|
Nobody has to wait for an attribution ruling to know how badly exposed the water sector already is. This issue shows how to run the same exposure search researchers ran on Minnesota's water towers, using nothing but Shodan and a public IP range. A federal advisory, a presidential denial, and an unconfirmed intrusion are all sitting on top of the same public data this week, and reading it yourself is faster than waiting for the government to agree with itself. Intercept
Since 27 July, hackers have degraded operations at water utilities across seven US states by hijacking the same class of internet-facing controller: Rockwell Automation's MicroLogix 1100 and 1400. Minnesota alone reported more than thirty affected systems; victims across the campaign described flooding and loss of water pressure. The open question is whether that exposure was visible before the intrusion, or only after. Signal
Censys counts more than four thousand internet-exposed Rockwell and Allen-Bradley controllers right now, the same device family this campaign hit. The same search that found them is free, takes minutes, and works on any state's public IP space. Here is how to run it yourself. Shadow
A federal advisory names the underlying pattern as Iranian. The president publicly denies it. Neither statement is the forensic record, and the method here is how to hold both against what is actually confirmed. • • •
Section 01 of 03 · Intercept
01
Water utilities in seven US states lost control of exposed PLCs starting 27 JulyBeginning 27 July 2026, water and wastewater utilities in at least seven US states reported unauthorised access to internet-facing programmable logic controllers to the FBI. The FBI and Environmental Protection Agency named the affected device family as Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series controllers in a joint public service announcement issued 30 July. Minnesota confirmed more than thirty affected water systems, including the city of Plymouth. Michigan's Department of Environment, Great Lakes, and Energy confirmed a second cluster on Saturday, 1 August. The remaining five states have not been named publicly.
DATE · 27 Jul 2026 onward
ADVISORY · FBI/EPA PSA, 30 Jul 2026 DEVICE · Rockwell MicroLogix 1100/1400 Seven US states affected. Two confirmed by name. Five not. The exposure was flagged before this specific wave began. CISA's joint advisory on Iranian-affiliated PLC exploitation (AA26-097A), originally published April 2026, was updated 22 July 2026 to add Rockwell Automation code-tampering detection guidance and expand its scope to Schneider Electric and Siemens devices, five days before the first water utility reports came in. CISA's water-sector alert, issued 30 July, made the blind spot explicit: even utilities with mature cybersecurity processes need to validate their external connections, since the activity includes cellular modems installed by operators, vendors, or integrators that often go undocumented and fall outside routine attack-surface scans. A practitioner reading that update, or running the same class of Shodan and Censys queries it implies, would have known the device class and its exposure pattern five days before this specific wave began. That does not mean this exact intrusion was predictable. It means the technical signal for what was about to be exploited was already public, dated, and government-sourced when it happened. Section 02 walks through the search itself, and the case of a Minnesota utility where it was run after the fact. Do this now:
Run a Shodan or Censys search for Allen-Bradley or Rockwell on ports 44818, 502, 102, and 2222, scoped to any client or state IP range you cover. Cross-reference every hit against the advisory's named device models. Note the scan date; treat anything older than a few weeks as needing confirmation. Do this before assuming an advisory means someone already checked. This is not a story about Iran. It is a story about how much operational technology sits on the public internet in plain sight, indexed and searchable months before anyone with hostile intent has to try. The attribution fight tells a practitioner nothing about the exposure itself. The exposure was never secret. |


