TL;DR: A coordinated cyberattack targeted more than 30 Minnesota community water systems and incidents across at least seven U.S. states, with attackers abusing internet-exposed HMI and PLC devices to alter IP addresses, change passwords, and disrupt monitoring and control, according to ColorTokens. The case reinforces that OT defenders must treat perimeter failure as expected and design for containment, not just prevention.
NHIMG editorial — based on content published by ColorTokens: Public Water Systems Are Targeted by State Actors, focusing on how to protect PLCs and HMIs in the operational technology network
By the numbers:
- More than 30 community water systems in Minnesota were targeted in a coordinated cyberattack, with additional incidents reported across at least seven U.S. states.
Questions worth separating out
Q: What breaks when OT devices are exposed to the internet?
A: Internet exposure turns HMIs and PLCs into reachable control points rather than protected field assets.
Q: Why does microsegmentation matter in industrial control environments?
A: Microsegmentation matters because it limits how far an attacker can move after the first foothold.
Q: How can organisations tell whether OT access controls are actually working?
A: Look for evidence that access is issued only on demand, expires automatically, and can be tied to a named user, task, and session record.
Practitioner guidance
- Remove direct internet exposure from OT control devices Inventory HMIs, PLCs, engineering workstations, and remote maintenance paths, then place them behind controlled jump hosts, VPNs, or equivalent access brokers with strict allowlists.
- Segment OT zones to block lateral movement Define traffic policies between HMIs, PLCs, historians, SCADA servers, and administrative systems so a compromise in one zone cannot propagate.
- Harden privileged access to device credentials Review every account that can change passwords, IP settings, or control logic on OT assets.
What's in the full article
ColorTokens' full article covers the operational detail this post intentionally leaves for the source:
- How the vendor maps IT and OT traffic to support microsegmentation decisions in mixed environments
- The enforcement options described for agent-based and agentless OT assets, including PLCs and actuators
- The article's device-level examples for HMI, SCADA, historian, and engineering workstation segmentation
- The vendor's explanation of how its controls are positioned for water utilities and other critical infrastructure operators
👉 Read ColorTokens' analysis of public water system attacks and OT containment →
OT network exposure in water systems: what do practitioners need to fix?
Explore further
Exposed OT devices create a control-plane problem, not just a perimeter problem. When HMIs and PLCs are reachable from the internet, the real failure is governance over device exposure and remote management paths. Preventive filtering helps, but the core question is whether process-control assets are ever allowed to sit inside a reachable trust boundary. Practitioner conclusion: treat reachability as an access decision tied to operational risk.
A question worth separating out:
Q: Who is accountable when a water utility loses control of OT systems?
A: Accountability usually spans operations, security, and utility leadership because the impact is physical as well as cyber. The useful question is whether the organisation can prove who approved remote access, who owns privileged device credentials, and who is responsible for containment when normal control paths fail.
👉 Read our full editorial: Public water systems face OT attacks through exposed HMI and PLC devices