The Attackers Didn’t Need to Be Clever. Minnesota’s Water Systems Left the Door Open.

minnesota water utility attack portnox

Schedule a Portnox Cloud demo today.

Contents

Thirty plus water utilities in Minnesota got hit at the end of July. Cellular modems bolted onto PLCs by a system integrator years ago, still phoning home to the internet, still running default credentials, likely forgotten for a while at this point. Add a known auth bypass in the Rockwell engineering protocol, CVE-2021-22681 (unpatchable because it’s a design flaw in the challenge-response scheme, not a bug you can push a fix for), and you’ve got a group that didn’t need to be clever. They just needed a device that was reachable.

Everyone wants to talk about Iran; fair enough. The tradecraft lines up with CyberAv3ngers, the timing lines up with a CISA advisory update four days prior, and IRGC-linked units have run this exact playbook against water utilities since 2023. But I’d argue the attribution conversation is doing a lot of work to distract from the actually embarrassing part of this story, which is that we keep finding out about internet-facing OT equipment after someone else finds it first.

The part nobody wants to own

I’ve spent enough time in incident response to recognize the shape of this one from a mile away, because it’s not a new shape. It’s the same shape as Aliquippa, Pennsylvania in 2023, when CyberAv3ngers walked into a booster station through an internet-exposed Unitronics PLC running a default password. Different vendor, different device family this time around, but the same root failure. A device gets installed, it works, everyone moves on to the next fire, and the fact that it’s sitting on the open internet with weak or default credentials becomes tribal knowledge that eventually nobody remembers.

That’s not a nation-state problem. That’s an asset inventory problem. Iran, or a bored teenager with Shodan and some patience, is going to find the same exposed controller either way. The IRGC angle makes for a better headline. It does not make the underlying failure any more sophisticated.

Where this gets uncomfortable for my side of the industry

Here’s the part I won’t dress up. A chunk of these PLCs had their own cellular connections, bridged straight out, completely independent of whatever network the utility thought it was securing. If a controller’s uplink never touches your monitored network, no amount of segmentation, fingerprinting, or access policy on that network does anything for you. You cannot enforce a policy on a path you don’t know exists. That’s true no matter whose logo is on the dashboard.

So before anyone in security vendor land, myself included, points at this incident and says “see, this is why you need X,” the honest first move is systems integrators and utilities doing the unglamorous work of finding every device with its own uplink and killing the ones that shouldn’t have one. That’s not a product. That’s a flashlight and an afternoon.

What prudent access control actually buys you

Once you’ve found the things, and you will find things you didn’t know were there, the question becomes what happens next. Does an engineering workstation that’s never talked to a PLC before get to start pushing ladder logic to it at 2am on a Sunday? Does a device that fingerprints as a ten year old Allen-Bradley controller get to sit on a flat network next to everything else? Access control, done well, is the difference between “we found the exposed device” and “we found the exposed device after it had already been talking to something in another country for six months.”

That’s the whole pitch, and it’s not a complicated one. Least privilege for machines, not just people. Know what’s on your network before someone else tells you. Segment so that a compromised PLC is a contained problem instead of a lateral movement highway. None of that requires a specific vendor, and none of it requires Iran to be the culprit for it to matter. It would have mattered just as much if this had been financially motivated ransomware or a curious grad student.

The boring truth

Just like the movie WarGames was never really a story about AI gone rogue, it was a story about a kid who found a modem nobody was watching, Minnesota’s water utilities weren’t breached by a sophisticated adversary. They were breached by the same three failures that show up every single time. Default credentials. Undocumented exposure. No segmentation between “thing that manages physical infrastructure” and “the entire internet.” The attacker’s flag doesn’t change any of that math.

If there’s a lesson here worth actually acting on, it’s not “buy a NAC platform.” It’s “go find out what’s plugged into your network right now, today, before you find out from CISA.” Everything else, the fingerprinting, the segmentation, the access policies, is just what you do once you’ve stopped being surprised by your own infrastructure.

Share

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

Related Reading

Network Access ControlSecurity Trends

Your NAC Admin Just Got an AI Assistant (Here’s How to Keep It Honest)

August 2, 2026
Security Trends

We Just Got Our First AI Insider Threat, and Nobody’s Ready for It

July 22, 2026
Articles

Portnox CFO Bryce Birdsong Named One of Austin’s Best CFOs

July 22, 2026

[Webinar with Forrester] The Identity Blind Spot: AI Agents & Access Control (Sept. 10)

X