Skip to content

Attacks on Minnesota water utilities: why the attackers know your facility better than you do

Bottom line: The advisories on the Minnesota water utility attacks provide concrete, immediately actionable hardening steps for OT controllers, and implementing them matters more than the still-unresolved attribution question.

In coordinated OT attacks on more than 30 municipal water utilities in Minnesota on July 26 and 27, several operators lost remote control of their facilities or deliberately cut it off to limit damage. For CISOs, the open attribution question matters less than the fact that the advisories published since July 30 contain concrete action items that have so far barely been implemented.

The incidents affected small municipal water systems that predominantly control their Rockwell Automation MicroLogix 1400 controllers via cellular connections rather than publicly reachable IP addresses. This architecture explains why internet scans such as Shodan showed little of the affected infrastructure – the attack surface remained largely invisible to both external and internal observers. CISA’s advisory AA26-097A has been tracking the underlying campaign since March and was expanded on July 22: in addition to Rockwell devices, Schneider Electric and Siemens controllers are now also within the target scope, and for the first time the agency documents the exfiltration of PLC project files as well as manipulated, reusable code modules within PLC programs. Rockwell’s own recovery guide SD1790, dated July 30, is not a vulnerability advisory with a CVE number – the attackers did not exploit a vulnerability but rather used regular device functions such as IP configuration and password protection. The described recovery procedure for locked MicroLogix 1400 controllers requires disconnecting the battery, performing a power cycle into a fault state, and then re-uploading the project file – provided that a current, offline-stored version exists in the first place.

This creates a double asymmetry for CISOs: first, a lockout can only be resolved without lasting damage if a current offline copy of the control logic is available – after years of rotating technicians and integrators, this is often not the case at many small utilities. If this copy is missing, the attackers may well hold the only current version of the plant logic. Second, cellular exposure cannot be captured through classic network scans; it must be determined via carrier billing records and inventories of SIM-based OT devices. Where a shared system integrator or a shared remote-access architecture connects multiple affected operators, the unit of compromise is not the individual utility but the integrator’s entire customer base.

Concretely, the affected facilities report varying recovery times: Braham was back in operation after roughly two hours, while Plymouth continued to operate manually while cellular connections were being re-established. This time-to-manual is a testable metric, not an assumption that should be carried unverified in emergency plans. As immediately actionable hardening measures, the advisories recommend: forcing RUN mode via the keypad, enabling the strongest password protection supported by the firmware, disabling the HTTP server, and not assigning a public IP address. There is as yet no public confirmation that project files were actually exfiltrated at the Minnesota utilities – which, according to the advisory, is no reason to rule out this possibility in one’s own planning assumptions.

Share on: