I Warned Them About the Buildings. Now It’s the Water.

This week, CISA told water utilities nationwide to pull exposed industrial-control equipment off the internet. Not as a hypothetical. As a response to an actual attack. More than 30 community water systems in Minnesota were hit this week. Some utilities had to run their equipment by hand. One town, Braham, briefly lost control of its well and water treatment plant. Officials suspect Iran.

I wrote about this exact threat class in April, after CISA issued Advisory AA26-097A warning that Iranian-affiliated actors were exploiting Operational Technology — the programmable logic controllers running HVAC systems, elevators, and building management systems at facilities like VA medical centers. I called it “the buildings nobody thinks about.” Three months later, it’s not a building. It’s a water system. Same vulnerability. Same threat actor. Different target.

That’s the part worth sitting with. This isn’t a new warning arriving. It’s the same warning, proven correct, in a different sector.

The Pattern Doesn’t Care What You Call the Building

A programmable logic controller doesn’t know if it’s running a well pump in Minnesota or an air handler at a VA medical center. It just runs the code it’s given, and it trusts whoever gives it that code. CISA’s alert this week describes hackers going after exactly the kind of internet-exposed PLCs that show up in water systems, in energy grids, and in the OT layer of VA facilities I wrote about in April. The agency’s advice is the same in every sector: get these devices off the open internet, kill the default passwords, and stop assuming nobody’s looking.

One water-sector worker put it to Nextgov/FCW more bluntly than I would in a policy piece: exposing a PLC to the public internet, in 2026, after everything we’ve watched happen, isn’t an oversight anymore. It’s a choice.

Fiction Caught Up Too

The Chariot Protocol opens with exactly this failure mode. Not a firewall breach. A building. Elevators that stop between floors. Pharmacy dispensers that lock up. HVAC systems cycling on their own, with nobody able to say why. I wrote it as fiction because the actual advisories, the actual audits, weren’t landing. This week, a real Minnesota town found out what it feels like to lose control of a well pump to someone else’s hands. That’s not my plot anymore. That’s Thursday.

Zero Trust Ends at the Firewall. The Threat Doesn’t.

Every agency I watch, VA included, is spending real money on Zero Trust architecture right now. Good. Necessary. Not sufficient. Zero trust that stops at the network layer and never reaches the physical layer — the pump, the thermostat, the elevator controller — is a fence around half the yard. Iran’s affiliated actors aren’t choosing between attacking IT and attacking OT. They’re going wherever the door’s unlocked, and right now, in sector after sector, the OT door is still unlocked.

I made this argument about VA’s buildings in April. The water utilities in Minnesota just turned it into evidence.

Leave a Reply

Your email address will not be published. Required fields are marked *