What happened
Between 26 and 27 July 2026, a coordinated cyberattack disrupted water and wastewater operations across more than 30 Minnesota communities — disabling computerised controls, forcing manual operations and triggering a local state of emergency in Maple Plain. Through August the campaign widened: the FBI confirmed water systems in at least seven states were affected, with subsequent reporting putting the figure at 12. In Clayton County, Georgia, customers lost water pressure; in Utah, attackers manipulated readings so pumps ran dry while control panels showed normal operation.
The attackers' method was mundane: internet-exposed industrial controllers (PLCs). Meanwhile CISA reported that Medusa ransomware affiliates have breached more than 500 critical-infrastructure organisations by watching for newly disclosed vulnerabilities and hitting whoever hasn't patched yet.
Why it matters to your business
Two lessons travel directly from water utilities to ordinary businesses. First: anything reachable from the internet will be found and probed — remote access points, management interfaces and forgotten devices are the equivalent of those exposed PLCs. Second: trust your monitoring, but verify it. The Utah incident is chilling because the control panels lied — attackers manipulated what operators saw.
Medusa's method is the other wake-up call: you don't need to be targeted personally. Automated campaigns scan for known vulnerabilities within days of disclosure and breach whoever is unpatched. Your patching cadence is your real exposure window.
What you should do
Get remote access off the open internet or behind MFA and strict access rules.
Patch on a schedule measured in days — vulnerability-to-exploit time is now that short.
Monitor independently. Device health monitoring that alerts when systems behave oddly is how you catch manipulated readings.
Back up operations-critical data immutably, so that even a successful attack can't hold your business hostage.
Source: Xage Cyber Attack News Roundup