33 Water Systems Hacked in One Weekend: Converged Security Can No Longer Wait
By David Strickland, COO of Kenton Brothers
Over a single weekend in late July, coordinated cyberattacks hit more than 30 municipal water systems across Minnesota.
In Braham, a community of about 1,700 people, attackers disabled the controls governing the city’s well and treatment plant, knocking the facility offline. The only thing standing between residents and an interruption in water service was the reserve sitting in the town’s water tower.
In Plymouth, a city of 80,000, the attack targeted cellular-connected equipment at two water towers and multiple lift stations. South St. Paul and Maple Plain reported incidents as well. And Minnesota was not alone: within weeks, federal officials confirmed similar attacks on water systems in at least a dozen states.
Let that sink in. Dozens of American communities, in one campaign, had the operational technology that treats and delivers their drinking water manipulated by a remote adversary.
The FBI, CISA, and the EPA are investigating, and while attribution has not been formally announced, the tactics closely mirror those of Iran-linked groups that have targeted U.S. water infrastructure before.
At Kenton Brothers, we have been sounding this alarm for years. This is not a cyber story. This is not a physical security story. This is a converged security story, and it is exactly the scenario we built our cyber-physical convergence practice to address.
How It Happened: A Chain of Overlooked Basics
Based on the advisories published by CISA and the EPA, the attackers did not need exotic zero-day wizardry to reach these systems. They found programmable logic controllers, the industrial devices that open valves, run pumps, and dose chemicals, exposed directly to the internet. They reached others through cellular modems that bypassed the utilities’ network security entirely. Once inside, they changed device passwords and IP addresses, locking operators out of their own equipment, and in some cases modified controller logic itself.
Every link in that chain represents a different discipline of security:
- The exposed controllers are an OT and network architecture failure.
- The unmanaged cellular modems are a procurement and process failure; somebody installed a convenient remote connection and nobody governed it.
- The default and weak credentials are a policy failure.
- And the physical mode switch on those controllers, the small key or toggle that determines whether a PLC will accept remote programming changes at all, is a physical security control failure. CISA’s own mitigation guidance tells operators to set that switch to Run and validate project files before touching it. A physical switch, in a locked panel, in a secured room, behind access control and surveillance, would have blunted the most dangerous part of this attack.
No single department owns all of those links. That is precisely the problem.
The House of Cards
Modern critical infrastructure security rests on four pillars: physical security, cybersecurity, operational technology, and the processes and procedures that tie them together. Here is the uncomfortable truth about those pillars: they do not average out. Excellence in three of them does not compensate for weakness in the fourth.
You can spend millions on firewalls and endpoint detection, and it means nothing if the control cabinet in the pump house is unlocked and unmonitored. You can install the best access control and video surveillance in the industry, and it means nothing if a forgotten cellular modem gives an attacker a direct line to your PLCs from the other side of the world. You can harden every device on the network, and it means nothing if there is no procedure requiring anyone to verify who plugged in that laptop, changed that configuration, or requested that remote session.
It is a house of cards. Pull any one card, physical, cyber, OT, or process, and the entire structure comes down. The attackers who hit Minnesota understood this instinctively. They did not attack the strongest pillar; they walked around it and pushed on the weakest one. Adversaries always will.
Why This Keeps Getting Deprioritized, and Why That Has to End
We hear the same objections in conference rooms across the Midwest. We are too small to be a target. Our systems are too obscure. We will address it in next year’s budget.
Braham, Minnesota has 1,700 residents. It was not too small to be a target. It was exactly the right size to be a target: essential services, aging infrastructure, a lean staff wearing many hats, and security spread across departments that rarely sit in the same meeting. That description fits thousands of utilities, manufacturers, healthcare campuses, and municipalities across the country, and adversaries know it.
Nation-state groups and their proxies are deliberately hunting soft targets because disrupting everyday American life is the objective. In today’s threat landscape, deprioritizing convergence is not a budget decision. It is an acceptance of risk that most boards, councils, and communities would never knowingly sign up for.
What a Converged Security Program Actually Looks Like
A converged program treats physical security, cybersecurity, OT, and process as one system with one owner and one risk picture. In practice, that means a handful of commitments:
- A unified risk assessment that walks the fence line and the network diagram in the same engagement, because the attacker does not respect the org chart.
- Hardened physical protection for cyber and OT assets: locked and alarmed control cabinets, access-controlled equipment rooms, surveillance on critical panels, and tamper detection that tells you the moment someone opens a door they should not.
- Hardened cyber protection for physical and OT assets: segmented networks, no direct internet exposure for controllers, multifactor authentication on every remote access path, and an inventory of every modem and gateway, including the ones nobody remembers installing.
- And finally, the processes and procedures that keep it all honest: change management for control systems, validated offline backups, incident response plans that are actually rehearsed, and technician practices that treat every device installation as a security event.
None of these is glamorous. Together, they are the difference between a headline and a near miss. Braham got lucky; the water tower bought them the hours they needed. Luck is not a commercial security program.
The Time Is Now
Kenton Brothers has spent 129 years protecting people, property, and possessions, and we built our CYPHY cyber-physical convergence program because the line between a physical breach and a cyber breach has disappeared. The Minnesota attacks are not an anomaly. They are a preview.
If you operate critical infrastructure, or if your organization simply depends on operational technology to function, ask yourself one question: who in your organization owns the whole house of cards? If the answer is nobody, or if the answer is four different people who have never compared notes, we should talk before someone else finds the weak card for you.
Contact Kenton Brothers today for a converged security assessment. Because in today’s threat landscape, holistic security is no longer optional. It is the whole game.


Leave a Reply
Want to join the discussion?Feel free to contribute!