Last time this happened, it was a a malicious group brute forcing TeamViewer credentials, does anyone know if it was something different this time?
In Plymouth, officials started noticing technology malfunctions at some facilities Sunday night and switched to a backup plan to run those systems manually. Officials said there was no disruption to public water service.
At least they had people actually monitoring for issues. I wonder if close calls will ever be enough to motivate securing these endpoints better? It’s only a matter of time before a bad actor hits a utility that doesn’t catch them in the act.
Yeah the utilities area is downright scary. Usually run on thin margins, really old specialists that are rapidly retiring, no IT budget to speak of, and most mission critical tech is 20+ years old, off the shelf from companies long dead, and loosely networked by people who’s objective was “make it work”, not security or resilience.
The only way out- electrical companies basically HAVE to become public like all the other utilities, and funding, wages, job training, and modernization for all utilities needs to be prioritized massively.
Of course, there’s lots of political reasons for idiots to fight against all this, so it won’t happen until the worst already has.
does anyone know if it was something different this time?
The article says that Minnesota law classifies cyberattacks as nonpublic information, so what we learn about the details is likely to be limited.
The hegemonic narrative is that it’s Iran - retaliating for the imperial terror attacks on civilian infrastructure including and especially water plants. I’m not sure about their methods.

