{"id":16547,"date":"2026-08-04T09:05:56","date_gmt":"2026-08-04T09:05:56","guid":{"rendered":"https:\/\/newestek.com\/?p=16547"},"modified":"2026-08-04T09:05:56","modified_gmt":"2026-08-04T09:05:56","slug":"the-minnesota-attackers-may-hold-a-better-backup-of-your-plant-than-you-do","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16547","title":{"rendered":"The Minnesota attackers may hold a better backup of your plant than you do"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since \u2014 including <a href=\"https:\/\/www.csoonline.com\/article\/4203638\/a-coordinated-attack-hit-30-minnesota-water-systems-who-did-it-and-what-does-a-rockwell-notice-add-to-the-picture.html\">CSO\u2019s own news analysis<\/a> \u2014 has rightly chased two open questions: Who did it, and whether a shared weakness in Rockwell Automation MicroLogix 1400 controllers tied dozens of small utilities together. Both questions matter. Neither changes what operators must do this week. Attribution is the investigators\u2019 problem. Exposure is yours \u2014 and the advisories published since July 30 contain considerably more actionable detail than most coverage has extracted from them.<\/p>\n<h2 class=\"wp-block-heading\" id=\"key-takeaways\">Key takeaways<\/h2>\n<ul class=\"wp-block-list\">\n<li><strong>Assume the attackers have your control logic. <\/strong>CISA\u2019s advisory AA26-097A documents exfiltration of PLC project files. Rockwell\u2019s recovery notice for locked-out MicroLogix 1400s requires a current offline project file to restore operations \u2014 an artifact many small utilities cannot produce. Where both are true, the adversary may hold the only current copy of the plant\u2019s logic.<\/li>\n<li><strong>You cannot Shodan your own cellular exposure. <\/strong>Researchers found little internet-facing Minnesota water infrastructure precisely because these utilities connect over cellular. The same opacity blinds defenders\u2019 self-assessments. Enumerate SIM-equipped OT devices from carrier invoices, not from network scans.<\/li>\n<li><strong>Your integrator is part of your attack surface. <\/strong>If a shared systems integrator or communications architecture connected the victims, the unit of compromise is not the utility \u2014 it is the integrator\u2019s customer fleet. Ask yours which other customers share your remote-access design.<\/li>\n<li><strong>Recovery is not resilience. <\/strong>Braham was back in roughly two hours; Plymouth ran manually while cellular links were rebuilt. Time-to-manual is a testable metric, not an assumption. Test it.<\/li>\n<li><strong>The first hardening steps are configuration, not procurement. <\/strong>RUN mode at the keypad, the strongest password protection the firmware supports, HTTP server off, no public IP. The gap exposed in Minnesota is not knowledge. It is execution order under pressure.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"the-asymmetry-nobody-is-naming\">The asymmetry nobody is naming<\/h2>\n<p class=\"wp-block-paragraph\">The most consequential sentence of the past week is buried in <a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories\/advisory.SD1790.html\">Rockwell\u2019s July 30 notice SD1790<\/a>. It is not a vulnerability disclosure \u2014 there is no CVE. The attackers did not exploit a flaw; they used the controller\u2019s intended functionality. Changing an IP address is an administrative operation, and setting a password is a security feature \u2014 the malicious element was never the command, only who issued it, from where and against which physical process. What SD1790 actually is, is a recovery procedure for operators locked out of their own MicroLogix 1400s: Power the controller off, disconnect the battery, power-cycle into a fault state, reconnect. That sequence erases the program, the data and the IP configuration. Then, the notice says, redownload your project file.<\/p>\n<p class=\"wp-block-paragraph\">That instruction presumes you have one. Current. Offline. Matching what actually runs in the field after fifteen years of undocumented tweaks by three generations of technicians and two integrators. In my project work across energy and manufacturing, that assumption fails more often than any firewall \u2014 in one plant assessment, the only person who could have restored a controller had left the integrator two years earlier, and the project file left with him.<\/p>\n<p class=\"wp-block-paragraph\">Now cross-reference the federal advisory. <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\">AA26-097A<\/a> has tracked this campaign since March; its July 22 update expanded the target set beyond Rockwell to Schneider Electric and Siemens devices, documented exfiltration of PLC project files for the first time and added detection guidance for manipulated reusable code modules embedded in PLC programs. No one has publicly confirmed exfiltration at the Minnesota utilities themselves \u2014 which is exactly why it belongs in your planning assumptions rather than your press statements. Read those two documents together and the strategic picture inverts: An adversary who may be able to study \u2014 or quietly modify \u2014 control logic that the owner cannot even restore.<\/p>\n<p class=\"wp-block-paragraph\">The countermeasure costs nothing but discipline. Treat control logic like source code. Every controller gets an offline, versioned, hash-verified project archive. Verification means uploading the running program and comparing it against the archive \u2014 not assuming the file on the engineering laptop is current. And widen the definition of backup: A rebuild-ready package includes firmware versions, HMI configuration, I\/O lists, the vendor software with valid licenses, the right cable and a record of the last authorized change. <a href=\"https:\/\/doi.org\/10.6028\/NIST.SP.1339\">NIST\u2019s OT Backup Quick Start Guide, SP 1339<\/a>, published in June, makes the same point in two pages: Create, test and review backups inside change management \u2014 otherwise they are storage, not capability. Schedule it like instrument calibration, not like an IT backup job, because that is the operational category it belongs to.<\/p>\n<h2 class=\"wp-block-heading\" id=\"you-cant-shodan-a-sim\">You can\u2019t Shodan a SIM<\/h2>\n<p class=\"wp-block-paragraph\">One detail from the investigation deserves more attention than it received: Researchers scanning Minnesota\u2019s public IP space found little obviously exposed water infrastructure. One plausible explanation, offered by researchers quoted in the initial coverage, is that many of these utilities communicate over cellular links \u2014 Plymouth\u2019s disconnection of cellular-connected equipment confirms at least part of that picture \u2014 and cellular paths are far harder to enumerate from outside than internet-facing systems.<\/p>\n<p class=\"wp-block-paragraph\">Operators have drawn comfort from the wrong conclusion. Cellular opacity did not protect the victims; it merely hid the exposure from everyone, including themselves. If a security researcher cannot see your cellular attack surface, neither can your own assessment \u2014 and that is precisely the population that got hit.<\/p>\n<p class=\"wp-block-paragraph\">There is a mundane fix, and it is the one I run in my own asset-inventory workshops: Pull the carrier bill. Every modem generates an invoice line whether or not it appears on any diagram, and the invoice regularly surfaces devices that three network revisions missed. Reconcile every SIM against a named device, a named owner and a documented purpose. <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/30\/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs\">CISA\u2019s July 30 alert<\/a> told water utilities to check for undocumented cellular modems installed by operators, vendors or system integrators \u2014 and the word undocumented is the tell: The agency assumes your architecture diagram is wrong. Then move what remains behind a private APN or VPN termination, strip every public IP and port-forwarding rule and restrict management access to known engineering workstations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"your-integrator-is-your-blast-radius\">Your integrator is your blast radius<\/h2>\n<p class=\"wp-block-paragraph\">The distributed character of this campaign is its most important feature. Dozens of geographically clustered utilities, hit in a two-day window, with neighboring infrastructure apparently untouched, points toward some common technical thread \u2014 a shared systems integrator, a shared communications architecture, a shared remote-access design.<\/p>\n<p class=\"wp-block-paragraph\">If that hypothesis holds, the defensive unit is no longer the individual utility. It is the integrator\u2019s customer fleet. A standing vendor tunnel, replicated with the same design across forty small customers, converts one compromised contractor into forty compromised water systems.<\/p>\n<p class=\"wp-block-paragraph\">Here are the three questions I put to integrators in my own projects \u2014 ask yours this week: Which of your other customers share my remote-access architecture? Who at your firm can reach my controllers today, and are those individual identities or a shared account? Can I pull the session logs myself? Then change the model: Replace standing tunnels with just-in-time access \u2014 request-scoped, time-boxed, individually authenticated with a second factor, brokered through a jump host you control, recorded. And put a notification clause in the contract: If the integrator is compromised, you hear about it in hours, not from the FBI.<\/p>\n<h2 class=\"wp-block-heading\" id=\"minnesotas-fast-recoveries-were-earned-not-lucky\">Minnesota\u2019s fast recoveries were earned, not lucky<\/h2>\n<p class=\"wp-block-paragraph\">Braham\u2019s water plant was back under operator control in roughly two hours, with no boil-water order. Plymouth\u2019s operators switched to manual operation and disconnected the compromised cellular equipment at two water towers and fourteen lift stations, keeping service running until communications were restored. None of that was produced by a security product; it was produced by operating capability that existed before the attack needed it. Restoring the screens is not the finish line, either: After an unauthorized hand has changed a controller\u2019s configuration, the first recovery question is not whether the HMI is back online but whether you can trust what it is telling you \u2014 which means verifying levels, pressures and pump states against local indicators before the display regains its authority.<\/p>\n<p class=\"wp-block-paragraph\">Manual operation is a designed capability, not a folk memory. It requires procedures that exist on paper \u2014 literally on paper, because the HMI may be what you just lost \u2014 people trained on them, and decision rights assigned in advance. The sector had, in fact, just rehearsed this: <a href=\"https:\/\/www.epa.gov\/cyberwater\/epa-2026-national-cyber-drill\">EPA\u2019s 2026 National Cyber Drill<\/a> on July 8 \u2014 18 days before Minnesota \u2014 put utilities through precisely that scenario, operating with SCADA remote connectivity, cloud services and communications degraded or unavailable. Whether that capability actually exists at your site is testable: I\u2019ve published a free, browser-based <a href=\"https:\/\/sabinefroemling-tech.github.io\/island-mode-72h-stresstest\/?lang=en\">Island Mode 72-hour stress test<\/a> \u2014 one of six no-signup companion tools I maintain openly on GitHub \u2014 that walks a site through exactly this question, from credential caches to offline backups. Joint guidance issued by CISA with its Australian, British and Canadian counterparts in late July makes the same point at doctrine level: Maintain isolation and recovery plans so essential services continue under degraded conditions, through manual or alternative SCADA paths.<\/p>\n<p class=\"wp-block-paragraph\">The decision-rights half is the part most plans skip. Which systems may a SOC or an MSSP isolate unilaterally, and which require the operator who understands the process? That is <a href=\"https:\/\/www.csoonline.com\/article\/4200141\/the-containment-paradox-why-your-ransomware-playbook-has-the-wrong-people-in-charge.html\">the containment paradox<\/a> I wrote about in these pages two weeks ago, and the water-sector version is identical: The artifact is one page, the conversation that produces it takes an afternoon, and the absence of it is what turns a two-hour incident into a two-day one.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-response-calendar\">The response calendar<\/h2>\n<p class=\"wp-block-paragraph\"><strong>Within 72 hours:<\/strong> Kill every direct external path and public IP, pull the carrier bill and flag every SIM you cannot map to a device, preserve gateway and engineering-workstation logs, verify the physical process against local indicators and upload the running logic from each critical controller to compare against your archive.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Within 30 days:<\/strong> Finish the SIM-to-asset reconciliation, rotate every credential that ever traveled through an exposed path, give every third party an individual identity with session logging and assemble a rebuild-ready package \u2014 project file, firmware version, HMI configuration, software, cable \u2014 for each critical controller.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Within one quarter:<\/strong> Run a factory-reset recovery drill on a representative controller, measure time-to-manual in a live exercise, replace the last standing vendor tunnel with just-in-time access, put the notification clause into integrator contracts and get the containment matrix \u2014 who may isolate what \u2014 signed.<\/p>\n<h2 class=\"wp-block-heading\" id=\"5-numbers-to-know-by-friday\">5 numbers to know by Friday<\/h2>\n<ol class=\"wp-block-list\">\n<li>SIM-equipped OT endpoints on your carrier invoice versus devices in your asset register. Any delta is unmanaged attack surface.<\/li>\n<li>Controllers still running default, blank or shared passwords. After this month, that number is a decision, not an oversight.<\/li>\n<li>Days since the last verified offline project-file backup, per controller. Verified means uploaded and compared \u2014 not assumed.<\/li>\n<li>Tested time-to-manual, per site. Measured in a drill, with the people actually on shift, not estimated in a workshop.<\/li>\n<li>Third parties with standing access paths into your OT. The target is zero. Everything else becomes just-in-time.<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">Attribution may firm up, or the ambiguity may itself be the point \u2014 it serves the attacker either way. The five numbers above will not tell you who attacked Minnesota. They tell you how much room the next attacker has inside your plant. The next campaign gets to learn from this one. Attribution can wait. Your exposure math cannot.<\/p>\n<p class=\"wp-block-paragraph\"><strong>This article is published as part of the Foundry Expert Contributor Network.<\/strong><br \/><a href=\"https:\/\/www.cio.com\/expert-contributor-network\/\"><strong>Want to join?<\/strong><\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>More than 30 Minnesota community water systems were hit by coordinated cyber activity against their operational technology on July 26 and 27; several lost remote control or deliberately cut it while operators contained the intrusion. The reporting since \u2014 including CSO\u2019s own news analysis \u2014 has rightly chased two open questions: Who did it, and whether a shared weakness in Rockwell Automation MicroLogix 1400 controllers&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16547\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16547","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16547"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16547\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}