After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...
https://news.ycombinator.com/item?id=39243560
https://web.archive.org/web/20240409155326/https://www.awwa....
(cybersecurity practitioner is a component of my professional persona)
The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.
The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.
These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.
[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…
[1] https://www.epa.gov/dwreginfo/information-about-public-water...
Struggling for a source.
Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?
If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.
https://archive.org/details/operatingmanualforspaceshipearth...
If a water supply chain attack happened, we would just distribute bottled water for drinking, and people would go without washing for a few days whilst the issue was sorted.
Bottled water production is already big enough that delivering a bottle a day per person in new York is within the scale of the current production and retail networks scope.
It wouldn't cause the mass casualties an enemy might assume.
> Agriculture accounts for about 80 percent of consumptive use in the United States
https://www.nifa.usda.gov/topics/water
Maybe if we're worried about running out of water, we should prioritize getting the water we do have to actual people. Could the problem be that we're trying to grow avocados in a literal desert? Nah, it's the dang citizens taking too many showers again.
You don't need a full bidirectional internet connection for remote monitoring, and data diodes are a relatively cheap way to monitor them in complete safety.
Completely stopping ingress of control (using above mentioned data diodes) is relatively easy, and should be legislated into being the norm.
You add server to the network, it's purpose is to query, the SCADA system and get the status, error logs, process parameters, whatever you need, and spool them into a directory on a drive. A second process on that server then spools them off via a one-way optical link (high speed optocoupler, specially modified fiber link, etc) using some sort of protocol that broadcasts all the collected information, along with some form of error correction, on a continuous basis. It will do this until the end of time, never knowing if the information was recieved.
The outside server then monitors the broadcast stream, using it to update it's own directory with the relevant data, and makes it available like any normal server to an internet connection.
Because the connection has only one physical link, and it CAN NOT be reversed, ingress of control is completely prevented. Yet you can monitor the system from the outside, and never have to worry about compromise of the air-gapped network.
A pair of raspberry pi's with ethernet (and not wifi/bluetooth) could do the job.
Once it works, the "outside" host could be hacked, but it won't, CAN'T influence the other host, so things remain actually safe from remote hacking.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
This is a bit unhinged.
[Riffing on the gag, not an actual misunderstanding, just to be clear.]
The ICE budget was just increased by $70 BILLION, bringing its total to >$200 billion.
What a coward and a traitor to the American people.
I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.
I think we should think about making blatant lies by politicians a crime.
Coordinated cyberattack disrupts water utilities in 30 Minnesota communities
https://statescoop.com/coordinated-cyberattack-disrupts-wate...
https://news.ycombinator.com/item?id=49091021
[ok]
29 Jul 2026 07:47:11 UTC
Cyberattack targeted 30 Minnesota water systems
https://mn.gov/mnit/media/blog/?id=38-761869
https://news.ycombinator.com/item?id=49094533
[ok]
30 Jul 2026 17:08:40 UTC
U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems
https://www.nytimes.com/2026/07/30/us/politics/minnesota-wat...
https://news.ycombinator.com/item?id=49112788
[ok]
30 Jul 2026 23:12:21 UTC
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-...
https://news.ycombinator.com/item?id=49117018
[ok]
31 Jul 2026 13:35:38 UTC
US investigating if Iran was behind cyberattack on water systems in seven states
https://www.cbsnews.com/news/us-investigating-iran-cyberatta...
https://news.ycombinator.com/item?id=49122974
[ok]
31 Jul 2026 18:17:17 UTC
Iranian hackers likely behind Minnesota municipal water cyberattack
https://www.axios.com/local/twin-cities/2026/07/30/report-ir...
https://news.ycombinator.com/item?id=49126761
[ok]
31 Jul 2026 23:55:10 UTC
Cyberattack on water systems in multiple states has US officials on edge
https://www.cnn.com/2026/07/31/politics/sweeping-cyberattack...
https://news.ycombinator.com/item?id=49129814
[ok]
The only thing I can see is some political crony company getting a big payment from the federal budget to take on the "burden" of doing so. But then not actually distributing enough water so they can still price-gouge individuals because we wouldn't want people to become entitled, right?
28 Jul 2026 22:47:42 UTC | Coordinated cyberattack disrupts water utilities in 30 Minnesota communities | https://news.ycombinator.com/item?id=49091021
29 Jul 2026 07:47:11 UTC | Cyberattack targeted 30 Minnesota water systems | https://news.ycombinator.com/item?id=49094533
30 Jul 2026 17:08:40 UTC | U.S. Sees Iran as Likely Behind Cyberattack on Minnesota Water Systems | https://news.ycombinator.com/item?id=49112788
30 Jul 2026 23:12:21 UTC | A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran | https://news.ycombinator.com/item?id=49117018
31 Jul 2026 13:35:38 UTC | US investigating if Iran was behind cyberattack on water systems in seven states | https://news.ycombinator.com/item?id=49122974
31 Jul 2026 18:17:17 UTC | Iranian hackers likely behind Minnesota municipal water cyberattack | https://news.ycombinator.com/item?id=49126761
31 Jul 2026 23:55:10 UTC | Cyberattack on water systems in multiple states has US officials on edge | https://news.ycombinator.com/item?id=49129814
But I do appreciate the attempt anyway.
Why?
Why didn't they have firewalls, admin accounts, access rights, you know, proper security? They were glad it barely worked at all.
It would be interesting to go down this design path trying to make a generic product. I'd aim to dovetail into the bespoke engineering that PLCs already involve. I'd be tempted to design it as something like a modbus target (that PLC engineers would set up the system to write data to), except that modbus sucks rocks as a data format, never mind lacking the abstractions to do express multiples of the same systems. So then I guess you're left with some schema language that you're trying to appeal to PLC engineers to write securely. Maybe akin to the IEC 61131-3 Functional Block Diagram language, but with a very clear "this is the airgapped dividing line" ?
But in the general case, you still need to get control data back into most systems system. So your data link will likely still be bidirectional, but with the goal to keep the protocol small and simple, to keep the attack surface small.
The main problem is that it still only takes one PLC engineer to connect the two sides of the network for their own expedience. From what I can tell this is how the horror stories abound. PLCs generally use ethernet/IP these days, so one has to do deliberate work to segment the networks. And it just takes one too-smart-for-their-own-good person who wants to make that PLC available from their desk/home/vacation to ruin it.
The fuzzy way we depreciate the term Engineer shows up in situations like this. An actual Professional Engineer, with a state issued license, would be assuming liability for their actions, and would know better than to bypass an air gap in this manner.
Someone who uses the term willy-nilly, as most programmers seem to do these days, has no such restraints, nor caution, nor deep consideration of consequences.
Nor do I think that personal liability is a great avenue for moving the needle here, as that would really just be creating indirect regulation through insurance companies (with a specific focus on what the Professional Engineer might be found liable for), while creating an ongoing tax (the insurance premiums) for anyone involved in such work. Why not just write and mandate those codes directly? something like the National Electric Code but focused on best practices for setting up secure control networks.
(And while the NEC does enter into the PE dynamic, there is plenty of work subject to the NEC but that doesn't involve a PE)
If your question was only a trite recitation of the fact that private enterprise consistently refuses to practice cybersecurity then you've added nothing.
If your question was about who watches the watchers and what we're doing about the fact that private enterprise refuses to practice cybersecurity then it was an incredibly relevant statement.
You know, I said that as a joke, but...
It's getting hard to tell jokes from reality with this administration (excluding roasts at the WHCD).
Look at what 9/11 did - for quite a while after the attack, which was heinous but in the grand scheme of things nothing compared to the scale of destruction that was visited upon Iraq and Afghanistan afterwards; And at least for a few years, very many Americans were in favour of those conflicts.
You would have to fire your entire nuclear arsenal and commit mass genocide.
Even then, you may not be able to destroy the missile cities, many of them were built to be nuclear resistant.
[0]: https://www.commondreams.org/news/iran-water-desalination-pl...
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
Homosexuals.
Communists.
Islamics.
Hispanics.
Liberals.
Intellectuals.
There’s always an other. That’s what the Republicans have been doing for decades.
Please reconsider your logic. And:
> Please don't use Hacker News for political or ideological battle. It tramples curiosity.
The Blacks! hacked our firewall!
Those darn Hispanics! exfiltrated customer data!
F\*\*ing Liberals! hijacked the PLC for pump 3!
...said no one ever.