# Cyberattacks Target Minnesota Water Utilities and Exploit Vulnerabilities

*Published August 3, 2026*
*Source: [https://www.sans.org/newsletters/newsbites/xxviii-56](https://www.sans.org/newsletters/newsbites/xxviii-56)*

## Executive Summary

Cyberattacks have impacted over 30 Minnesota water utilities by exploiting vulnerabilities in IPMI and Cisco Secure FMC systems. These incidents highlight the urgent need for robust security measures to protect critical infrastructure from unauthorized access.

## Article

Recent cyberattacks have targeted over 30 community water utilities in Minnesota, revealing significant vulnerabilities in their systems. These attacks exploited a flaw in the Intelligent Platform Management Interface (IPMI) that led to the leakage of Baseboard Management Controller (BMC) password hashes. Additionally, cybercriminals took advantage of a hardcoded credential vulnerability in Cisco Secure Firewall Management Center (FMC), raising alarms about the security of critical infrastructure.

The exposure of PLCs, often due to inadequate firewalls or misconfigurations, has been identified as a major risk factor. A search on Shodan reveals thousands of open PLCs worldwide, many located in the United States. These devices are often accessible through cellular routers that lack proper security measures, making them easy targets for unauthorized access.

Asset owners and operators are urged to take immediate action to secure their systems. Utilizing tools like Shodan or Censys can help identify open PLCs within a network. Collaborating with vendors and service providers is crucial to implement effective security measures and protect these vulnerable devices from potential threats.

The incidents underline the necessity of robust cybersecurity practices for protecting critical infrastructure. By addressing these vulnerabilities, organizations can prevent future cyberattacks and safeguard essential services.
