Technology Innovation Partners

Small Towns. Big Vulnerability. Water Systems Under Attack.

By Mark Putiyon·August 6, 2026·3 min read

Small Towns. Big Vulnerability. Water Systems Under Attack.

Last Sunday, while most of us were grilling in the backyard, hackers were busy breaking into water systems across Minnesota. Not one or two. Thirty-plus communities. Braham, Plymouth, South St. Paul, Maple Plain. Places you've never heard of, with populations you could fit in a high school gym.

And that is exactly the point.

I've been in IT for over 30 years. I've seen ransomware hit hospitals, Crypto locker locks up small businesses, and phishing emails fool smart people. But this one is different. This is not about stealing data or extorting money. This is about turning off the water.

What Actually Happened

Between July 26 and 27, a coordinated cyberattack hit water and wastewater systems across Minnesota. The attackers went after PLCs, programmable logic controllers. Think of PLCs as the thermostats of the industrial world. They control pumps, valves, chemical dosing, and pressure. They tell the water where to go and how clean to be when it gets there.

In Braham (population 1,700), the attack disabled computerized controls and shut down the city's well and water treatment plant. Crews scrambled and got it back in about two hours. In Plymouth (population 80,000), the city had to physically disconnect cellular-connected equipment at water towers and lift stations to stop the bleeding.

Let that sink in. They had to unplug the WiFi to keep hackers away from their water.

The FBI says attacks have now spread to seven states. CISA issued an advisory warning of a "significant escalation" in attacks targeting PLCs. And here's the kicker, the vulnerability being exploited (CVE-2021-22681, if you like your CVE numbers) has a CVSS score of 9.8 out of 10 and there is no patch. None. Rockwell Automation says it can't be fixed with software. The only fix is architectural: segment your networks, lock down your PLCs, and get them off the public internet.

Why Small Utilities?

Because they're easy targets. Most small water systems don't have a CISO. They don't have a security operations center. They have Bob, who also fixes the trucks. Many use consumer remote access tools like TeamViewer to manage their systems. Some have their PLCs directly on the public internet with default passwords. The EPA warned in 2024 that over 70% of US water systems were failing to meet basic cybersecurity requirements.

There are roughly 150,000 to 170,000 water systems in America. Most are small, rural, and underfunded. Censys found 3,891 internet-exposed Rockwell Automation devices just sitting there, waiting.

Who Is Doing This?

The prime suspect is a group called CyberAv3ngers, linked to Iran's Islamic Revolutionary Guard Corps. The US Treasury sanctioned six of their officials in 2024. The State Department is offering 10 million for information on them. And this isn't their first rodeo, they hit the Municipal Water Authority of Aliquippa, Pennsylvania, back in 2023.

The timing matters. The US and Iran have been in active armed conflict since February 2026 (Operation Epic Fury). In June, US strikes destroyed a water facility near the Strait of Hormuz. The next day, an Iran-linked group claimed it breached water utilities in California as a retaliatory warning. Now 30+ Minnesota communities are hit.

Coincidence? Maybe. But I've been doing this long enough to know that in cybersecurity, coincidence is usually just evidence you haven't found yet.

What Should You Do?

If you run a business that depends on water (and that's every business), here are three things to do this week:

1. Ask your water utility one question: "Are your PLCs exposed to the internet?" If they don't know, that's your answer.

2. Segment your networks. Your email server and your water pumps should not be on the same network. Ever.

3. Get offline backups. If someone modifies your PLC logic, you need a clean copy to restore from. Store it on physical media, not in the cloud.

Cybersecurity isn't just about protecting your data anymore. It's about protecting your water, your power, your life. The attackers figured that out before most defenders did.

Don't be the last to know.

What is your community doing to protect its water infrastructure? Please comment below, I value your input.

Originally published by Mark Putiyon on LinkedIn. Join the discussion there.

Read on LinkedIn
MP
Mark Putiyon

Founder of Technology Innovation Partners — 30+ years helping businesses secure and modernize their IT.