Thirty Towns Without Water Contro...

Thirty Towns Without Water Controls – Minnesota, Rigged PLCs, and the Bug That Can't Be Patched

AI
Tech Talks With Kinsoft by Steven Kinnas
Aug 13, 2026
22:22

Episode notes

Over two days in late July, a coordinated attack disrupted water and wastewater operations across more than 30 Minnesota communities — Braham's well and treatment plant shut down entirely, Plymouth disconnected cellular-connected water towers and lift stations, Maple Plain declared a local state of emergency. Drinking water quality was never affected and no boil-water advisories were issued, but the mechanism matters more than the outcome. Four days earlier CISA had expanded its advisory on Iranian-affiliated PLC targeting to cover Schneider Electric and Siemens alongside Rockwell, documented PLC project file theft for the first time, and described an FBI-observed case where malicious Add-On Instructions disabled safety shutdowns and alarms while operator displays were manipulated to show normal conditions. The central Rockwell authentication bypass (CVSS 9.8) was disclosed in February 2021, added to CISA KEV in March 2026 — and Rockwell says it cannot be fully fixed by a software patch. Censys found 5,219 internet-exposed Rockwell/Allen-Bradley hosts globally, disproportionately on cellular carrier networks, which is exactly how a small utility connects a remote water tower. Attribution: suspected, NOT formally attributed — treat nation-state headlines as speculation. Five actions for Australian businesses: inventory your control equipment and its connectivity (especially cellular routers), assume it can't be patched, segment it off the corporate network and off the internet, know and practise your manual fallback, and build an independent way to verify reality that isn't the compromised control system's own screen. Context: the ASD told Australian critical infrastructure operators on 28 July to be ready to isolate systems for three months, and the SOCI Act's eleven sectors capture far more businesses than most owners realise.

Visit www.kinsoft.com.au to talk through your security and IT needs.

Sources: Tenable Research Special Operations FAQ (28 July 2026, updated 31 July); Minnesota IT Services and municipal statements; StateScoop; SecurityWeek; CISA Advisory AA26-097A (updated 22 July 2026) and the Known Exploited Vulnerabilities catalogue; Censys internet exposure scanning (April 2026); Australian Signals Directorate critical infrastructure guidance (28 July 2026) via iTnews.