A community of 1,700 people in Braham, Minnesota got its water plant knocked offline by what officials are calling a coordinated cyberattack, and the thing that saved the day wasn’t a SIEM alert or a next-gen firewall. It was a public works crew flipping a physical switch to manual and running the plant by hand until it was safe to reconnect. Two hours, done. Meanwhile, a few states over, security researchers are warning that cloud environments are riddled with dormant, forgotten identities that nobody’s watched in months, quietly holding onto permissions that would make an attacker’s week. Same theme, wildly different scale: the stuff that actually protects you is rarely the stuff on the dashboard, and cybersecurity teams keep discovering that the hard way.

Cybersecurity’s Best Defense This Week Was a Physical Switch
Here’s what happened, briefly. Between July 26 and 27, a coordinated attack hit water and wastewater systems across more than 30 Minnesota communities. Braham’s well and treatment plant got shut down by disabled operating controls. Plymouth, a city of about 80,000, had to disconnect cellular-connected equipment at two water towers and several wastewater lift stations to stop the bleeding. South St. Paul lost some automated controls. Maple Plain declared a local emergency. Nobody’s officially pointed a finger yet, but the timing lines up awfully well with the CISA advisory update from July 22 warning about Iranian-affiliated actors hammering internet-exposed PLCs, expanded that week to include Schneider Electric and Siemens gear on top of the Rockwell Automation controllers they’d already been hitting.
The vulnerability doing a lot of the work here, CVE-2021-22681, is a five-year-old authentication bypass in Rockwell Logix controllers. It’s rated 9.8. There is no patch. Rockwell has said outright that this one can’t be fixed with a software update, full stop. The only path forward is architecture: get these things off the internet, isolate the engineering workstations, turn on CIP Security, and set the physical mode switch to Run so nobody can push new logic to the controller remotely even if they get in. That last one sounds almost embarrassingly analog for a 2026 headline, and that’s exactly the point. It worked in Braham because water treatment, unlike your CRM, still has a manual mode. Most of what we call “critical infrastructure security” this year comes down to whether that manual mode still exists and whether anyone remembers how to use it.
Meanwhile, Nobody Even Knows What’s Still Logged In
Now flip to the cloud side of the world, where the opposite problem is quietly compounding. Researcher Aleksandr Krasnov has been publishing work on what he calls ghost credentials: dormant nonhuman identities, service accounts, API keys, machine-to-machine tokens, that were spun up for some project eighteen months ago and never torn down. Nobody’s using them. Nobody’s watching them. And in a lot of environments, nobody can even produce a clean inventory of them on request. He’s released an open source tool specifically to trace the trust paths these things create, because the scary part isn’t the dormant account itself, it’s what it can still reach.
This is the identity version of an internet-exposed PLC on a cellular modem. Both are things that got connected for a reason that made sense at the time, then fell out of anyone’s active attention while retaining full privileges. A forgotten service account with stale permissions to a production database is not meaningfully different from a forgotten water tower controller reachable from anywhere in the world. Neither one shows up in the weekly standup. Both are exactly what an attacker goes looking for, because they know your team is watching the things you remember, not the things you forgot.

Same Blind Spot, Different Zip Code
Small water utilities keep getting hit for a structural reason, not a technical one: they’re running lean, often with consumer-grade remote access tools bolted onto industrial equipment because that’s what was affordable and available. Cloud teams have the opposite problem, too much tooling, too many automated pipelines spinning up identities faster than anyone can track them, and no equivalent of a physical mode switch to fall back on when things go sideways. You can’t manually operate your way through a compromised IAM role the way Braham’s crew manually operated the well pump.
That asymmetry matters. It means threat detection built entirely around “alert on something unusual” will miss both failure modes, because a dormant credential logging in for the first time in a year and a PLC responding to unexpected traffic from a foreign IP both look like edge cases until they’re the whole incident. Detection tuned only for volume and speed misses the slow, quiet stuff. And defense in depth isn’t a slogan here, it’s the actual difference between a two-hour outage and a multi-week forensic nightmare with a boil-water advisory attached.
What To Actually Do About It, Starting Monday
None of this requires a product purchase. It requires an inventory, some uncomfortable questions, and follow-through.
- Pull a real list of every internet-facing OT device and every nonhuman identity in your cloud environment. If you can’t produce both lists today, that’s the finding, not the tooling gap.
- For anything industrial that doesn’t need to be internet-reachable, take it off the internet. Put a VPN or secure gateway with multifactor authentication in front of what’s left.
- Set physical mode switches to Run wherever that option exists. It’s free, it’s boring, and it stops remote logic changes cold.
- Deprovision dormant service accounts and API keys on a schedule, not “when someone notices.” Treat unused nonhuman identities as an expiring resource, not a permanent fixture.
- Segment IT from OT and segment automation pipelines from production credentials. A compromised email account should never be one hop from a lift station or a database.
- Feed current indicators of compromise into your firewall and IDS, and actually check whether anything’s matching, brute-force login attempts against management interfaces are a leading indicator, not background noise.
- Keep offline backups of PLC logic and configuration, and rehearse restoring from them the same way you’d rehearse incident response for a ransomware hit.
Security hardening isn’t glamorous, and it doesn’t produce a headline. But the utilities that recovered in hours instead of weeks did it because someone, at some point, had already asked “what happens if this thing goes dark” and built an answer that didn’t depend on the network working.
Sources
- Coordinated “cyberattack” on Minnesota water utilities: What you need to know
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
