logo

Water Under Attack: A Decade of Warnings, and the Same Gaps Still Open

ID: 5cece0d0-84fd-58b5-a476-7b3a901740ee

STIX ID: report--5cece0d0-84fd-58b5-a476-7b3a901740ee

Feed Name: Dragos Blog

Threat Score
80/100

Date Published: 2026-08-13

Date Updated: 2026-08-19

...
...

**Executive summary:** The report compares the 2013 Bowman Dam intrusion and the July 2026 Minnesota PLC incidents to show persistent, systemic OT security gaps in the water sector: internet-exposed controllers, weak/default credentials, lack of segmentation and monitoring, and delayed patching (notably CVE-2021-22681). Both events involved Iran-affiliated actors (including CyberAv3ngers), caused loss of operational visibility/control across multiple utilities (30+ in Minnesota, spanning at least seven states), and demonstrate that adversaries are reusing a documented playbook — the sector must remove OT from the public internet, implement OT-aware visibility and vulnerability prioritization, and adopt collective defense and coordinated incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.