Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
13:24
In late July 2026, more than 30 community water systems in Minnesota were hit in a coordinated cyberattack that spread within a week to at least seven states. Operators were locked out of their own plants, utilities dropped to manual operation, and boil-water notices went out across the Midwest.
In this Breach Files episode, Cole Drayden walks through what actually happened while it is still unfolding: internet-exposed Rockwell Allen-Bradley PLCs, attackers changing passwords and, in at least one case, rewriting the ladder logic itself so that a password reset leaves the compromise running underneath. Plus the attribution question, the CyberAv3ngers / Iran-IRGC pattern going back to Aliquippa in 2023, why investigators are keeping a false-flag possibility open, and four concrete things every OT defender should do tonight.
No contamination was reported and the water is safe. Cole makes the case for why that is good news we did not earn.
Facts as reported by CISA, the FBI, the EPA, and major outlets as of early August 2026. Known facts, suspicions, and open questions are kept distinct throughout.
Dark Perimeter: Security, AI, and the Edge of What is Coming.
On the night of july twenty sixth, twenty twenty six, a water tower in Bram, Minnesota stopped filling. Not because a pump failed, not because a pipe burst, because somewhere someone had reached across the internet, into the controller that ran that plant, and locked the operators out of their own equipment. Bram is a town of about fifteen hundred people. It is not a strategic target in any conventional sense. And yet by the next morning, more than thirty community water systems across Minnesota had been hit in what state officials would call a coordinated cyber attack. Within a week, the count had spread to at least seven states. I'm Cole Draden, this is Dark Perimeter, and tonight we're going to walk through one of the most serious attacks on American water infrastructure in years while it is still unfolding. Everything I'm about to tell you is drawn from what federal agencies and state officials have said publicly as of early August. Some of it will change. I'll be clear about what we know, what we suspect, and what is still an open question. Let's start with what actually happened, because the mechanism matters more than the headline. The systems that got hit were running programmable logic controllers. If you don't live in the operational technology world, a programmable logic controller, a PLC is a small ruggedized computer that runs physical equipment. It opens and closes valves, it starts and stops pumps. It watches a tank level and fills the tank when it drops. It is the thing standing between a control room and a few thousand gallons of water moving in the right direction. In a water plant, the PLC is not paperwork. It is the plant. The FBI and the EPA named the specific hardware in their advisory Rockwell Automation, Allen Bradley Controllers, the Micrologics eleven hundred and fourteen hundred series. These are common workhorse devices. They are all over the water sector, and the attackers were targeting the ones that were reachable from the open internet. That phrase reachable from the open internet is the whole story. Let me say it plainly. A controller that runs a municipal water plant should never be directly exposed to the public internet, not behind a weak password, not behind a good password, it should not be there at all. And yet, according to SISA, a significant number of them were. The acting director of CISA said the quiet part out loud in the agency's own guidance. Remove publicly exposed PLCs and other operational technology from the internet as soon as possible. When your national cyber defense agency has to tell water utilities in the middle of an active campaign to take their pumps off the public internet, that tells you where the baseline was. Here is what the attackers did once they reached those controllers. In the simpler cases, they changed passwords. They locked the operators out of the interface that runs the plant. That alone is enough to force a utility into manual operation, which is exactly what happened in Plymouth and South St. Paul. Manual operation means a human being physically standing at the equipment, running the plant by hand, around the clock, because the automation can no longer be trusted. It is exhausting, it is error prone, and it does not scale. A small utility does not have a deep bench of people who can do that for days, but in at least one victim, the attackers went further, and this is the part that should get every operational technology defender's attention. They didn't just change a password, they modified the controller's project file. They altered the ladder logic. Ladder logic is the program that tells the PLC what to do, fill the tank to this level, hold this pressure, trip this alarm at this threshold. When you change a password, you're locking the front door. When you change the ladder logic, you're rewriting what the machine does when nobody is looking. And here's the vicious part. A password reset does not fix it. You can lock the attacker out, restore your own access, feel like you've recovered, and the altered program is still running underneath because the logic itself was changed, not just the credentials on top of it. That is a persistence mechanism hiding inside the physical process. There is a law enforcement memo out of Minnesota reported publicly indicating the goal in at least some of this activity was to contaminate drinking water by dropping pipe pressure. I want to be careful here. That is an assessment of intent described in reporting, not a confirmed outcome. And the outcome, the thing that actually matters to the people drinking the water, is this. No contamination has been reported, multiple utilities issued boil water notices as a precaution. Officials across every affected state have said there is no indication the water is unsafe to drink. The system, meaning the people and the manual fallbacks and the emergency responses, held. But it held by hand. Now the question everyone asks first, which I've deliberately saved for last. Who did this? The honest answer, as of early August, is that investigators believe it was probably Iran linked and they are not certain, and they are actively entertaining the possibility that they are being fooled. Let me give you the case for Iran because it's substantial. The techniques match a threat ecosystem researchers call cyber Av Thringers. That is a hacking operation tied to Iran's Islamic Revolutionary Guard Corps. If that name sounds familiar to you, it should. This is not their first American water plant. Back in late twenty twenty three, Cyber Av Thangers hit the municipal water authority of Aliquippa, outside Pittsburgh, by compromising Internet exposed controllers, in that case Unitronics devices made by an Israeli company. They left a defacement message on the screen. You have been hacked down with Israel, same playbook, Internet exposed operational technology, default or weak credentials, disruption over destruction, and a political message underneath. The timing this time is also suggestive. The current campaign kicked off just days after CISA updated a major advisory on Iranian targeting of industrial control systems. And there's geopolitical context. The United States and Iran were in open armed conflict earlier this year, in February, followed by a ceasefire in the spring, and Iranian cyber operations against American infrastructure have continued and escalated since. An Iran attributed group had, days before the Minnesota attacks, explicitly warned that U.S. water, electricity, and transportation would be targeted. So the pattern fits, the timing fits, the motive fits. And yet, investigators are also probing whether an attacker deliberately borrowed Iranian tradecraft to point the finger at Iran. This is called a false flag, and it is a real technique in sophisticated intrusions. When the tells are this legible, when the playbook is this well documented, it becomes easier for someone else to wear it as a costume. I'm not telling you it was a false flag, I'm telling you the people whose job it is to know are keeping that box open, and that is the correct posture. Attribution in this domain takes weeks or months, not hours, and anyone selling you certainty in the first week is selling you something. So let's pull back. Because this is dark perimeter, and the point was never the who done it. The point is what this tells us about the ground we're all standing on. There are roughly one hundred and fifty three thousand public drinking water systems in the United States. The overwhelming majority are small, they serve towns like Brahham, they do not have a security team, they frequently do not have one full time IT person. They have an operator who also fixes the pumps and reads the meters and now, apparently, is expected to defend an internet facing control system against a nation state. That is the actual threat model, and it is wildly asymmetric. We have known this for a long time. The warnings go back a decade. Aliquippa was almost three years ago. The EPA tried to make cybersecurity part of mandatory water system inspections back in twenty twenty three, and that effort was challenged by states and withdrawn. Surveys have repeatedly found that the majority of inspected utilities fail to meet basic cybersecurity standards, some estimates putting it around seventy percent. This attack did not exploit some exotic zero day. It exploited controllers sitting on the public internet with weak authentication. The vulnerability was not clever, the vulnerability was structural, and we chose not to fix it. If you defend one of these environments or any environment with operational technology in it, here is what this incident actually asks of you. First, get your controllers off the public internet, not hardened on the internet, off it, if an engineer needs remote access that goes through a VPN with multifactor authentication into a segmented network, not straight to a PLC on a routable address. Go find out tonight, what of your operational technology is internet reachable? Most operators are wrong about that answer and they're wrong in the dangerous direction. Second, change default and weak credentials on every control device and stop treating the PLC layer as if physical obscurity protects it. It doesn't, it hasn't for years. Third, and this is the subtle one this incident really drives home, have a known good copy of your controller logic offline and a way to verify what's running against it, because if the attacker altered the ladder logic, a password reset makes you feel recovered while you are still compromised. Detection and recovery in operational technology has to reach down to the program running on the device, not just the login on top of it. And fourth, practice manual operations before you need them. The utilities that came through this best were the ones that could drop to running the plant by hand without panicking. Your business continuity plan for operational technology is not a document. It's whether your people have actually done it. No one was hurt. The water is safe. That is the good news and it's real. But I want to be honest with you about why it's good news. It is not because our defenses were strong, it's because the attackers, whoever they are, chose disruption over destruction, and because human operators stepped in and ran the plants by hand when the automation turned hostile. We got the outcome we wanted through a margin we did not earn. The next group might not be interested in sending a message. They might be interested in the thing the Minnesota memo warned about, and the controllers are still out there, still on the internet, in towns whose names you'll only learn if something goes wrong. That's the perimeter. It's dark and it runs right through the water main under your street. I'm Cole Draden. Watch your edges.