Minnesota Water OT Attacks: NC Manufacturer Defense 2026

Hackers hit 30+ Minnesota water systems in July 2026 and CISA says remove internet-exposed PLCs now. NC industrial OT defense playbook. (336) 886-3282.

Cover Image for Minnesota Water OT Attacks: NC Manufacturer Defense 2026

TL;DR: On July 26-27, 2026, a coordinated cyberattack hit more than 30 water and wastewater systems across Minnesota, knocking one treatment plant offline and forcing several communities to run controls manually. On July 30, CISA urged every water and wastewater utility to remove publicly exposed programmable logic controllers (PLCs) and other operational technology from the internet as soon as possible. The same internet-exposed PLC problem sits on the plant floors of North Carolina manufacturers, and the defense is the same: get OT off the public internet, segment it from office IT, and put a managed eye on it.

Key takeaway: If a controller that runs your production line, HVAC, or building systems can be reached from the public internet, it can be reached by an attacker. The Minnesota attacks were not sophisticated zero-days, they were exposed devices with weak or default access, which is exactly what most small industrial firms still have.

Not sure whether any of your plant-floor or building controllers are exposed? Contact Preferred Data Corporation at (336) 886-3282 for an OT exposure and segmentation assessment. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What happened to the Minnesota water utilities in July 2026?

Between July 26 and 27, 2026, attackers disrupted operational technology at more than 30 Minnesota water and wastewater systems in a single coordinated push. Minnesota IT Services confirmed more than 30 systems statewide were impacted, with named incidents in Braham, Plymouth, South St. Paul, and Maple Plain. Braham's water treatment plant went offline and residents were asked to minimize use, Plymouth reported communications problems at its water towers, South St. Paul had automated controls affected, and Maple Plain declared a local state of emergency.

Importantly, drinking-water quality was not compromised and no boil-water advisory was issued in the affected Minnesota communities. Attribution is still pending a federal investigation. Security researchers noted the timing lines up with an escalating campaign against internet-exposed industrial controllers, but no confirmed actor has been named. On July 30, a joint FBI and EPA warning identified attacks on Rockwell Automation/Allen-Bradley MicroLogix PLCs across at least seven states, signaling this is a national pattern, not a Minnesota problem.

The reason a Piedmont Triad manufacturer should care is not the specific victims. It is the method: reach an exposed controller, change its password or IP so operators are locked out, and force the plant into manual operation.

Why does an attack on water utilities matter to a North Carolina manufacturer?

Because the exact same controllers and the exact same exposure exist on the plant floor of nearly every small manufacturer. Water utilities and factories both run on PLCs from vendors like Rockwell, Schneider Electric, and Siemens, and both sectors have historically connected those devices to the internet for convenient remote access. CISA's AA26-097A advisory update on July 22, 2026 expanded the observed targeting from Rockwell devices (CompactLogix, Micro850, MicroLogix 1400) to include Schneider Electric Modicon M340 and Siemens S7-1200 controllers, the same hardware that runs North Carolina production lines, packaging systems, and building automation.

Manufacturing is already the most-attacked sector for industrial cyber incidents. Dragos found manufacturing accounted for 62% of all observed industrial ransomware victims in the first quarter of 2026. And attackers increasingly enter through exposed edge and remote-access systems: Verizon's 2025 Data Breach Investigations Report found exploitation of edge-device and VPN vulnerabilities grew nearly eightfold, from 3% to 22% of exploitation-based intrusions. An internet-facing PLC is an even softer target than a VPN, because many were never designed to face the internet at all.

Key takeaway: A controller that stops your line for a day is a ransomware-scale event without any ransomware. Downtime, spoiled product, and missed shipments are the damage, whether the motive is extortion, sabotage, or geopolitics.

Worried an exposed controller could halt your production line? Call Preferred Data at (336) 886-3282 or explore our Cybersecurity Services and Network Infrastructure Services.

How are attackers getting into these industrial controllers?

They are not defeating strong security, they are walking through open doors. According to CISA's July 30 alert, attackers in this campaign have been modifying passwords to lock out operators, disconnecting PLCs by changing their IP addresses, and forcing plants into manual operation. None of that requires a novel exploit. It requires a controller that is reachable from the internet and protected by a default, weak, or missing password.

That is the uncomfortable reality for small industrial firms: the problem is exposure and hygiene, not a lack of expensive tools. Three facts drive the risk:

  • PLCs were built for trusted networks, not the open internet. Many industrial protocols have little or no authentication by design, so exposure alone is often enough.
  • Remote access was bolted on for convenience. A controller put online so a vendor or an off-site engineer could reach it becomes reachable by everyone, including automated internet-wide scanners.
  • OT is rarely monitored. Office laptops get endpoint detection and patching, but the machine controlling a production line frequently has neither, so an intrusion goes unnoticed until the line stops.

What should NC manufacturers and industrial firms do right now?

Follow CISA's guidance and treat it as an operational checklist, not a suggestion. CISA's three immediate mitigations are the fastest way to cut the risk, and a few durable controls keep it down. Here is the practical sequence for a Piedmont Triad plant:

  1. Take OT off the public internet today. Inventory every PLC, HMI, and building controller, then remove any that are directly reachable from the internet. Route legitimate remote access through a VPN or secure gateway, never straight to the device.
  2. Enable and change passwords. Turn on password protection where it exists and replace every default or shared credential. Weak and default passwords are the campaign's primary entry point.
  3. Allowlist remote access. Permit connections only from known engineering workstations and IP addresses, so a controller answers your team and no one else.
  4. Segment OT from office IT. Separate the plant floor from business systems so a compromised email account or laptop cannot reach a controller. This is the Purdue-model principle, applied at a small-business scale.
  5. Keep known-clean PLC backups. Maintain offline images of controller programs so you can restore quickly if an attacker locks you out, and store them where ransomware cannot reach them.
  6. Add monitoring and a response plan. Put a managed eye on OT and IT together so an intrusion is caught early, and rehearse who isolates what when something looks wrong.

Internet-exposed OT versus segmented, managed OT

FactorInternet-exposed OT (common today)Segmented, managed OT
Attacker reachAny scanner on the internetOnly allowlisted engineering assets
Primary entry pointDefault/weak passwords on exposed PLCsVPN or gateway with strong auth
Time to detect an intrusionOften not until the line stopsAlerted by continuous monitoring
Recovery if locked outRebuild under pressure, extended downtimeRestore from known-clean PLC backups
Typical impactPlant offline, spoiled product, missed shipmentsContained, minimal or no downtime

Ready to get your controllers off the internet and behind a managed perimeter? Call (336) 886-3282 or explore our Managed IT Services and manufacturing IT expertise.

How does Preferred Data secure OT for small industrial businesses?

Preferred Data Corporation has served North Carolina manufacturers and industrial firms since 1987, and OT security is where our plant-floor experience and our IT discipline meet. We start with an exposure assessment, using the same approach an attacker would to find any controller reachable from outside, then we bring those devices behind a secure remote-access gateway. We segment OT from office IT so one phished laptop cannot reach a production line, harden credentials and access, and stand up monitoring that watches IT and OT together. We also make sure controller programs are backed up offline so a lockout is a quick restore rather than a shutdown.

Because we are local, on-site within 200 miles of High Point, we can walk your floor, see how your lines and building systems are actually wired, and fix the exposure in person rather than over a ticket queue.

Get an OT exposure and segmentation assessment. Contact Preferred Data Corporation at (336) 886-3282. We deliver Cybersecurity, Network Infrastructure, Managed IT, and Backup and Disaster Recovery for manufacturers across the Piedmont Triad. Serving the region since 1987, BBB A+ rated.

Frequently Asked Questions

What is a PLC and why is it a security risk?

A programmable logic controller (PLC) is the small industrial computer that runs machinery, production lines, HVAC, and building systems. Many were designed for trusted internal networks with little or no authentication, so when they are connected directly to the internet for remote access they become easy targets. In the July 2026 campaign, attackers reached exposed PLCs and locked out operators by changing passwords and IP addresses.

Were the Minnesota water attacks a sophisticated hack?

No. The attackers exploited exposure and weak access rather than novel vulnerabilities. More than 30 Minnesota water and wastewater systems were disrupted on July 26-27, 2026 by reaching internet-facing controllers and forcing plants into manual operation. Drinking-water quality was not affected and no boil-water advisory was issued, but one treatment plant went offline.

My business is a manufacturer, not a utility. Am I actually at risk?

Yes. Factories and utilities run the same PLC brands, Rockwell, Schneider Electric, and Siemens, and share the same habit of exposing controllers to the internet for convenience. CISA's July 22, 2026 advisory update expanded observed targeting across all three vendors, and manufacturing was 62% of industrial ransomware victims in Q1 2026, so an exposed controller on a plant floor is a live risk.

What is the single most important step to take?

Get operational technology off the public internet. Inventory every controller, remove direct internet exposure, and route any remote access through a VPN or secure gateway with strong, non-default passwords and IP allowlisting. That one change removes the exact door attackers used in this campaign.

What is OT and IT segmentation?

Segmentation means separating your plant-floor or building-control network (OT) from your office network (IT) so a compromise on one side cannot spread to the other. If an employee's laptop is phished, segmentation keeps the attacker away from the controllers that run your equipment. It is the small-business application of the industrial Purdue model.

Can Preferred Data help if we are not sure what controllers we even have?

Yes. Most small industrial firms do not have a current inventory of their OT, so we start there, discovering every PLC, HMI, and building controller, identifying what is exposed, and then securing it with segmentation, hardened remote access, monitoring, and offline backups. We serve manufacturers across High Point, Greensboro, Charlotte, Raleigh, and the greater Piedmont Triad.

Support