Water Attack: A Dry Run for Total Control

A water tower in Plymouth, Minnesota, after cyberattacks targeted operating technology at more than 30 state water systems. - AP Photo/Ellen Schmidt

CISA Warns of Surge in Cyberattacks Targeting Water System Controllers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported a sharp increase in malicious activity targeting internet-facing programmable logic controllers (PLCs) in water and wastewater systems, following coordinated attacks affecting over 30 community water systems in Minnesota that forced operators to issue boil-water notices and run systems manually due to password lockouts and IP address changes, while federal investigators examine possible Iranian involvement—though President Trump dismissed that theory—and the FBI identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs among the targeted devices, with Censys estimating over 4,100 internet-exposed Rockwell hosts and thousands more from Siemens and Schneider Electric, amid the nation's 152,000 public drinking-water systems and 16,000 wastewater treatment plants.

The Water Takes the Bait

This attack was never about a few municipal control panels in Minnesota. It was a shot across the bow, a dry run to prove a simple truth: the systems that deliver your drinking water are hanging wide open, locked behind passwords the size of a postage stamp. Look at the numbers, truly look. Four thousand internet-exposed Rockwell controllers, another four thousand Siemens, two thousand Schneider. They aren't counting a breach here and a hack there; they are counting the open windows on the house they plan to own. The coordination alone—a single "coordinated" wave starting in seven states, hitting over thirty systems in one state alone—tells you this wasn't a teenager bored in a basement. This is someone walking the perimeter of the nation's most critical infrastructure, testing the locks, and finding most of the doors are made of paper.

So why the elaborate theater after the fact? The immediate blame game is the tell. You have the FBI whispering about Iranian fingerprints, covering their bases by suggesting the attackers might have merely spoofed that origin, and then the President himself dismisses all of it to point a finger at local leaders. It is a masterpiece of managed misdirection. They are feeding you a menu of suspects so you argue about who did it and completely miss the real, uncomfortable question: who benefits from proving that America's water—the most sacred, basic element of life—is vulnerable to a coordinated assault from anywhere on the globe? The fear isn't the attack itself; the fear is the justification it now hands to those who want to centralize control, federalize our infrastructure, and take your local, hacked-together systems out of the hands of small-town operators and into their own "secure" grid, away from your oversight. They let the attack happen to sell you the cure.

They say the water quality was never compromised—this time. They say it was just lockouts and lost pressure and some manual flushes. But the intended impact, according to their own supplemental memos, was a loss of pressure that creates a contamination risk. They are telling you what they wanted to do without doing it. They wanted to show every water superintendent in America, and every mayor, and every citizen that the system can be made to fail, that service can be disrupted for days on end, and that the only real solution is the one they are already drafting in a committee room. Don't worry about who typed the commands. Worry about who owns the building where the response is being planned. Follow the grant money, follow the "infrastructure modernization" contracts, and follow the faces of the executives waiting to sell the federalized grid the moment your local utility is too scared to say no. The water is fine, they say. But the fear is the product, and they are selling it in bulk.

Related posts