the utility finds out when they're locked out of their own equipment.
What changes after each incident is the advisory language, not the underlying architecture. Vendors patch specific CVEs. CISA issues bulletins. Utilities that were directly affected make changes. The thousands of others running similar configurations watch from the sideline and decide their systems probably aren't interesting enough to target — until they are.
## What Actually Needs to Happen
CISA's immediate recommendations are the right starting point: get PLCs off the public internet entirely. Where that's not immediately possible, put them behind a VPN or gateway device, change default credentials, and lock access to an IP allowlist. Those are not hard steps technically. They're hard organizationally, because they require budget, they require someone to own them, and they require utilities to first discover all the devices that need to be addressed — including the ones installed by a contractor two years ago and forgotten.
The Censys data on EoS firmware is a separate problem that doesn't get solved with a VPN. Many of the exposed MicroLogix 1400 devices are running end-of-sale firmware versions, which means no security patches are coming. Replacing aging OT hardware at 50,000+ water systems across the country is not a patch cycle — it's a capital expenditure problem that takes years and requires federal funding to address at scale.
---
## HackWire Analysis
The Minnesota attacks land at an interesting moment. The water sector has received sustained federal attention since the EPA's aborted attempt to mandate cybersecurity requirements in 2023, which was struck down after legal challenges from state attorneys general. The result is a sector where threat actors know federal mandates don't exist, budgets are thin, technical expertise is scarce, and the internet-exposed attack surface is publicly enumerable in real time via Censys and Shodan.
The cellular modem issue is the detail other coverage is underplaying. This isn't just a case of utilities making a deliberate choice to expose their OT — it's a case where third-party vendors and integrators install connectivity for their own access and leave behind a permanent exposure that the utility's security team may never discover through normal means. That's a supply chain problem. It means an organization can have a documented asset inventory, a firewall policy, a VPN requirement, and still be exposed because an HVAC contractor or telemetry vendor installed a cellular modem outside the approved change management process.
The "coordinated" nature of the Minnesota attacks also suggests reconnaissance preceded execution. Someone built or obtained a target list of accessible PLCs in Minnesota's water sector, validated credentials or default access, and worked through that list methodically. That tradecraft is getting easier as OT exposure data becomes more accessible. The gap between "skilled nation-state operation" and "motivated script kiddie with a Censys subscription" is narrowing for this class of attack.
For defenders: the immediate action isn't an architecture review. It's an asset discovery exercise. Find every device that can be reached from the public internet before someone else does. Cellular modems are invisible to network-layer scanning from inside the utility's infrastructure — you need to look at your vendor contracts, your remote access agreements, and ideally run an external scan against your own ASN.
— HackWire Editorial
---
## Related Coverage