Daylila

Cybersecurity · Thursday, 6 August 2026

01 · Briefing · what happened

Hackers locked operators out of water plants across a dozen states - and the water kept flowing

Cybersecurity 2 min 9 sources

A wave of attacks on internet-exposed water controls hit at least 12 US states, but operators ran plants by hand and restored service in hours - a lesson in surviving a break-in, not just preventing one.

12

states hit

water systems targeted in one campaign

30+

Minnesota systems

targeted over two days, July 26-27

hours

to restore service

at a Georgia utility that lost pressure

16 yrs

prison sentence

for the Ransom Cartel operation's builder

At a glance

  • Attackers reached the digital controls of dozens of US water systems - at least 12 states hit.
  • They locked operators out of internet-exposed controllers and changed their network addresses.
  • The water kept flowing: plants ran by hand, and one Georgia utility restored service within hours.
  • CISA's core fix is resilience - pull controllers off the internet, keep clean backups to restore fast.
  • The same week's ransomware cases showed the reverse: recovery decided the outcome, not the walls.

Forces in play

Exposed controls High

PLCs reachable straight from the internet

Manual fallback Steady

operators ran plants by hand, water stayed safe

Ransomware pressure Building

Chaos, INC, SonicWall flaws chained this week

Recovery readiness Easing

clean backups and fast IR limited the damage

In play Water utilities — hit across at least 12 states; kept water flowing manually CISA + FBI — urged pulling controllers offline, keeping clean backups Ransomware crews — Chaos, INC, and others hit firms the same week River, De Bijenkorf — breached but contained fast, kept operating

How it unfolded

  1. Jul 26-27 30+ Minnesota water systems targeted
  2. Jul 30 FBI and CISA issue alerts, urge OT off the internet
  3. This week 12+ states confirmed; Chaos and INC ransomware active
  4. Now water safe, service restored; recovery is the story
Full briefing

Attackers reached the digital controls of dozens of American water systems over the past two weeks, locking out operators and disconnecting equipment. At least 12 states were hit [1]. And yet, so far, the taps kept running and the water stayed safe [1].

The intruders went after internet-exposed programmable logic controllers - the small industrial computers, or PLCs, that open valves and run pumps [3]. The FBI said the attackers targeted MicroLogix PLCs made by Rockwell Automation, changed passwords to lock operators out, and altered the devices’ network addresses to cut them off [1]. Minnesota reported more than 30 community water systems targeted on July 26 and 27; Michigan, South Dakota, and a Georgia utility confirmed activity too [1]. Wired reported that seven states’ systems were hit in a campaign likely tied to Iran [2].

The striking part is what did not happen. A Georgia utility saw reduced water pressure but restored service within hours [1]. Across the campaign there were boil-water notices and stretches of running plants by hand - but drinking water remained safe [1]. Where a computer was locked, a person could still turn the valve.

CISA, the US cyber-defence agency, told water operators to pull exposed controllers off the open internet and route remote access through a gateway instead [3]. Its most telling instruction: keep a known-clean backup of each controller’s settings, so a locked-out operator can wipe and restore it [3]. That is not advice for keeping attackers out. It is advice for getting back up fast after they get in.

The same week showed the other face of the problem - when a break-in is not survived. In a campaign Sophos calls STAC4749, attackers phoned staff over Microsoft Teams while posing as IT support, then planted Chaos ransomware [4]. One intrusion went from first access to encrypted files in under 17 hours [4]. River, a financial firm, was hit by ransomware on June 16, spotted it three days later, pulled the affected servers offline, and disabled the compromised admin accounts [5]. A Dutch department store, De Bijenkorf, was breached through a logistics supplier - but the partner blocked access at once and the stores, website, and app stayed open [6].

There was a note of consequence, too. A Belarusian man who built the Ransom Cartel ransomware operation - used against at least 18 companies - was sentenced to 16 years in a US prison [7]. Separately, the INC ransomware gang was the most active group chaining a pair of SonicWall flaws to encrypt victims for extortion [8]. Security firm Brinks Home disclosed a breach after attackers leaked its files [9].

02 · Lesson · why it matters

Why the water kept running after the break-in

You cannot keep every attacker out, so the real defence is surviving the one who gets in - detect fast, contain, recover.

How it works

  1. You cannot keep every attacker out of an exposed system
  2. So assume a break-in will happen
  3. Detect it fast, contain it, keep a manual fallback
  4. Restore from a clean backup - a bad day, not a disaster

The twist

The water systems that survived did not have better walls - they had a person who could still run the plant when the computer was locked.

Where you've seen this

Ransomware

clean offline backups turn a company-ending attack into a bad weekend

Aviation

pilots trained to fly by hand when the autopilot fails

Power grids

manual switching keeps the lights on when control software is down

The catch

Resilience buys survival, not immunity - the goal is a break-in you detect fast and recover from, not one that never happens.

Full lesson

The wall that was never going to hold

For years, the promise of security was a wall. Build it high enough, patch it fast enough, and the attacker stays outside. This week, across at least a dozen states, that promise met the real world.

Attackers reached the digital controls of dozens of American water systems. They locked operators out. They changed the addresses of the small computers that run the pumps. There was no single wall they climbed - there were thousands of small utilities, some with a cellular modem nobody had written down, each a door left ajar.

And still, the water kept running.

The quiet thing that saved the day

Look at what actually held the line. A Georgia utility lost water pressure, then restored service within hours. Elsewhere, plants ran by hand for a stretch. Drinking water stayed safe.

The systems that survived did not have better walls than the ones that got hit. They had something else: a person who could still turn the valve when the computer was locked. A backup of the controller’s settings, ready to wipe and restore. The break-in happened. It just did not become a catastrophe.

This is the shift the security world has been making for years, and it has a name: assume breach. Stop promising that no one gets in. Start designing for the day someone does.

Prevention says never; resilience says survive

A prevention mindset asks one question: how do we keep them out? It buys thicker walls, faster patches, more locks. All of it useful. None of it enough - because the attacker only has to find one door, and you have to guard them all.

A resilience mindset asks a different question: when they get in, how do we make it small and short? Detect it fast. Contain it so it cannot spread. Keep running on manual if you have to. Restore from a clean copy. Turn a break-in into a bad afternoon instead of a shuttered company.

Notice what CISA, the US cyber-defence agency, actually told water operators. Pull the controllers off the open internet, yes. But then: keep a known-clean backup of each one, so a locked-out operator can restore it. That is not advice for keeping attackers out. It is advice for getting back up after they are already in.

The same week, the other ending

The reverse case was there too. In one campaign, attackers phoned staff over a work chat tool, posed as tech support, and planted ransomware - software that scrambles a company’s files and holds them for money. One intrusion went from first access to encrypted files in under 17 hours.

The firms that came through it were the ones ready to recover. A financial firm called River spotted its ransomware in three days, pulled the affected servers offline, and cut off the accounts the attackers were using. A Dutch store breached through a supplier had the partner block access at once and kept its shops and website open. The break-in was not the disaster. Whether you could recover was.

Why this reaches your kitchen tap

It is tempting to file this under someone else’s problem - the utility’s, the IT department’s, the government’s. But you drink the water. You bank at the firm. You shop at the store.

The reason the tap still ran this week is not that the attackers were kept out. They were not. It ran because the systems were built to survive being broken into. That is a quieter kind of safety than a fortress, and a more honest one. No one can promise you a wall that never falls - not the utility, not the bank, not you with your own passwords and your own backups. The break-in is coming. The question worth asking is not whether it happens. It is whether the thing you depend on can take a hit and keep working.

From any single seat - one operator, one IT team, one regulator - you cannot see every exposed door. What you can build is a system that bends without breaking. This week, a lot of them did.

03 · Lab · your turn

Take the Hit

Rehearse how detection speed, segmentation, and backups decide whether a break-in stays small or becomes a catastrophe.

04 · Hope · carry this

The tap ran because people knew how to run their plants by hand - proof that the oldest safety net is a person who knows their work.

Across the beats