```html ``` We Said Five Minnesota Water Systems. It Was More Than Thirty. The 21 Indicators Are Still Free.
top of page

We Said Five Minnesota Water Systems. It Was More Than Thirty. The 21 Indicators Are Still Free.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 7 minutes ago
  • 3 min read

On the morning of 27 July we published that five Minnesota towns had their water controls attacked, and we put 21 IP addresses in the post for anyone to grep for, free, no registration.


The number has since grown. Reporting today puts it at more than thirty Minnesota community water systems targeted across 26 and 27 July.


We were early and we were right about the event. We were wrong about the size, by a factor of six. Both of those are worth saying plainly, and the second one is the more useful of the two.


What we actually had, and when



Our post went live at 02:57 UTC on 28 July — the morning of the incident, in the same news cycle. It named the attack against five systems, tied it to the CISA advisory AA26-097A safety-envelope guidance we had been writing about that week, and published 21 indicators including the 175.110.121.x cluster.


That is the part we will stand on: same-day, with indicators, for free, from Minnesota, about Minnesota.


We are not going to dress up the scale miss. We reported what was confirmed at the time and did not extrapolate, which is the correct instinct — but it produced a number that read as bounded when the event was not.


Why five became thirty, and why that shape matters



Small municipal water systems do not each have a security team. They share things. They share integrators, they share remote-access vendors, they share PLC configurations copied from one deployment to the next because the next town's plant is the same plant with a different nameplate.


When an incident of this class expands from five to thirty over a couple of days, it is rarely thirty separate intrusions. It is usually one access method meeting a population that was configured identically. The interesting question stops being "who got hit" and becomes "what do these thirty have in common that the other towns do not."


For Minnesota specifically, that likely means a shared integrator or a shared remote-access product across small systems in the same procurement orbit. We are not going to name a vendor on inference — but if you run one of these plants, the question to ask your integrator this week is which of your peer systems share your remote-access path, because that is the list that matters more than any indicator we can give you.


The indicators, again, still free



Here are the same 21 addresses from the original post. If you skipped it because five towns sounded like somebody else's problem, it is now thirty, and the cost of grepping is a few minutes.



The 175.110.121.0/24 cluster is the part to pay attention to — consecutive addresses in one range is a rotation pool, not three unrelated hosts, and the useful move is to check the whole /24 rather than the specific addresses we happened to observe.


The full set of 21 is in the original post and in our free feed. There is no registration wall on either. A small water utility does not have a threat-intelligence budget and should not need one to check whether these addresses touched their network.


What to check tonight, unchanged



Pull your remote-access logs for the last two weeks, not the last two days — the reporting window keeps moving backwards on this event and yours may already contain something.


Inventory what is internet-reachable on the control side. In our own honeypot data, the traffic that actually finds exposed systems is relentless, automated and permanent; it does not need a targeted campaign to find you, and it never stops looking.


Ask your integrator the peer question above.


And if you find something, tell the state. Minnesota's small systems are in this together whether or not anyone has said so out loud — the shared-configuration problem that turned five into thirty also means the town that reports first protects the twenty-nine that have not looked yet.


Why we are correcting ourselves in public



Because the alternative is letting the original number stand, and the original number is now wrong in a direction that makes people feel safer than they are.


We publish a 95% confidence cap on everything, which is a way of saying we guarantee some of what we tell you is wrong. That is only worth anything if we come back and say which part. This part: the scale. Five was what was confirmed. Thirty is what it was.


Confidence capped at 95%. Indicators and the AA26-097A linkage are from our original 27 July post and unchanged; the revised scale is from public reporting today and may still move.





Her name was Renee Nicole Good.


His name was Alex Jeffery Pretti.

 
 
 
bottom of page