Shared PLC Exposure Turns One Attack Into Many

A single exposed control surface can let one disruptive campaign reach dozens of small water systems at once. The standard response would treat this as a local utility incident, but the real problem is that internet-facing PLCs give attackers a shared way into separate OT environments that were never meant to be managed as one target set. MNIT says more than 30 Minnesota community water utilities were hit over July 26-27, and reporting now points to a likely Iran-affiliated actor behind the activity. CISA’s updated guidance also puts Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs in scope, and warns that any internet-exposed PLC can be a target. That changes the containment problem. Even when drinking water and wastewater service keep running, the blast radius now includes manual operation, cross-site response coordination, and the possibility that one weak OT footprint can be used again across many small utilities.

Part of the PlainSec briefing for 2026-07-30

Sources