CiberLATAMbywhalemate

US Water Attacks Hit 12 States, NY Funds Defense

Water attacks in the U.S. affected at least 12 states. New York is funding 153 systems as Latin America exposes energy gaps.

Whalemate Labs · AI-assisted researchAug 10, 202638 min read

Between July 26 and 27, 2026, a coordinated campaign hit more than 30 community water systems in Minnesota, disrupting operational technology, SCADA communications, cellular telemetry, and visibility into valves, pumps, and remote controls. The wave later spread to other states and triggered federal alerts from CISA, the FBI and the EPA, which warned about rising activity against internet-exposed PLCs and other OT assets in the water and wastewater sector. Public evidence compiled in the source points to intrusions centered on industrial devices reachable from the public internet, with password changes, IP address manipulation, blocked remote access and, in some cases, forced manual operation. The material also documents boil-water notices in some areas, low pressure and temporary shutdowns of wells or plants, although there is no public evidence of deliberate contamination or a broader service collapse.

The case remains unresolved on attribution. Several news reports cited investigators who linked the activity to Iran-backed actors, especially CyberAv3ngers, but that connection is presented in multiple items as a theory or suspicion, not an official conclusion. Technical analysis in the source also agrees that the observed method did not rely on a unique zero-day. Instead, it abused direct internet exposure, weak credentials, insecure remote services and legitimate PLC engineering software. CISA’s July 22 update to advisory AA26-097A expanded the focus to Unitronics, Schneider Electric, Siemens and Rockwell Automation PLCs, while its July 30 alert urged operators to remove PLCs from public exposure, use gateways or VPNs, change default passwords and review unauthorized configurations.

In parallel, New York responded with a concrete budget decision. Governor Kathy Hochul announced more than $9 million in SECURE program funding for 153 drinking water and wastewater systems, covering cybersecurity assessments, technical upgrades and free assistance from the Environmental Facilities Corporation. The state had already imposed minimum standards in March, including mandatory training, incident reporting, risk-based protections and a designated cybersecurity lead for large systems. The move points to a regulatory response that combines funding, compliance and technical support, in contrast to the regulatory lag the source identifies in Latin America.

The Oldelval case in Argentina serves as a regional mirror. The operator of the country’s main oil transportation system reported an incident in its administrative systems, described by several reports as ransomware or as a claim associated with groups such as TheGentlemen and Incransom. The company said crude transport was not interrupted, SCADA systems were not reached and the episode came under control. Even so, the source uses the case to show a governance gap: Argentina lacks a comprehensive cybersecurity framework specific to critical energy infrastructure, and its current rules do not match Chile’s, which already has a law, notification deadlines, vital operator designations and a formal list of critical sectors that includes water and sanitation.

Executive Summary

Between July 26 and 27, 2026, a coordinated campaign hit more than 30 community water systems in Minnesota. According to the consolidated material, it affected operational technology, interrupted automated SCADA communications, disabled cellular telemetry controllers, and compromised remote access to valves, pumps and treatment equipment. The activity did not stay confined to one state. In the days that followed, the compiled coverage from CBS News, BBC News, Reuters, CNN, Associated Press, NBC News, The Guardian, Al Jazeera and others expanded the reported scope to at least seven states, and later to at least a dozen, with recurring mentions of Michigan, Minnesota, Georgia, New Jersey and South Dakota.

The public evidence in the research points to a fairly consistent operational pattern. There are no signs that ransomware was the main vector in the U.S. water campaign. There is also no public indication of custom malware or a specific zero-day exploit as the dominant mechanism. What repeats instead is abuse of internet-exposed OT devices, access to PLCs and industrial components through publicly reachable interfaces, remote password changes, IP address changes and blocking of operator access, with direct consequences for visibility, monitoring degradation and the need to switch to manual operation. CISA summarized that pattern in its July 30 alert, recommending that operators remove exposed PLCs and other OT equipment from the internet, use secure gateways or VPNs, change default credentials and review unauthorized configurations.

On July 22, CISA had already updated advisory AA26-097A to warn about cyber actors linked to Iran exploiting Unitronics PLCs with HMI, then broadened the scope to Schneider Electric, Siemens and Rockwell Automation equipment. According to the source, that update also added exfiltration of PLC project files and detection guidance for manipulation of reusable code modules. Several media outlets also reported suspicion that the campaign could be tied to Iran-backed hackers or the bogus CyberAv3ngers group. That attribution, however, remains in the realm of hypothesis or journalistic inference. No source in the package presents a definitive official attribution.

The operational impact was real, but contained. Some wells and treatment plants were temporarily offline, pressure dropped, boil-water notices were issued, and in certain cases operators moved immediately to manual control. At the same time, the sources agree there is no public evidence of deliberate contamination of drinking water or a broad service outage. The clearest reading is that this was a sabotage and disruption campaign against the OT layer, not an intrusion aimed at mass data theft or a traditional ransomware event.

The institutional response was also fast. Minnesota activated a state cybersecurity response with support from MNIT, the state health department and federal agencies. New York, by contrast, turned the threat into policy and budget. On August 3, Governor Kathy Hochul announced more than $9 million in SECURE grants for 153 drinking water and wastewater systems, aimed at cybersecurity assessments, technical upgrades and free assistance from the Environmental Facilities Corporation. The decision builds on minimum standards introduced in March, including mandatory training, incident notification, risk-based protections and a cybersecurity lead for large systems.

From a regional perspective, the Oldelval case in Argentina is the most useful contrast. The company reported an incident in its administrative systems, with crude transport continuing uninterrupted and systems later restored. But the source also notes that Argentina lacks a comprehensive cybersecurity law for critical energy infrastructure, and that the region shows uneven governance, with sector frameworks that are incomplete or fragmented. Chile stands at the other end of the spectrum, with a specific law, strict notification deadlines to the National CSIRT, designated vital operators and an explicit list of critical sectors that includes drinking water and sanitation.

Context and Background

The campaign against water systems in the United States did not emerge in a vacuum. The source shows a chain of prior alerts that helps explain why the attack surface was already well understood. On July 22, 2026, CISA updated advisory AA26-097A to warn that actors linked to Iran were exploiting PLCs across multiple critical infrastructure sectors, including water, wastewater and energy. That update already described activity against internet-exposed PLCs, with traffic observed on common industrial ports such as 22, 102, 502, 2222 and 44818. It also included concrete mitigations: keep PLCs off the internet, route remote access through secure gateways or VPNs, require MFA on access paths and segment OT communications tightly.

Shortly afterward, on July 30, CISA issued a sector-specific alert for water and wastewater. The agency said threat actors were significantly increasing activity against PLCs and other OT assets, and noted tactics such as password changes to lock out operators, IP address changes to disconnect PLCs from the network and manipulation of systems that forced some utilities into manual operation. The warning was no longer abstractly preventive. It was responding to incidents that had already occurred in the prior days and, according to the FBI, EPA and CISA, had affected at least seven states.

The source also places a key technical precedent outside the water sector. Tenable’s analysis notes that CISA added CVE-2021-22681 to the Known Exploited Vulnerabilities catalog in March 2026 after confirming use by Iran-linked actors. The flaw affects Rockwell Automation Logix controllers and allows an attacker to impersonate Studio 5000 Logix Designer engineering software to send malicious commands. CastleRockSky connects that issue to the Rockwell Automation and Allen-Bradley ecosystem that appears in the July campaign. That is not proof of authorship, but it does point to technical continuity between earlier campaigns and the Minnesota episode.

There are also direct operational precedents. Jim Guckin’s blog recalls that between late 2023 and early 2024, a group attributed to the same environment compromised at least 75 Unitronics Vision Series PLCs with HMI in critical infrastructure in the United States, Israel, the United Kingdom and Ireland, taking advantage of default passwords and direct internet exposure. The important point in that precedent is not the group name, but the persistence of the same pattern: industrial devices reachable from the public internet, weak credentials and a disruptive capability that does not require first entering traditional IT.

At the same time, technical notes from LevelBlue, Rescana and Shieldworkz converge on a similar reading. The focus was not phishing or desktop ransomware, but the OT layer: PLCs, HMIs, cellular modems, industrial routers, telemetry gateways and poorly protected remote access services. Rescana classifies the initial vector as Internet Accessible Device, MITRE ATT&CK for ICS T0883. LevelBlue adds that the public evidence does not point to a specific zero-day as the main entry point, but rather to the use of legitimate engineering software and standard industrial protocols on insecure controllers. Shieldworkz, meanwhile, argues that the synchronized outages across more than 30 systems would fit better with a shared dependency, such as an MSP, a centralized remote access platform or cellular gateways, than with separate intrusions against each utility.

This is why the state response in the United States did not stop at the single incident. New York, although not listed as affected in the campaign, chose to invest in the sector with preventive resilience in mind. The state had already introduced minimum cybersecurity standards for water utilities in March, and the August 3, 2026 announcement is aimed precisely at implementing those requirements. The contrast with Latin America is stark. The material on Argentina and Chile shows two different regulatory paths, one with robust frameworks and reporting obligations, the other with a more fragmented architecture that can help define crimes or create committees, but is still too weak to impose minimum controls on private operators of critical infrastructure.

Key Facts Table

Date Fact Source Confidence
2026-07-22 CISA updated advisory AA26-097A and warned that Iran-linked actors were exploiting PLCs in critical infrastructure, including water and wastewater. CISA Confirmed
2026-07-22 The advisory documented traffic to PLCs on common industrial ports and recommended removing PLCs from the internet and using secure gateways with MFA. Cyberpress Confirmed
2026-07-23 Oldelval appeared in ransomware listings associated with TheGentlemen. Dexpose, Darkfield, Ransomware.live Source attribution, unconfirmed
2026-07-26 More than 30 community water systems in Minnesota were attacked between July 26 and 27. Minnesota IT Services, Reuters, USA Today Confirmed
2026-07-26 Shieldworkz described disruptions to SCADA communications, cellular telemetry and OT control in several Minnesota municipalities. Shieldworkz Confirmed
2026-07-27 Rescana identified T0883, Internet Accessible Device, as the initial vector consistent with the campaign. Rescana Confirmed
2026-07-28 MNIT activated a state cybersecurity response to support more than 30 affected systems. MNIT Confirmed
2026-07-30 The FBI, EPA and CISA issued a joint alert for the water and wastewater sector. CBS News, ABC News, NBC News Confirmed
2026-07-30 CISA published a sector-specific alert about activity against PLCs in the water sector. CISA Confirmed
2026-07-31 NBC News reported the operation had all the signs of an Iranian campaign, though without official attribution. NBC News Unconfirmed attribution
2026-08-01 AP reported new cases in Michigan and said systems were operating safely. Associated Press Confirmed
2026-08-03 New York announced more than $9 million in SECURE grants for 153 water and wastewater systems. Governor’s Office, CBS6 Albany Confirmed
2026-08-04 BBC News, The Guardian and others expanded the reported scope to at least seven states and then a dozen. BBC News, The Guardian, CBS News Confirmed
2026-08-05 CBS News reported incidents in at least 12 states, with suspected links to Iran-backed hackers. CBS News Unconfirmed attribution
2026-08-06 Datatrends Latam described the Oldelval case as RaaS ransomware and used it to discuss regional governance gaps. Datatrends Latam Confirmed

Timeline of the Operation

Date Event Actor / Vector Verified Source
2026-07-22 AA26-097A advisory updated on exposed PLCs and Iran-linked actors. CISA, Unitronics PLCs, internet-exposed OT CISA
2026-07-26 Visible start of the campaign in Minnesota against more than 30 community water systems. Exposed OT devices, remote SCADA access Reuters, Minnesota IT Services, USA Today
2026-07-26 SCADA communications, cellular telemetry and wellhead and treatment controls are disrupted in several municipalities. SCADA, cellular controllers, valves and pumps Shieldworkz
2026-07-27 Rescana describes T0883 and says there are no public signs of phishing or ransomware in the water campaign. Internet Accessible Device, exposed OT Rescana
2026-07-28 MNIT activates a state response with health and federal agencies. State and federal coordination MNIT
2026-07-29 Governing and other outlets report that public attribution remains open. Ongoing investigation Governing
2026-07-30 FBI, EPA and CISA issue a joint alert about remote access to water infrastructure in seven states. FBI, EPA, CISA CBS News
2026-07-30 CISA issues a sector-specific alert and asks operators to remove exposed PLCs from the internet. PLCs, OT, public exposure CISA
2026-07-31 NBC News and ABC News detail attackers changing passwords, changing IPs and forcing manual operation. Credential changes, operator lockout NBC News, ABC News
2026-08-01 AP reports expansion to Michigan and confirms systems are operating safely. Additional affected states Associated Press
2026-08-03 New York announces more than $9 million for 153 water and wastewater systems. SECURE program Governor’s Office
2026-08-04 BBC News and The Guardian confirm there is no reported evidence of water contamination. Contained operational outcome BBC News, The Guardian
2026-08-05 CBS News raises the state count to at least 12 and mentions a possible link to Iran-backed hackers. Preliminary attribution CBS News
2026-08-06 Datatrends Latam connects the Oldelval case to governance gaps in Latin American energy infrastructure. Ransomware, governance, administrative systems Datatrends Latam

Attack Chain and TTPs

The Minnesota campaign, based on the available material, followed a relatively simple but effective sequence: internet-exposed access, credential or network parameter changes, loss of operator visibility and degradation of OT control. There is no sign of a long espionage intrusion or complex lateral movement inside office networks. The center of gravity is industrial operations technology.

The most consistent initial vector, according to Rescana, is T0883, Internet Accessible Device. That classification fits several details in the package. Shieldworkz referred to industrial cellular modems and routers, including Sierra Wireless, Cradlepoint and Moxa equipment, with default credentials, unauthenticated remote execution issues or weak VPN tunnels. LevelBlue, along the same lines, said the public evidence points to PLCs, HMI interfaces, cellular modems, poorly protected remote access services and third-party configurations in OT environments. CISA, for its part, described cases in which attackers changed passwords to block operators and altered IP addresses to isolate PLCs from the network.

That pattern suggests operational denial more than immediate physical destruction. When an attacker can change credentials, force disconnects or disable alarms, the practical result is to blind the operator. ES News, citing the FBI, said exactly that attackers can leave operators without visibility by changing passwords or disabling alarms. That explains why several utilities had to return to manual control. It also explains why boil-water notices were issued in some cases even though there was no evidence of contamination. The operational problem was not chemical. It was uncertainty about process status and the reliability of remote monitoring.

Cellular telemetry appears as a recurring support point. Shieldworkz said cellular telemetry controllers and automated SCADA communications were compromised. That kind of infrastructure typically sits between the plant floor and the central operator. If that layer is cut, the system still exists, but operations become degraded. Technicians lose telemetry, alarms and the ability to act quickly. That drives the move to manual operation and the need for local physical inspection, which is also reflected in Quadratín, NBC News and ABC News.

As for equipment families, the material points to a clear line. CISA first spoke about Unitronics PLCs with HMI. Then Tenable and CastleRockSky broadened the focus to Schneider Electric, Siemens and Rockwell Automation, and CastleRockSky emphasized CVE-2021-22681 in Rockwell Automation Logix controllers. DeNexus, more specifically, identified the publicly affected devices as Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400. That convergence suggests the campaign was not limited to a single brand, but rather to an ecosystem of exposed OT assets with similar exploitation and operational handling.

At the TTP level, the case can be reconstructed as follows: reconnaissance of exposed assets, access through internet-reachable devices, interference with authentication and addressing, loss of remote control, disruption of OT communications and a shift to manual operation. The material contains no public indicators of data exfiltration in the U.S. water campaign. There are also no ransom payments or ransomware notes. That distinction matters because it keeps this episode separate from the Oldelval case, where there are references to ransomware or leak sites, although the exact attribution is not closed and the company said physical pipeline operations were not affected.

Technical TTP Matrix

TTP / Technique Description Source
T0883 Exploitation of internet-exposed OT devices as a consistent initial vector Rescana
Public PLC exposure PLCs and other OT equipment directly connected to the internet CISA, Cloudlink Tech
Default or weak credentials Password changes or abuse to block operator access CISA, IndianWeb2, Jim Guckin
IP manipulation Changing IP addresses to disconnect PLCs from the network CISA
Alarm suppression Disabling alarms to leave operators without visibility ES News
Forced manual operation Temporary switch of utilities to manual mode Quadratín, El Comercio, ABC News
SCADA compromise Disruption of automated supervision and control communications Shieldworkz, TechRadar
Compromised cellular telemetry Disabling telemetry controllers and industrial cellular links Shieldworkz
Use of legitimate engineering software Interaction with PLCs through standard tools and protocols LevelBlue
Exfiltration of PLC project files Detection added by CISA and Tenable in the advisory update Tenable, CISA
CVE-2021-22681 Authentication bypass in Rockwell Automation Logix controllers CastleRockSky, Tenable
Common industrial ports 22, 102, 502, 2222 and 44818 observed in malicious traffic Cyberpress

Regional Impact

Regional Overview

The material is not limited to isolated incidents. It also shows how the U.S. campaign reshaped regulatory and investment conversations across the region. The American case works as a concrete demonstration of a very specific OT threat, while the Latin American cases serve to measure institutional capacity to absorb similar incidents. In that contrast, Chile appears to have the strongest regulatory maturity, Argentina still shows visible governance gaps, Uruguay has a monitoring ecosystem and national response teams, and Peru, Colombia and Brazil appear as markets that echoed the coverage without adding local evidence of physical impact on their own water infrastructure.

In the United States, the combination of a federal alert, debate over attribution and New York’s budget response shows that the impact was not only technical. It was also regulatory. A state that was not attacked decided to fund 153 utilities to close operational security gaps, with caps of $50,000 for assessments and $100,000 for improvements, plus technical assistance from the EFC. That grant structure rests on minimum standards already in force. The practical effect is twofold. It strengthens basic hygiene, and it institutionalizes a compliance process that forces asset inventory, configuration fixes and incident reporting.

The technical details matter because the attack hit the layer that moves water, not just the administrative perimeter. The material insists that water quality was not compromised. That does not reduce the seriousness. A system can keep delivering safe water and still lose telemetry, remote control and fast response capability. The business impact, operational pressure and recovery cost are real. On top of that, switching to manual operation for hours or days increases staffing burden and raises the risk of human error.

Argentina

The Oldelval case is the most useful Argentine example because it mixes a verified incident, corporate response and a regulatory gap. Oldelval informed the CNV of a cybersecurity incident in its administrative systems. The company said crude transport was not affected, that it activated its internal protocol, recovered systems and returned to normal operations. Several reports repeat that line and note that the SCADA controlling pumping and transport was not reached.

Even so, the way the source treats the case is revealing. Datatrends Latam classifies it as RaaS ransomware and uses it as an example of weak governance in energy infrastructure. Ransomware.live, Dexpose, Darkfield and other trackers list Oldelval on leak sites associated with TheGentlemen or Incransom, but those entries do not amount to an official confirmation of attribution. What remains firm is that Argentina does not have a comprehensive cybersecurity law specific to critical energy infrastructure. Law 26,388 criminalizes cyber offenses, but it does not set protection, notification or minimum-standard obligations for private operators. Administrative Decision 641/2021 creates a committee and guidelines for the public sector, but it does not solve the private critical infrastructure layer.

That gap matters beyond Oldelval. Masindustrias describes a highly uneven OT maturity level, with legacy technologies and limited real-time visibility. LACNIC, by contrast, shows that Argentina does have multiple CSIRTs and CERTs, including specialized capacity for critical sectors. The problem is not a total absence of response. It is the fragmentation of responsibilities and the lack of a binding sector framework that forces prevention, reporting and remediation under common criteria.

Chile

Chile is the most orderly counterexample in the source. The Library of Congress and Zynap summarize a cybersecurity law that covers electricity, fuels, drinking water and sanitation, as well as telecommunications and digital infrastructure. The definition of a vital operator explicitly includes institutions that provide drinking water and sanitation services. Exempt Resolution 187 reinforces that reading and ties the designation to the functional dependence of the service and the possible impact on physical operations or critical information.

The operational center is timing. Early warning to the National CSIRT must be issued within three hours. The initial update is due within 72 hours, or within 24 hours if the operator is vital and essential services are compromised. The final report must be filed within 15 calendar days. Ley21663.info adds that the criterion of significant effect, which triggers the notification duty, covers continuity of essential service, physical integrity or health of people, and personal data processing. In other words, Chile already has a reporting mechanism that fits the pace of OT incidents, where every hour matters.

Growmktech and Mister-IT Tech round out the picture with technical measures. OT segmentation into security zones, logical separation, anomaly monitoring in SCADA and PLCs, documented risk management, continuity and recovery. In Chile, the issue is not left at the level of principle. There is a framework, a classification of operators and a notification path already described in technical and legal materials.

Uruguay

Uruguay appears in the research less as an incident case and more as an institutional architecture. CERTuy is listed as the national incident response team, with public statistics on information security incidents. TIUruguay presents water treatment plants as part of the set of high-priority infrastructures under constant monitoring, alongside energy, telecommunications, transportation, finance and health. Convergint, meanwhile, describes specific services for water and wastewater, including secure access, environmental monitoring and cyber-physical threat detection.

That does not mean immunity. It means there is an institutional and market conversation around critical infrastructure. Visibility is better than in other countries in the bloc, but the source does not include a Uruguayan incident comparable to Minnesota or Oldelval in this investigation. What it does include is structure, a national CERT, semiannual statistics and a market that already sells monitoring for water and wastewater services.

Brazil

Brazil appears not through a domestic case, but as a regional amplifier of the U.S. story. Tecmundo and CNN Brasil carried the Minnesota campaign as a coordinated attack on more than 30 water systems. O Globo added that there were no signs of water alteration or risk to consumption. The value of these reports is contextual. They show that the incident was read in the region as an OT event of international scope, not just another U.S. news item.

Colombia

In Colombia, the source uses two layers. First, coverage of the U.S. attack by El Colombiano and other outlets, with emphasis that there are no signs of altered water or public risk. Second, the regulatory reading from Datatrends Latam, which notes Law 1581 on personal data protection and the SIC as data authority, but no specific cybersecurity regulation for energy infrastructure comparable to NIS2. The contrast is useful because it shows that even with personal data regulation, a country can still lack a dedicated framework for protecting critical OT infrastructure.

Peru

Peru appears as another country where the case circulated through media. El Comercio picked up the joint FBI and EPA alert and reported that some plants switched to manual operations without service interruption. WWWhatsNew, MarketScreener, Reuters and other outlets cited in the research reinforced the same framing. Peru’s contribution to the dossier is not a local incident, but the way regional coverage conveyed the scale of the event.

United States

This is the operational core. Minnesota was the initial epicenter and the state with the most public visibility. Reports later surfaced in Michigan, New Jersey, South Dakota, Georgia and others, with CBS News putting the total at at least a dozen states. Documented effects include pressure drops, boil-water notices, temporary shutdowns of wells and plants, loss of monitoring and control functionality, and the need for manual operation. Water quality was not compromised, but the infrastructure was degraded.

Georgia, according to CBS News, saw a pressure drop in Clayton County and a boil-water notice for roughly 300,000 customers in the Atlanta area. Michigan reported a small number of affected communities. New Jersey had at least two affected communities. South Dakota suffered an attack on a wastewater plant in Rapid City. Wisconsin appears as a possible affected state in some coverage, though without state confirmation. The geography confirms that the problem is not local, but sector-wide.

Technical Indicators

The consolidated material did not publish classic IOCs such as hashes, malicious infrastructure domains, IP addresses, certificates or specific malware names. It did include technical references that function as exploitation and hardening indicators. They are listed below because they may help with defensive prioritization, even if they are not traditional IOCs.

Type Value Source
MITRE technique T0883, Internet Accessible Device Rescana
PLC brand and family Unitronics with HMI CISA
PLC brand and family Rockwell Automation, Allen-Bradley, MicroLogix 1100 and 1400 DeNexus, CastleRockSky
Other brands cited Schneider Electric, Siemens Tenable
Industrial ports observed 22, 102, 502, 2222, 44818 Cyberpress
Behavior Password changes to block operators CISA, ABC News
Behavior IP address changes to disconnect PLCs CISA
Behavior Alarm suppression and loss of visibility ES News
Affected environment SCADA, cellular telemetry, wellheads, treatment, pumps, water towers Shieldworkz, TechRadar
Operational result Forced manual operation, boil-water notices, pressure loss Quadratín, The Guardian, CBS News

Analysis for Security Teams

The clearest operational lesson is that direct OT exposure to the internet remains the cheapest failure point for an attacker and the most expensive one for an operator. The material shows that the attacker did not need a sophisticated exploitation chain or a long intrusion. It was enough to find PLCs, cellular modems, remote gateways or HMI interfaces that were exposed or poorly protected. When that happens, the impact may not show up as a full service outage, but it can still mean lost monitoring, lost remote control and slower response.

For security and OT teams, the first priority is to inventory all public exposure. CISA and Nozomi Networks said that explicitly. PLCs, HMIs, industrial routers, cellular modems, VPNs and gateways reachable from the internet should be identified, and anything without a documented operational need should be removed. A device having a web or telemetry interface does not mean it should be public. If remote access is necessary, it should go through a secure gateway, MFA and IP allowlists, with logging and monitoring.

The second priority is to review default credentials and factory configurations. The campaign showed abuse of default passwords, attacker-driven credential changes and loss of operational visibility. In plants where PLCs still use static or shared passwords, the line between a minor incident and a service disruption becomes very thin. Clean PLC image backups, also recommended by CISA, are not a luxury. They are the difference between recovery and rebuilding under pressure.

The third priority is OT/IT segmentation. Growmktech proposes it for Chile, but the recommendation applies anywhere. The industrial control layer should not be tied to administrative networks, external integrator access and monitoring platforms without strict controls. The Minnesota case also suggests that shared dependencies, such as an MSP or a centralized remote access platform, can amplify the reach of an intrusion. That means third parties, support agreements, VPN tunnels and cellular gateways need the same scrutiny as internal assets.

The fourth priority is detection of unauthorized OT configuration changes. The CISA advisory and Tenable’s analysis mention manipulation of reusable modules, exfiltration of PLC project files and configuration changes. Defenders should look for anomalies in PLC programs, differences between baseline and active configuration, IP changes, alarm changes, failed logins, telemetry shutdown and any unexpected shift to manual operation. Visibility has to reach the process layer, not stop at the network.

The fifth priority is incident governance. A water utility cannot improvise what it reports, to whom and within what timeframe. Chile offers a clear model of deadlines and templates, and New York is using budget to turn minimum standards and technical assistance into practice. Weak frameworks, by contrast, end up relying on operator goodwill or media pressure. For critical infrastructure, notification time is part of control. It is not useful if the regulator hears about the incident only after it has already been resolved or after the operator has already gone back to manual mode without traceability.

At the tactical level, the case suggests reviewing five points immediately:

  1. Public exposure of PLCs, HMIs, gateways and cellular modems.
  2. Default or shared passwords.
  3. Third-party and MSP remote access without strong MFA.
  4. Configuration baselines to detect changes in PLCs and SCADA.
  5. The ability to switch to manual mode with documented procedures and periodic testing.

The Oldelval case adds a different lesson. Even though transport operations were not interrupted, the impact on administrative systems was enough to trigger protocols, notification to the CNV and later recovery. For energy, water and sanitation companies, that means the separation between administration and operations must be real, not declarative. If an administrative incident can grow to reach SCADA or telemetry, the problem is no longer just IT. It becomes a service continuity issue.

Material Limitations

The source consolidates a large number of news reports and technical analyses, but it does not contain a definitive official attribution for the campaign against U.S. water systems. Several sources mention suspicions or probabilities involving Iran or CyberAv3ngers, but those references are framed as hypotheses or preliminary assessments, not as a closed conclusion.

The package also does not include classic IOCs such as hashes, malicious domains, IP addresses, certificates or a specific malware name for the Minnesota campaign. The technical research relies on behavior, PLC families, industrial ports and observed operational patterns. That limits the ability to produce a traditional threat-hunting indicator list.

The exact scope of the affected states also varies by source and publication date. The material moves from seven states to at least a dozen. That difference is not necessarily contradictory, but it does reflect an evolving campaign with staggered reports and partial confirmations. Some mentions of Wisconsin appear as possible impacts without state confirmation.

In the Oldelval case, the confirmation of ransomware and the attribution to groups such as TheGentlemen or Incransom are not uniformly closed. The company confirmed a computer incident that affected administrative systems and not pipeline transport operations, but the ransomware readings come in part from leak sites and incident trackers. For that reason, the episode is better used as a governance and regional exposure case than as a definitive technical attribution.

Finally, regional coverage of Chile, Uruguay, Colombia, Brazil and Peru has uneven depth. Chile provides strong legal and technical material. Uruguay adds institutional structure. Colombia, Brazil and Peru appear mostly as coverage markets and receivers of the U.S. story, with less local evidence in the research. Countries without additional verifiable facts were not included because the package did not provide enough material to develop them without speculation.

Sources

View all