Recently, a coordinated intrusion locked operators out of water and wastewater controls across more than 30 Minnesota communities.1 Within days, the count crossed multiple states, prompting the FBI and EPA to issue an alert regarding malicious cyber actors targeting internet-facing programmable logic controllers.2 The instinct after an attack like this is to patch faster. Today, there's a better answer.
What happened wasn't sophisticated. That's the point.
The attackers didn't burn a zero-day. They reached internet-exposed controllers, authenticated against weak or default credentials — in several cases exploiting CVE-2021-22681, an authentication-bypass flaw with no vendor patch — then changed device IP addresses and passwords to lock legitimate operators out of their own booster and pump stations. Investigators found modified ladder logic on at least one system. CISA had already catalogued the pattern in advisory AA26-097A, published four days before the campaign began, and it is the same technique that disabled a booster station in Aliquippa, Pennsylvania in late 2023.3
As Tatyana Bolton, Executive Director of the Operational Technology Cybersecurity Coalition, put it, this is “a reckoning of the consequences of ignoring the importance of investing in our nation's cybersecurity for our critical infrastructure.”4
Nothing in that sequence required advanced tooling. It required a controller reachable from the open internet, a credential nobody had changed, and a flat network with nothing between the attacker and the process. That is not a patching failure. It is a hygiene and controls failure — which is also why it is fixable without waiting on a single vendor update.
You can't patch your way out of this — and you don't need to.
A water system can't be rebooted for a patch on demand. Safety recertification, process-continuity requirements, and vendor dependencies mean planned outages happen once or twice a year. Many of the controllers running production today — legacy PLCs, RTUs, aging HMIs — will likely never receive another vendor patch at all. Telling a two-person utility team to “patch faster” ignores the physics of their plant. The right question isn't "when can we patch?" It's "how do we shield the system while patching waits for its scheduled downtime?" Three network controls do exactly that — and none of them require touching or rebooting the vulnerable device.
First: See what's actually exposed.
You can't segment or protect what you can't see. These utilities were breached through PLCs and cellular field gear that operators didn't know were internet-reachable — the towers and lift stations in Plymouth, Minnesota were connected over consumer cellular with no firewall in front of them. Continuous, passive asset visibility fixes the blind spot: it identifies every controller, its firmware and function, and — critically — every path that reaches it, including the remote and cellular-connected sites that never appear on a network diagram. What it means for you: an internet-exposed PLC stops being the thing you discover during an incident and becomes something you find and close on a normal Tuesday.
Then: Contain the blast radius with micro-segmentation.
One technique hit more than 30 communities because the same flat, exposed design repeated in each of them. Segmentation is what stops a single exposed controller from becoming plant-wide loss of control. Micro-segmentation enforced at the firewall isolates PLCs from engineering workstations, separates IT from OT, and puts remote and cellular field sites behind an inspected, authenticated path instead of an open one. Visibility shows the exposure; segmentation removes the path to it. And because the next-generation firewall is both the sensor that sees the asset and the enforcement point that governs traffic to it, closing that path is a policy change on the same platform — not a detection handed to someone to translate into a firewall rule while an attack is underway. What it means for you: the exposed controller in one town can't be reached from the internet, and even inside the plant an attacker who lands on a workstation can't pivot to the chlorine-dosing controller.
Finally: Protect what you can't patch — with risk-prioritized virtual patching.
Some exposures can't be closed by a patch at all. CVE-2021-22681 had none, and the PLC units and legacy RTUs across these systems will likely never get another vendor update. That's where prioritization and virtual patching work together. Prioritize first — by operational consequence, not CVSS score. A vulnerability on a production-critical or safety-classified controller carries far more operational risk than a higher-scoring CVE on a non-essential workstation. Palo Alto Networks Industrial OT Security scores vulnerabilities by real-world operational risk — factoring in device function, safety classification, blast radius, and existing network controls so protected assets aren't misranked.
For the exposures that matter, AI-driven virtual patching shifts protection to the network layer. OT Security correlates those vulnerabilities with available threat-prevention signatures and automatically generates enforceable inline protections that intercept exploit attempts before they reach the controller — no maintenance window, no vendor involvement, no change to the running system. Because the firewall is already the IT-OT and OT segmentation enforcement point, that protection applies immediately to both north-south and east-west traffic. And when a new protection is ready, cloud delivery puts it in force fast. In an OT context, that speed is an uptime and public-safety argument, not a spec — the compensating control is live before the next shift, not the next scheduled outage.
For a water operator, that is the difference that matters. The chlorine-dosing controller you can't take offline, the booster-station PLC a vendor stopped supporting years ago, the remote pump site reachable over cellular — each can be shielded inline while traditional remediation runs on its own timeline.
What it means for you.
The Minnesota campaign wasn't a sophistication problem you out-patch. It was a hygiene and controls problem you architect against — and the three controls that would have contained it exist today, none of them dependent on a maintenance window. See every asset and every path that reaches it. Segment so one exposed controller can't become plant-wide loss of control. Virtually patch the legacy and unpatchable devices inline. Do that, and patch timing comes off the critical path: your remediation keeps its own schedule, and your defense stops waiting on it.
For the deeper technical case behind this approach, read the Palo Alto Networks blog on operational risk prioritization and virtual patching for OT.
Talk to a Critical Infrastructure Security Specialist.
Schedule a 30-minute strategy call to evaluate your OT and 5G posture against exposed assets, flat networks, and legacy visibility gaps.
What you'll get from the call:
- A tailored visibility review: Map your current asset coverage against enterprise baselines where, according to Palo Alto Networks' 2025 Device Security Threat Report, 32.5% of devices on corporate networks operate completely unmanaged and invisible to security teams.
- Architecture and segmentation guidance: Identify opportunities to eliminate tool sprawl, harden OT segmentation, and protect legacy OT systems without operational downtime.
- 5G & edge security: Learn how inline inspection and identity intelligence protect private cellular expansions.
To schedule a brief call or to receive more information, please contact us.
1 Minnesota IT Services. (2026, July 28). MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure. State of Minnesota. https://mn.gov/mnit/media/blog/?id=38-761869
2 Federal Bureau of Investigation, & Environmental Protection Agency. (2026, July 30). Malicious cyber actors targeting water and wastewater sector internet-facing programmable logic controllers, causing operational disruptions (Alert: I-073026-PSA). Internet Crime Complaint Center (IC3). https://www.ic3.gov/PSA/2026/PSA260730.pdf
3 Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, & National Security Agency. (2023, December 1). IRGC-Affiliated Cyber Actors Exploit Programmable Logic Controllers in Multiple Sectors (Advisory AA23-335A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
4 Operational Technology Cybersecurity Coalition. (2026, July 31). A Wake Up Call for OT Security: OTCC Statement on Critical Infrastructure Cybersecurity and the Need for Congressional Action. https://www.otcybercoalition.org/post/a-wake-up-call-for-ot-security-otcc-statement-on-critical-infrastructure-cybersecurity-and-the-nee