Five Minnesota Towns Had Their Water Controls Attacked This Morning. Here Are 21 IP Addresses to Grep For Tonight, Free.
- Patrick Duggan
- 5 minutes ago
- 5 min read
At 9:34 this morning, the water plant in Braham, Minnesota went offline. Operating controls for the well and the treatment plant were shut down by what city officials are calling a malicious cyberattack. Public works had it back inside two hours.
South St. Paul was hit. Plymouth was hit. Officials have said at least five Minnesota communities were targeted on the same day.
No physical damage. No contamination. The water is safe to drink in all three cities, and the crews who got those plants back deserve the credit for that.
We are a Minnesota company. Plymouth is about fifteen miles from our office. So this one is going to be short on commentary and long on things you can actually do before you go to bed.
First, what we are NOT saying
Officials have described the actors as unidentified. No agency has attributed this to anyone.
We track Iranian-affiliated PLC targeting closely — it is a standing watch for us and we have published on it repeatedly since April. The temptation to connect today's attack to that campaign is enormous, and we are not going to do it. We have written three separate posts in the last twenty-four hours about the damage done by treating a plausible claim as a confirmed one. It would be pretty rich to abandon that the moment the story landed in our own state.
What follows is a hypothesis worth checking, not an attribution. Check it and rule it out.
The context that makes this worth checking tonight
On April 7, CISA, the FBI, the NSA, the EPA, DOE, and US Cyber Command published joint advisory AA26-097A: Iranian-affiliated actors exploiting internet-exposed programmable logic controllers across US critical infrastructure since at least March 2026. Water and wastewater named explicitly.
They updated it on July 22 — five days ago — to add detection guidance for malicious changes in reusable code modules, and to expand the manufacturer scope beyond the original targets to include Schneider Electric, Siemens, and potentially other PLC brands.
The tradecraft in that advisory is not exotic. It is internet-exposed controllers, default and reused credentials, and lateral movement into the plant network. In our April analysis of roughly 4,000 exposed US industrial devices, the finding was blunt: they are not burning zero-days, they are reading the manual.
A small municipal water system is exactly the profile: a handful of PLCs, a remote-access requirement so one operator can cover several sites, a budget with no line item for OT security, and no SOC.
The 21 addresses
We ingested the AA26-097A indicator set into our free feed. All 21 are live in the public blocklist as of tonight — we checked before publishing this rather than assuming.
135.136.1.133 — 141.11.164.153 — 175.110.121.39 — 175.110.121.41 — 175.110.121.42 — 175.110.121.107 — 185.82.73.162 — 185.82.73.164 — 185.82.73.165 — 185.82.73.167 — 185.82.73.168 — 185.82.73.170 — 185.82.73.171 — 185.82.73.175 — 185.225.17.225 — 192.142.54.79 — 79.133.46.209 — 84.200.205.165 — 88.80.150.199 — 88.80.150.200 — 88.80.150.202
Note the clusters — eight consecutive addresses in 185.82.73, four in 175.110.121, three in 88.80.150. If you find one, look at its neighbours.
What to do with them, in order:
Grep your firewall and VPN logs for all 21, going back to March. Not just today. The advisory describes activity since at least March 2026, and the pattern in this class of intrusion is reconnaissance and access long before anything visible happens. A hit in April matters as much as a hit this morning.
Then check the /24s around them. Operators rotate within a block far more often than they abandon it. Our own hunting today found a case where the address published in every public feed was already dead while nine numbered siblings stayed live. Do not treat an exact-match miss as an all-clear.
Pull the full list from analytics.dugganusa.com — IP, domain, hash, and malicious-package blocklists, no cost, no sales call. If you run a small utility and you want the CSV rather than an API, it is a single request and it is free. That is what it is for.
What to check that has nothing to do with us
Honestly, these matter more than our indicator list:
Is any PLC or HMI reachable from the internet? Search your own public IP ranges on Shodan — it is free and takes five minutes. If a controller answers from outside your network, that is the finding. Nothing else on this list matters as much.
Are you still on factory-default or shared credentials? The 2023 Unitronics attacks on US water systems succeeded largely on default passwords. Not a clever exploit. The default.
Is remote access on a VPN with MFA, or is it a port forward? Small utilities frequently expose remote access directly so a contractor or an on-call operator can reach the plant at 2am. That convenience is the attack surface.
Can you run the plant with the HMI dark? This is the question that separates an outage from an emergency. Braham's crew restored operations in under two hours because people knew what to do without the computer. Manual override procedures, printed, practiced, and current — that is your actual resilience, and it costs nothing but an afternoon.
Do your PLC code modules match your last known-good backup? This is the specific thing the July 22 advisory update added. Reusable code blocks are where a modification hides, because nobody re-reads a library they wrote in 2019. If you have a backup, diff it. If you do not have a backup, tonight is the night.
Who to call in Minnesota
The Minnesota Rural Water Association maintains cyber resources for exactly this population and knows the operators personally. The League of Minnesota Cities published guidance on water system cyber risk this month. CISA Region 5 provides free vulnerability scanning to water utilities — free, as in no invoice — and most small systems have never asked.
If your plant was one of the five and you are reading this at midnight trying to work out what to do next: call CISA, preserve your logs before anything is rebuilt, and do not wipe the affected machines until someone has imaged them. The evidence in those systems is how the other utilities in the state find out whether they are next.
Why we are giving this away
Braham has around 1,800 residents. That water system does not have a security team, a threat intel subscription, or anyone whose job title contains the word "cyber." Neither do most of the roughly 970 community water systems in this state.
That population is the entire reason our feed is free. Not a trial, not a lead magnet — free, because a town of 1,800 is never going to be a customer, and the water still needs to be safe. Today it was our state. It will be somebody else's next week.
The honest part
We do not know who did this. We do not know if it is connected to AA26-097A. We know the timing is striking — a joint-agency advisory about PLC attacks on water systems gets updated on July 22, and five Minnesota water systems get hit on July 27 — and we know that striking timing is exactly the kind of thing that makes people confidently wrong.
We are 95 percent confident more US municipal water systems are hit before the end of the year, because the exposed-controller population has not meaningfully shrunk since April and the technique requires no sophistication. The five percent is the chance that today lands hard enough in state capitals to fund the fix. Minnesota just got a very cheap lesson — nobody was hurt, and the water was never unsafe. The expensive version of this lesson exists and other states have paid it.
Check your logs tonight.
Free IP, domain, hash, and malicious-package blocklists at analytics.dugganusa.com. Minnesota utilities: if you need help reading your logs against this list, contact us and we will do it with you at no charge.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.
