Twenty-One Addresses Attacked Water Systems in Seven States. Every One of Them Has a Perfect Abuse Score.
- Patrick Duggan
- 26 minutes ago
- 6 min read
The scope moved again today. Malicious activity has now affected water systems in at least seven states. Wisconsin detected activity at its facilities on Monday and told utilities to act immediately. Minnesota remains above thirty community water systems — we published five, corrected ourselves to thirty-plus yesterday, and it has held.
Most confirmed cases involved the equipment used to remotely monitor and control water infrastructure, including programmable logic controllers. Federal authorities have reported loss of monitoring and control functionality, leading to pressure loss and flooding.
Attribution is publicly disputed and publicly unevidenced in every direction, so we are going to spend no words on it. We took the twenty-one indicators we published on Monday and pulled them apart instead. Three things came out that we had not seen written down anywhere.
One: there are no singletons
The advisory lists its addresses numerically, which is the natural way to publish a list and the worst way to read one. Sorted by the network that owns them, the set has a different shape.
One provider holds eleven of the twenty-one. AS214036, UltaHost, across two countries.
And the six addresses that look like isolated one-offs are not. Three of them — 192.142.54.79, 79.133.46.209, 84.200.205.165 — sit on the same ASN as the largest cluster. They only look separate because they live in different /24s and two different countries, so a numeric sort scatters them to the far end of the list.
If that concentration reflects how the operator buys infrastructure rather than how investigators happened to find it, then provider-level watching beats address-level blocking for this actor. We cannot tell which from outside, and we flag it as the open question it is.
Two properties hold across all twenty-one: every address is commercial European hosting — Netherlands 13, Bulgaria 3, Romania 2, Germany 2, Switzerland 1 — and every one is typed Data Center / Web Hosting / Transit. No Iranian IP space appears anywhere in the set. Whoever runs this rents it, in the West, from ordinary providers, the same way you would.
Two: the reputation systems have nothing on any of them
This is the finding we would put in front of a plant operator first.
We enriched all twenty-one against AbuseIPDB and VirusTotal. Every single address returns an abuse confidence score of zero, with zero total reports.
Not low. Not "some historical noise." Twenty-one out of twenty-one, spotless.
So consider what that means for the defence most small utilities actually have. If your firewall, your DNS filter, or your managed service blocks on IP reputation — the overwhelmingly common model, and the one bundled into cheap products — not one of these addresses would have tripped it. They are, to every reputation system we checked, clean commercial hosts in friendly countries.
That is the entire argument for why a published advisory list matters and why we mirror it for free. Reputation scoring is retrospective by construction: it needs somebody to have been hurt and to have filed a report. Infrastructure that is used carefully, against a small number of targets, by an operator who does not spray, never accumulates a score. The list is the only thing that flags it, and a utility with no threat-intel budget will never see the list unless somebody puts it somewhere free.
Three: fifteen of them cluster, and the numbering has holes
Fifteen of the twenty-one live inside three /24 networks. Laid out by final octet, the gaps are visible.
Eight addresses sit between documented state-linked infrastructure and appear on no list anywhere — not ours, not any third-party feed we carry. We track rotation pools deliberately: a feed names the host that got caught, the numbered neighbours stay quiet and stay live. This set has that silhouette exactly.
So we tested it. And we want to report the result honestly, because it is not the one we wanted.
The test came back null. All eight gaps return the same ASN, the same provider, and the same zero abuse score as their listed neighbours — which sounds like corroboration until you check the allocation. RDAP for 185.82.73.0/24 returns handle LSW-CUST-ULTAHOST, type ASSIGNED PA. That is a provider allocation. Every address in that range belongs to UltaHost by construction, whichever customer is actually holding it. Same-ASN was guaranteed before we ran the query. It is not evidence of anything.
The only distinctive artefact we found is a reverse-DNS name on 175.110.121.40 — and it is 175-110-121-40.hosted-by-worldstream.net, the provider's generic pattern for every address in the block.
So: eight open questions, zero findings. We are not publishing them as indicators and you should not block them on our say-so. Manufacturing intelligence out of arithmetic is how feeds fill with garbage and somebody's legitimate host ends up firewalled. What those eight are is a hunt list — if you have passive DNS or certificate-transparency history with better visibility than ours, that is where we would point it. We do not have a paid source for either, which is now the second investigation this quarter that has stopped at that exact wall.
What our own sensors saw: nothing, and how we nearly got that wrong
We checked whether our edge has ever observed any of this infrastructure.
The first query used an address prefix and came back with counts in the tens of thousands. We nearly wrote that up. Two of the numbers were exactly 100,000, which is a ceiling rather than a count, and the rest were fuzzy matches from a search index that always returns a nearest neighbour whether or not one exists.
Re-run with exact values: zero matches. Every index, every address.
Our edge has never seen this. We redistribute a six-agency public advisory to people who would otherwise never consume it, which has real value for a three-person utility and is the reason the feed exists. It is not detection, we did not see this coming, and no part of this incident appeared in our own sensors. Anyone claiming otherwise about their own feed should be asked to show the exact-match query, because we just demonstrated how easy it is to believe the wrong number.
What to do
Block the twenty-one. They are in our free feed at confidence 90, family IOCONTROL, no registration required. None of them has any legitimate reason to speak to a water treatment plant, whoever turns out to own them.
Do not rely on reputation scoring for this. All twenty-one are invisible to it. That is measured, not asserted.
Find out whether any PLC or HMI in your plant is reachable from the internet. Not whether it is supposed to be — check from outside, today.
Establish whether you can run the plant on manual. Try it on a scheduled morning with the person who would have to do it, and write down what breaks. The four-agency guidance published this week says isolation must be built and tested before an incident rather than improvised during one. Pressure loss and flooding is what improvising looks like.
The honest position
We do not know who did this and have never claimed to. Our language has been the same since Monday: a hypothesis worth checking, not an attribution.
What we did today was take a list everyone already has and ask it three questions. Two produced findings we have not seen published elsewhere — the provider concentration, and the fact that every address in a state-linked OT campaign carries a perfect abuse score. The third produced a null result on a hypothesis we would have liked to confirm, and we are printing that with the same weight as the other two, because a rotation-pool story we cannot support is worth less than the trust we would spend telling it.
Confidence capped at 95%. Scope figures and the reported pressure loss and flooding are from federal statements and reporting by multiple outlets; the Minnesota count may still move. Enrichment is third-party (AbuseIPDB, VirusTotal) and a point-in-time read from 31 July — reputation scores can change, and if these addresses start accumulating reports that is itself worth knowing. The twenty-one indicators and their provenance are unchanged from 27 July. The eight adjacent addresses are unlisted, unobserved, and unproven.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
