On a Sunday night in late July 2026, water operators across Minnesota began to notice that their equipment had stopped responding.

By Monday, more than 30 community water and wastewater systems were affected. In Braham, malware shut down the plant's operating controls, and the water tower couldn't be filled for over an hour. Plymouth pulled the cellular-connected gear at two water towers and several lift stations (pumping systems that move wastewater to higher elevations). Maple Plain declared a local state of emergency.

Whoever did this wasn't after billing records. The attackers went for equipment that runs the plants — the programmable logic controllers (PLCs) driving pumps, valves and treatment — and in several towns they changed the device passwords and locked operators out of their own gear. Reported effects included pressure loss and flooding, and when pressure drops in a distribution main, untreated groundwater can work its way in. This was not a data breach. Someone outside the utility had their hands on the equipment.

It didn't take a zero-day. The controllers were sitting on the internet, and the passwords hadn't been touched in years. According to reporting by the New York Times, U.S. officials suspect Iran-affiliated actors. The timing lines up with the Iranian-linked PLC activity the Cybersecurity and Infrastructure Security Agency (CISA) has been tracking since March — but the technique required no sophisticated or OT-specific capabilities. Anyone who found the devices could have done it.

The FBI has since reported similar incidents in at least seven states, and CISA's advisory now covers Schneider Electric and Siemens controllers alongside the Allen-Bradley units hit in Minnesota.

Here's the part that should get your attention, and it isn't really about water. The same controllers run wastewater lift stations, municipal power substations, traffic signals, and the heating and ventilation in your schools and county buildings. The FBI said as much in its own guidance: the hardening steps apply to government facilities and energy infrastructure as well as water. If you run IT, cyber, public works or facilities for a state or local government agency, a school district or a college campus — what the industry calls the SLED sector, for state, local, education, and government — nothing about those Minnesota utilities made them special. Their controllers were reachable and their passwords were old — two conditions that describe a great deal of public-sector equipment today.

What Minnesota just showed every public agency in the country

The federal response came fast. On July 30, the FBI and EPA issued a joint public service announcement naming internet-facing PLCs as the way in, and a CISA alert the same day said the agency is observing a "significant increase in threat actors targeting" these controllers in the water and wastewater sector. The devices involved were a common Allen-Bradley line, reachable directly from the internet. In every Minnesota utility that recovered cleanly, the fallback was the same: run the plant by hand.

I've been doing this long enough to know how these stories usually land. An attack hits a major metro with its own security team and a real budget, everyone reads the headline, and the people running a county water district or a school district's building systems figure it's a different world from theirs. That's not what happened here. These were ordinary systems, run the way most public agencies run them — two or three people covering IT and operations both, controllers that went in the ground a decade ago and haven't been touched since, and a budget built to keep the service running, not to defend it.

If you're running technology for an agency this size, take this one seriously. You don't have to be a high-value target to get hit. You just have to be reachable.

And most public-sector OT is reachable for the same few reasons.

Why public-sector systems keep showing up on these lists

Whoever is behind these campaigns may well be sophisticated. The way the attack works usually isn't. The same handful of gaps keep showing up:

  • Controllers sitting on the open internet. A cellular modem and a remote-access tool were implemented during an upgrade three years ago so a contractor could dial in, and nobody ever took it back down — as true of a lift station or a signal cabinet as it is of a pump house. 
  • No real line between the business network and OT — the operational technology t hat runs physical equipment. One phished inbox in the front office and there's a path straight to the control system — whether that's a plant, a substation, a campus energy plant, or the building automation panel running a school's HVAC.
  • Shared or default credentials. One password everybody knows, unchanged since the system was commissioned — which is how the Minnesota attackers locked operators out of their own devices without needing an exploit at all.
  • No dedicated security person. Cyber is one of three or four hats somebody already wears, and it's the one with no deadline attached until something breaks.
  • No OT-specific incident response plan. There's a plan for a phishing email. There usually isn't one for the day the controllers are locked, and the system has to be run by hand.

None of that is a knock on the people running these systems. They're doing serious work on a budget that was never built for this fight. It's just why public infrastructure keeps coming up in every threat briefing this year.

The upside is that none of those are hard problems. Most of them are cheap to fix.

Five OT security priorities I'd start with

This doesn't take a Fortune 500 budget to fix. It takes doing the right things first:

  1. Get exposed controllers off the internet. This is CISA's top ask for a reason — it's the single highest-return move you can make, and for most agencies it's a configuration change, not a capital project. Network segmentation for OT environments is a critical, bedrock consideration.
  2. Put a real boundary between IT and OT. A compromised laptop in the office shouldn't have a path to the equipment that runs the service.
  3. Know what you actually have. You can't protect a controller or an operator screen you don't have on a list, and in most agencies that list has never been written down. Start there. Every security program starts with accurate asset tracking.
  4. Get eyes on the OT network. Passive monitoring catches the password change at 2 a.m. before it becomes a shutdown at 6 a.m.
  5. Write the OT incident response plan and actually run a tabletop on it. Include the manual-operation fallback — that's what saved the Minnesota utilities that recovered cleanly. The first real incident is a bad time to find out who's supposed to call whom.

If that list is more than your team can take on right now, you're in good company. Most agencies this size work through it over two or three budget cycles — which makes what it costs the next question.

What this costs, and what to tell your board

Here's the part you'll have to defend in a budget meeting. Start with the other side of the ledger: Sophos put median recovery costs for the energy and water sectors at $3 million in 2024[1], four times the cross-sector median. That figure is ransomware-weighted and predates this incident — Minnesota's own recovery costs haven't been published, and MNIT is still assessing — but it's the right order of magnitude to set against a request measured in staff hours and a firewall.

The good news on the other side of that comparison is how little the first moves cost. The first three items above are mostly labor, not capital. Taking a controller off the internet is a configuration change and a conversation with the integrator who put the modem there. An asset inventory is a person with a clipboard and plant access for a couple of weeks — tedious, not expensive. Segmentation is the first item with real money attached, and even that is usually a firewall and a redesign of a few VLANs rather than a platform purchase. Monitoring and a retained incident-response capability are the recurring line items, and they are the ones worth putting in next year's request rather than deferring again.

When the council or the board asks — and after an incident like Minnesota's, someone will — the questions come in a predictable order:

  1. Is any of our equipment reachable from the internet right now?
  2. If someone locked us out of it tonight, could we still run the plant by hand?
  3. How long would it take us to find out it happened?

You want to answer all three from a document rather than from memory. An agency that can say "none, yes, and within the hour" is in a materially different position than one that has to go find out — and that difference is the strongest funding argument available to you.

It's also worth knowing your reporting obligations before you need them. Depending on your state and your system size, a cyber incident affecting operations may carry notification duties to your state environmental or public-utility regulator, to your primacy agency, and to CISA — on clocks measured in hours, not weeks. Those deadlines land on the worst day you'll have all year. Read them now.

How we can help

Our Global Security Solutions team does this work every day, built for public-sector budgets and procurement cycles rather than enterprise ones.

Start with the Frontier Adversary Defense Accelerator (FADA) — a short diagnostic that scores exactly the gaps behind these incidents: what's reachable from the internet, whether you'd see an intruder's traffic, how fast you'd catch a credential change. The output is a scored finding register. A Mythos roadmap then sequences the fixes into this week, this month, and this quarter. Run the phases yourself or hand us the ones you don't have staff for.

Beyond the accelerator, the services public agencies ask us for most:

  • Control system assessments — what's exposed, what's unsegmented, and what to fix first, delivered as a roadmap your own staff can execute.
  • Vulnerability management — scanning, patch prioritization, and backlog remediation.
  • Managed detection and monitoring — overnight and weekend coverage for agencies without the staff to run a 24-hour rotation.
  • Tabletop exercises built around your own scenarios: a locked controller, a substation you can't see, a building system that won't respond.

We're not going to pitch you an enterprise security buildout your agency can't fund. Start with the accelerator, fix what's actually exposed first, and take the rest of the roadmap at whatever pace your budget cycle allows — this year's or next.

Bottom line

Public infrastructure is being targeted at a scale we haven't seen before, and being small isn't protection anymore. Minnesota's water systems were the ones in the headlines, but the same exposure runs through the controllers behind power, transit, and the buildings themselves. The first moves aren't expensive: find out what you have, get anything reachable off the internet, and put a real boundary between the office network and the plant. The rest — monitoring, a tested response plan, the manual-operation fallback — costs more, and it's worth budgeting for before you need it.

Every agency I talk to is working the same problem with less staff than it deserves. If it's useful to compare notes on where yours stands, I'm glad to.

Sources: FBI/EPA Public Service Announcement I-073026-PSA (July 30, 2026); CISA Advisory AA26-097A; CISA alert on PLC targeting in the Water and Wastewater Systems Sector (July 30, 2026); Minnesota IT Services (MNIT) statewide response statement, July 2026; Sophos, "The State of Ransomware in Critical Infrastructure 2024"; The New York Times reporting on suspected attribution, July 2026.


[1] Sophos, "The State of Ransomware in Critical Infrastructure 2024" (July 2024).  https://www.sophos.com/en-us/press/press-releases/2024/07/median-recovery-costs-2-critical-infrastructure-sectors-energy-and