Editor’s Note: Minnesota counted over 30 community water systems targeted inside 48 hours in late July, CISA warned the whole water sector days later about threat actors going after internet-exposed controllers, and the FBI and EPA separately said utilities in at least seven unnamed states had reported incidents to the FBI. Publicly disclosed impacts stayed limited; the governance question they surfaced did not. Federal guidance tells utilities how to inspect and restore a locked controller safely, and for the MicroLogix devices the alerts name, Rockwell’s own manuals document no password bypass: the recovery path is clearing controller memory, which removes the running program. None of the documents reviewed for this piece says who should capture a controller’s running project or configuration first, when doing so is safe and feasible.

For cybersecurity, data privacy, compliance and eDiscovery professionals, that lands in familiar territory: preservation duties, third-party records and litigation holds, applied to devices many data maps have never seen.

Watch what comes next: attribution remains open, preservation questions may follow as the incident record develops, and New York’s newly adopted rules put drinking-water requirements on a compliance clock ending Jan. 1, 2027.


Content Assessment: Restore the controller, risk losing evidence: federal water guidance leaves the sequence open

Information - 93%
Insight - 92%
Relevance - 92%
Objectivity - 92%
Authority - 90%

92%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Restore the controller, risk losing evidence: federal water guidance leaves the sequence open."


Industry News – Cybersecurity Beat

Restore the controller, risk losing evidence: federal water guidance leaves the sequence open

ComplexDiscovery Staff

Braham, Minnesota, had its water plant back online about 90 minutes after crews isolated the affected system and restored from backup. The public record does not say what, if anything, was documented or retained first.

The Cybersecurity and Infrastructure Security Agency (CISA) warned the water sector July 30 that threat actors are targeting internet-exposed programmable logic controllers (PLCs), days after a coordinated attack targeted over 30 Minnesota community water systems. The alert named no states.

In the activity CISA described, threat actors changed PLC passwords to lock operators out of the small industrial computers that run wells, pumps and treatment processes, and altered controller IP addresses to cut the devices off from the networks that monitor them. The agency wrote that the activity has resulted in boil-water notices and sustained manual operations at affected utilities, and Minnesota officials have not identified the products or access methods involved there.

In Minnesota, four cities publicly disclosed impacts: Braham, where the plant went offline before crews isolated the system and restored from backup; South St. Paul, where automated controls shifted to manual operation; Plymouth, which lost cellular communications to two water towers and several wastewater lift stations and ran them manually; and Maple Plain, which maintained operations after automated controls were affected and declared a local state of emergency.

As of Aug. 1, no Minnesota community had issued a boil-water notice tied to the attacks, and none had reported unsafe drinking water. Braham had briefly asked residents to minimize water use while its plant was down. Mike Ernster, a spokesman for the Minnesota Department of Public Safety, said no part of the state’s water supply had been reported compromised. Minnesota IT Services (MNIT), which coordinated the response with CISA, the FBI and the Environmental Protection Agency, said July 28 it was not aware of any active request for residents to change how they use their water.

The reassurance came with a caveat that matters for what follows: officials have not said how many of the 30-plus targeted systems experienced unauthorized access or operational impact, and MNIT has not identified the access method or the products involved.



Beyond Minnesota, a federal warning with no named states

Separately, the FBI and the EPA said in a joint July 30 alert that water and wastewater utilities in at least seven states had reported incidents to the FBI since July 27, with malicious actors remotely accessing internet-exposed Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers, changing IP addresses and passwords, and causing a loss of monitoring and control functionality; some of that activity degraded water operations. The agencies did not identify the states and have not publicly connected those incidents to the Minnesota attacks. At least one organization found modified PLC project files after spotting ladder logic discrepancies across several sites, the agencies said. Reported consequences included pressure loss and flooding, and the agencies cautioned that pressure loss could allow untreated groundwater to seep into distribution pipes. Press reports named Minnesota and Michigan among the states where utilities reported incidents, and Dale George, communications director for Michigan’s Department of Environment, Great Lakes and Energy, said every Michigan system known to be involved in the reported incidents kept operating safely, UPI reported.

John Israel, Minnesota’s chief information security officer and an assistant commissioner at MNIT, said attacks on critical infrastructure demand a coordinated, whole-of-government response, and credited that coordination with containing the incident before it produced worse outcomes.

The broader exposure is readily visible, even though officials have not publicly identified the Minnesota access path. Ron Fabela, an industrial control systems researcher, located at least two Rockwell MicroLogix 1400 controllers sitting in Plymouth’s public IP space through Shodan queries, CSO Online reported. Censys, an attack-surface research firm, said it observed 4,148 internet-exposed Rockwell EtherNet/IP hosts worldwide as of July 30, with 71 percent of them in the United States. That count spans all sectors worldwide, not water utilities alone; it sizes the whole exposed population rather than the water-sector slice CISA addressed, and Censys said the measurement characterizes exposure only, without confirming that any host is a victim. The agency urged utilities to pull exposed PLCs off the internet as soon as possible, route any remote access through virtual private networks or gateway devices, change default passwords and restrict access to allowlisted addresses. Rockwell Automation issued its own notice the same day covering the MicroLogix 1400.

Attribution is a question, not an answer

US authorities have not publicly attributed either the Minnesota incidents or the separate multistate activity. Nick Andersen, CISA’s acting director, urged critical infrastructure owners and operators to get publicly exposed PLCs off the internet as soon as possible. Separately, a July 22 update to advisory AA26-097A described an Iranian-affiliated campaign against US critical infrastructure PLCs and added Schneider Electric Modicon M340 and Siemens S7-1200 controllers to its targeted-device list alongside additional Rockwell models. The advisory, first issued April 7, ties that campaign to CyberAv3ngers, a group US agencies have linked to Iran’s Islamic Revolutionary Guard Corps. No agency has publicly said Minnesota was part of that campaign.

The fit is suggestive rather than settled. Researchers at security vendor Tenable wrote that the timing and operational pattern were consistent with prior CyberAv3ngers activity and its affiliated personas, while stressing that the incident has not been attributed. An Iranian state publication attributed the Minnesota attack to Handala, a pro-Iran hacktivist persona, on July 29, days after the incident; Handala itself had not claimed it and stayed silent about Minnesota on X even as it claimed credit for a concurrent attack on an internet service provider, CSO Online reported. The Washington Post reported that US spy agencies suspected Iran, and CBS News reported that investigators were weighing whether the operation was Iranian work or was staged to look like it. Suspicion relayed in news reports is not an on-the-record government attribution. Iran-affiliated actors did compromise US water utilities in late 2023 by exploiting default passwords on internet-facing Unitronics controllers, including at the Municipal Water Authority of Aliquippa in Pennsylvania, a precedent analysts repeatedly cite.

For utility lawyers, unresolved attribution cuts in every direction at once. It can keep war exclusions from settling insurance questions, can slow subrogation, and leaves open whether an intruder was a foreign service, a proxy or an opportunist who found port 44818 open.

Preservation can lose the race to recovery

A utility that loses access to its controllers faces an evidence-preservation question alongside a service-recovery problem. The federal materials prescribe inspection and recovery steps; they do not assign the preservation decision or set a capture-before-recovery sequence.

The compromised state of a locked-out PLC may hold important evidence. The attacker-set password, the altered IP configuration, the modified project file, the ladder logic that no longer matches what the integrator installed: those artifacts may help establish what happened, when, and potentially who bears responsibility for it. CISA’s alert advises utilities to keep a known-clean backup of the PLC image so they can restore if locked out. The FBI and EPA tell utilities to verify that backups are free of malicious logic before deploying them, to review project files running on PLCs for unauthorized changes against known-good logic, and to review logs and configurations on connected devices. That is real diagnostic guidance, and it is fair to say the documents do not ignore evidence. What none of them tells an operator standing at a panel at 6 a.m. is to preserve the compromised state, export the running project file or photograph the controller configuration before flashing it away.

The sector’s own guide narrows the gap without closing it. The joint CISA, FBI and EPA incident response guide for water and wastewater systems, published in January 2024, urges utilities to establish well-defined processes for preserving incident data and evidence, with clear guidelines for collection, storage and access, and to ask regional CISA or FBI offices for retention guidance; it also catalogs federal forensic support, including host, network and cyber-physical analysis. The guide describes itself as informational: by its own terms it does not mandate action, is not exhaustive, establishes no requirements and recommends no technical configurations. None of the documents reviewed for this article specifies who should capture a PLC’s running project or configuration before restoration, when doing so is safe and technically feasible. Braham’s recovery in about 90 minutes was the operational mandate working as designed. Whether anything was preserved first is a question the public record does not answer, and none of those documents requires anyone at the panel to ask it before restoring.

The lockout scenario the alerts describe makes the gap concrete for the very devices they name. CISA’s alert points owners, operators and integrators of MicroLogix 1400 controllers to a Rockwell Automation notice on restoring access when the password is unknown. Rockwell’s reference manuals for the MicroLogix 1100 and 1400 document no way to bypass a lost password to recover the program; the documented recovery option is clearing controller memory, which removes the running program. A recovery path that removes the running program is sometimes the only documented option, which is exactly why the capture question has to be answered before anyone is standing at a panel.

The operational lesson is not that an operator should delay a safe restoration. It is that a response plan should identify, in advance, what qualified operational technology (OT) personnel can document or collect before recovery changes the device state, and who is authorized to make that call. For an accessible controller, that can mean preserving project files and configurations. For a locked one, an upload may not be technically possible, and the available record may instead sit in the human-machine interface, the engineering workstation, the modem, the firewall, the network monitoring platform, the integrator’s archive or a managed-service environment. Which of those records exist, who controls them and how long they last depend on the system’s design and its contracts.

The legal clock runs on its own schedule. Once federal litigation is reasonably anticipated, Rule 37(e) of the Federal Rules of Civil Procedure can come into play if relevant electronically stored information is lost because a party failed to take reasonable preservation steps and the information cannot be restored or replaced; regulatory proceedings can create separate preservation duties or make litigation foreseeable. Incidents of this breadth are likely to generate insurance claims, regulatory inquiries and, depending on what investigators find, disputes involving utilities, vendors or integrators. A controller reimaged with nothing captured first can become the centerpiece of a lost-ESI fight if those threshold conditions are met, and the defensible answer is contemporaneous documentation: who decided to restore, why, what was captured first, and what could not be. Counsel should assess any preservation obligation on the applicable facts, forum, public-records rules, regulatory requirements, contracts and insurance policies rather than treating one federal civil rule as a universal answer.

Insurance recovery can turn on the same artifacts. Cyber policies typically condition payment on proof of loss, and depending on policy language and governing law, carriers may scrutinize forensic documentation in claims tied to suspected state-linked activity, where attribution evidence can shape war-exclusion fights and subrogation alike. A utility that reimaged its way back to service with nothing preserved may find the gap matters twice: once in any dispute, and once at renewal.

The data source the inventory may have missed

CISA’s alert flagged one detail that should stop information governance professionals mid-read: exposed OT can include cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack-surface scans.

A modem missing from the asset inventory may also be absent from the data map, the litigation hold template and any collection plan, leaving it an unmapped data source. Its connection logs may sit with a cellular carrier or a vendor on a retention clock the utility has never read, and the same goes for integrator remote-access records, vendor-managed connectivity and the project file archives that show what the ladder logic looked like before an intrusion. Plymouth’s disclosed loss of cellular communications is a reminder that the relevant records may sit with the utility, an integrator, a modem vendor, a managed-service provider or a carrier, depending on the system’s architecture and its contracts.

The practical work follows directly. Utilities and their counsel can inventory every cellular connection into OT now, in writing, by asking integrators and vendors to enumerate what they installed. Hold templates can be extended to controller images, project files, human-machine interface exports, modem logs and carrier records, with contract language obligating vendors to retain and produce them. Response plans can add a capture-before-restore step where safety and technical access allow: document accessible controller state, photograph the panel, and preserve associated human-machine interface, workstation, modem and network records. Exporting the running program works only while a controller remains accessible; a password-locked MicroLogix may not permit an upload.

The FBI’s reporting request identifies baseline incident data worth retaining: device models, serial numbers, IP addresses and unusual network addresses seen in logs. The list is an intake request, not a preservation protocol, but it helps define a minimum incident record. And federal technical assistance, including CISA forensic analysis, may be available at no cost on a case-by-case basis, which for a small town may be the closest thing to a forensics budget it has.

Service providers should read the same alert from the other side of the table. An integrator that installed a modem nobody documented may find itself a custodian of key records and, depending on the facts, a defendant, and its remote-access logs and project-file archives are the before-and-after record a court may ask for. Preservation letters tend to arrive before subpoenas do.

Regulators are not waiting for attribution

The policy response was already in motion before July. New York adopted water sector cybersecurity regulations March 11, 2026, billed by the governor’s office as the first in the nation, after proposing them in 2025. The rules from the state health and environmental agencies set drinking-water cybersecurity requirements for covered community water systems serving over 3,300 people; baseline controls for publicly owned treatment works, which may fully separate OT from IT and external networks or secure the connections they keep; enhanced network monitoring and logging for wastewater plants with permitted design flows of 10 million gallons a day or above, a regulatory definition rather than a statement about daily throughput; and cybersecurity incident reporting for all state wastewater permittees, with oral reports due within 24 hours. The state put the drinking-water requirements on a compliance clock ending Jan. 1, 2027, while the wastewater requirements phase in on their own schedule from the March adoption. After an event like Minnesota’s, a utility’s compliance posture stops being a checklist and becomes evidence.

CISA, for its part, asked for something faster than rulemaking: disconnection, as soon as possible, of every PLC still reachable from the public internet. The Minnesota window makes the urgency concrete. MNIT counted over 30 systems targeted inside 48 hours July 26 and 27, and the four cities that disclosed impacts kept water service: South St. Paul and Plymouth ran affected operations manually, Maple Plain maintained operations after its automated controls were hit, and Braham restored from backup after a brief outage.

No public record establishes that Braham, or any other Minnesota utility, failed to preserve evidence; the question is prospective, and the competing demands of safe water service, technical recovery, investigation and preservation are less mutually exclusive than unsequenced. That competence is worth studying, and so is its cost. The better a utility gets at restoring controllers, the faster it can overwrite whatever an intruder may have left behind. When the next lockout forces a choice between restoring service in 90 minutes and preserving evidence that may exist nowhere else, who at your organization, or your client’s, is authorized to make that call, and where is it written down?



News sources



Assisted by GAI and LLM technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).