Guest Column | August 27, 2026

SWAN Corner: From Warning To Reality — Lessons From The Latest OT Attacks On Water Utilities

By Tobias Nitzsche

Phishing Cyber Security Ransomware-GettyImages-2233776792

The Scenario We Described Has Arrived

On July 10, I published an article on Water Online warning that water and wastewater utilities had become prime targets for state-sponsored cyber actors.1 I described how attackers exploit internet-exposed PLCs, how the IT/OT divide leaves organizations vulnerable, and why the sector needed to act before an incident forced their hand.

Today, that scenario is no longer hypothetical.

Between July 26 and 27, more than 30 community water systems in Minnesota were hit in a coordinated cyberattack.2 Operators were locked out of their systems. Passwords were changed. IP addresses were modified. Some facilities lost pressure. Others issued boil-water notices. Within days, the FBI confirmed that water utilities in at least 12 states had reported incidents, with some experiencing operational degradation, flooding, and extended manual operations.3

On the same weekend, a small power generation plant in the United Kingdom was knocked completely offline by attackers using similar techniques. It stayed dark for four days.4 The UK National Cyber Security Centre briefed energy company executives and issued guidance to the sector.

These were not isolated opportunistic attacks. They were coordinated, multi-vendor, and designed to cause physical disruption.

How The Campaign Unfolded

The pattern became visible in hindsight. On April 7, CISA published advisory AA26-097A documenting Iranian-affiliated actors, specifically the IRGC-linked group CyberAv3ngers, targeting internet-exposed Rockwell Automation PLCs.5 At that stage, the activity was primarily reconnaissance: mapping infrastructure, testing access, probing defenses.

On July 22, CISA abruptly updated the advisory. The scope had expanded dramatically. Attackers were no longer limited to Rockwell devices. They were compromising Siemens S7-1200 series PLCs and Schneider Electric Modicon M340 controllers.5 More concerning, they had graduated from simple scanning to using legitimate vendor engineering software to steal project files and manipulate controller logic.

Then came the late July strikes. The Minnesota attacks hit more than 30 facilities simultaneously. In Braham, a community of 1,700 people, the attack disabled computerized controls and temporarily shut down the city’s well and water treatment plant. In Plymouth, population 80,000, IT staff disconnected cellular-connected equipment at water towers and wastewater lift stations to stop the attack.2 Maple Plain declared a local state of emergency.

On July 30, CISA, the FBI, and the EPA issued an emergency sector-wide alert.3 On August 19, a joint advisory from the NSA, FBI, DOE, EPA, and CISA warned of an active threat to all Siemens S7 Series PLCs across multiple critical infrastructure sectors.6

The Attack Pattern: No Zero-Days Required

The attackers are not exploiting sophisticated zero-day vulnerabilities. They are exploiting basic misconfigurations and poor security hygiene.

The pattern is straightforward. Attackers scan the internet for exposed PLC ports: Port 102 for Siemens S7 protocol, Ports 44818 and 2222 for Rockwell EtherNet/IP, Port 502 for Modbus on Schneider Electric devices. According to Censys, as of July 30 there were over 4,100 Rockwell EtherNet/IP hosts, over 4,100 Siemens S7-1200 hosts, and over 2,000 Schneider Electric hosts visible on the public internet.7

Once they identify an exposed device, attackers attempt default credentials or brute-force access. If successful, they use the manufacturer’s own legitimate engineering software, such as Rockwell’s Studio 5000 Logix Designer, Siemens TIA Portal, or Schneider’s EcoStruxure Control Expert, to connect to the controller.

From there, they do not just format the device or demand ransom. They alter project files and overwrite ladder logic. They inject malicious code into reusable modules. They manipulate the data sent to HMIs so operators cannot see what is happening in real time. The result: physical processes run outside safe parameters while the control room displays show everything is normal.

Federal agencies have confirmed that attackers are using AI to generate exploit scripts and accelerate reconnaissance, dramatically reducing the time and expertise required to identify and compromise vulnerable systems.6

Fundamentals First

There is a temptation after incidents like these to reach for the newest, most sophisticated security products. Vendors will line up to sell AI-powered threat detection, advanced behavioral analytics, and next-generation intrusion prevention systems. Some of these tools have their place. But they are not what would have needed to prevent the Minnesota attacks.

The utilities that were compromised in late July were not breached because they lacked cutting-edge technology. They were breached because PLCs were exposed to the public internet. Because default passwords had never been changed. Because remote access was not routed through secure gateways. Because nobody had a complete inventory of what was connected and where.

The fundamentals matter. Before investing in advanced shiny and costly solutions, water utilities need to answer basic questions: Are your PLCs accessible from the internet? Do you know every device on your OT network? Are remote connections secured with VPNs and multifactor authentication? Do you have tested, offline backups?

This is not glamorous work. It does not make for exciting conference presentations. But it is the work that stops attacks.

What does a practical implementation look like? Three categories of tools address the gaps exposed by the July attacks.

First, utilities need a unified security management platform that brings together your foundational security like backup status, patch levels, malware protection, and access controls into a single view. Most water utilities do not have dedicated security operations centers. Staff wear multiple hats. A consolidated dashboard makes it possible to maintain security hygiene without requiring a full-time team. At ABB, we call this the Cyber Security Workplace.8

Second, remote access needs to follow zero trust principles. Every connection should be authenticated, authorized, and logged. Network configurations should change dynamically so that even if an attacker gains access, they cannot maintain persistence. This approach, sometimes called Moving Target Defense.

Third, detection capabilities need to be tuned for OT environments. Generic IT security tools generate noise because they do not understand industrial protocols. Purpose-built OT event monitoring can identify lateral movement, unauthorized configuration changes, and anomalous traffic patterns specific to control systems. The Minnesota attacks showed how operators were blind until they were locked out. OT-specific event monitoring provides the visibility to detect intrusions while response options still exist.10

The point is not that any single vendor has all the answers. The point is that these capabilities exist, they are mature, and they address the specific attack patterns we saw in July. The water sector needs to stop treating foundational security as a checkbox exercise and start treating it as the core of their defense strategy.

When Theory Meets Reality

In my July article, I outlined five questions every water utility should answer. The events of late July and August validate each of them.

I asked whether asset criticality drives backup frequency and design. In Minnesota, facilities that could restore from clean backups recovered within hours. Those without tested offline backups faced extended manual operations.

I asked whether spare strategies match recovery time objectives. The UK power plant that went dark for four days likely had cold spares, not warm ones. Four days of downtime suggests a recovery process that was never stress-tested against an aggressive RTO.

I asked whether vendor SLAs cover the full incident lifecycle. Multiple reports indicate that affected utilities struggled to get forensic support and containment expertise. When your vendor’s scope ends at “get the system running again,” you are on your own during the investigation phase.

I asked whether disaster recovery plans include tested communication protocols. Several Minnesota communities had to coordinate with state agencies, the FBI, and media outlets simultaneously. Those with rehearsed communication plans managed the situation more effectively.

I asked whether tabletop exercises include OT-specific scenarios. The utilities that responded fastest were those where operations staff had trained alongside IT security teams and could distinguish between a system malfunction and a cyberattack.

What Needs To Change Now

Internet-exposed PLCs are not a theoretical risk. They are an active liability.

CISA’s guidance is unambiguous. Disconnect PLCs from the public internet. Route remote access through VPNs or gateway devices. Enable password protection and change default credentials. Allowlist IP addresses so only authorized engineering workstations can connect. For Rockwell CompactLogix and MicroLogix devices with physical mode switches, place the switch in RUN position to prevent unauthorized program changes.3

For water utilities with geographically distributed infrastructure, cellular-connected PLCs deserve special attention. The Plymouth attack specifically targeted cellular-connected equipment at water towers and lift stations. Consumer cellular modems should be replaced with industrial cellular gateways that support VPN tunnels and multifactor authentication.

Beyond the immediate technical fixes, utilities need to audit their OT asset inventory. Many organizations do not have a complete picture of what is connected, where, and how. You cannot protect what you do not know exists.

Finally, this is the moment to revisit vendor relationships. If your automation vendor cannot support you through investigation, containment, and eradication, not just recovery, you need to renegotiate that SLA.

The Window For Preparation Has Closed

In my previous article, I wrote that the question was no longer whether your utility would face a cyber incident, but when. For dozens of utilities across at least 12 states, that question has been answered.

The attackers have demonstrated capability and intent. They have shown they can compromise multiple vendors, multiple sectors, and multiple countries in a coordinated campaign. They have shown they can cause physical disruption, lock out operators, and manipulate processes while hiding the evidence from control room displays.

The good news is that the fundamentals still work. Utilities that had removed PLCs from the internet were not affected. Utilities with tested backups recovered quickly. Utilities with trained staff and clear communication plans managed the crisis effectively.

The path forward has not changed. Get the basics right. Test your assumptions. Train your people. Build relationships with vendors and partners who can support you through the full incident lifecycle.

The difference is that this is no longer preparation. It is active response.

References

  1. Nitzsche, T., "From Compliance to Resilience: Practical Lessons in OT Recovery for Water Utilities," Water Online, July 10, 2026. https://www.wateronline.com/doc/from-compliance-to-resilience-practical-lessons-in-ot-recovery-for-water-utilities-0001
  2. Tenable, "Coordinated Cyberattack on Minnesota Water Utilities: What You Need to Know," August 2026. https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know
  3. CISA, "CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs," July 30, 2026. https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
  4. Help Net Security, "Suspected Iran-linked attack knocked UK power plant offline for days," August 24, 2026. https://www.helpnetsecurity.com/2026/08/24/uk-power-plant-cyberattack/
  5. CISA, "Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," April 7, 2026 (updated July 22, 2026). https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
  6. NSA/FBI/DOE/EPA/CISA, "Joint Advisory AA26-231A: Defending Against an Active Threat to Siemens S7 Series PLCs," August 19, 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a
  7. Censys, "CISA Alert: Water Sector PLC Targeting," July 30, 2026. https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
  8. ABB, "ABB Ability Cyber Security Workplace." https://new.abb.com/process-automation/process-automation-service/advanced-digital-services/cyber-security/abb-cyber-security-services/abb-ability-cyber-security-workplace
  9. ABB, "Key cyber security trends to watch in 2025," January 2025. https://new.abb.com/news/detail/123029/key-cyber-security-trends-to-watch-in-2025
  10. ABB, "ABB Ability Cyber Security Event Monitoring." https://new.abb.com/process-automation/process-automation-service/advanced-digital-services/cyber-security/abb-cyber-security-services/cyber-security-event-monitoring

Tobias Nitzsche is Head of Legislation and Technology, Cyber Security at ABB. He works with critical infrastructure operators across the energy and water sectors on OT security strategy, incident response, and regulatory compliance. His previous article, "From Compliance to Resilience: Practical Lessons in OT Recovery for Water Utilities," was published on Water Online in July 2026.


SWAN, the Smart Water Networks Forum (SWAN), is the leading global hub for the smart water sector. A UK-based non-profit, SWAN brings together leading international water utilities, solution providers, academics, investors, regulators, and other industry experts to accelerate the awareness and adoption of “smart,” data-driven solutions in water and wastewater networks worldwide. Learn more at www.swan-forum.com.