Something happened in late July that most organizations outside the water sector missed entirely — and they probably shouldn't have.
Between July 26 and July 27, a coordinated cyberattack hit water and wastewater systems across 30 municipalities in Minnesota. It cascaded into at least six more states. By the time federal agencies finished counting the damage in August, more than 100 internet-exposed water systems had been targeted. These weren't large metropolitan utilities with dedicated security teams. These were small, rural operations — the kind with three people in IT and a Siemens PLC sitting on a cellular modem that somebody set up eight years ago.
What made this different from past infrastructure attacks was the method. Threat intelligence shows the group used generative AI throughout the attack: LLMs to parse technical documentation for specific hardware models, AI-assisted scripting to debug ladder-logic exploits, automated reconnaissance to locate exposed devices. The attackers didn't need to understand Siemens S7 PLCs. They asked an AI to figure it out for them. Then they ran the scripts.
That's the shift nobody is processing fast enough.
The expertise barrier is gone
For a long time, attacking operational technology required specialized knowledge. Proprietary protocols, ladder logic, firmware quirks — the learning curve kept most attackers out. Nation-states could do it. Sophisticated criminal gangs occasionally could. But most threat actors couldn't be bothered because OT attacks were hard and the payoff wasn't obvious.
Generative AI just flattened that curve to nothing.
CISA confirmed that attackers are now using AI to write exploit scripts targeting internet-exposed Siemens S7 controllers using nothing more than publicly available documentation. No specialized OT expertise required. The AI handles the technical parts. The attacker points it at a target and iterates until something works.
If your org runs on aging, internet-connected systems and a lean IT budget — which describes most small NGOs, municipal departments, and public sector teams — that's the part that should make you uncomfortable. The complexity barrier that kept your obscure systems safe is gone. "Nobody would bother targeting us" stopped being true.
116 companies said the quiet part out loud
On August 27, a coalition of 116 organizations published an open letter with an uncomfortable timeline: "In the coming months, AI-enabled cyberattacks will become far more widespread."
Months, not years.
The letter called out the "historic under-resourcing" of security around hospitals, water utilities, and critical infrastructure specifically. It asked governments to start mobilizing now. The signatories aren't wrong, and the timeline matches what we're already seeing on the ground. AI attack tooling that was expensive and rare six months ago is now cheap, fast, and available to anyone willing to spend a few hours on the right forums.
The organizations least equipped to defend themselves are landing in the crosshairs first. Small water utilities. Rural hospitals. Nonprofits running aging infrastructure. Municipal IT teams stretched across too many systems.
What the attack pattern looks like
The water utility attacks followed a playbook that is going to get applied to softer targets in the months ahead.
First, mass scanning. AI-assisted tools identify internet-exposed assets at scale. Your VPN login page, your legacy admin interface, that SaaS tool someone set up in 2021 that still has an open port — all of it gets found. Fast.
Then, custom exploit generation. The attacker feeds the asset type into an AI that pulls from public CVEs, documentation, and existing proof-of-concept code. It produces working exploit code faster than a human security researcher could write it. The fact that your system is niche or obscure doesn't buy you anything anymore.
Then, exploitation. The attacker gets in, establishes persistence, and either does damage or waits. Rural water utilities got boil-water notices and operational disruptions. The equivalent for an NGO is donor database exfiltration, a ransomware lockout during a funding crunch, or operational downtime when it matters most.
Three things to do this week
This isn't about buying enterprise security software. Most small orgs have three practical moves that matter more than anything else right now.
Inventory your internet exposure. Run a scan of what you have visible. Tools like Shodan will show you what attackers see when they look at your organization. Legacy admin panels, remote desktop, VPNs running old firmware, any internet-facing controller or management interface — every one of these is a possible target. Close what you don't need open. Restrict access to what you do need.
Subscribe to CISA's Known Exploited Vulnerabilities feed. The old patching schedule model is obsolete. Active exploitation is now happening within hours of a CVE being published. The CISA KEV catalog is the floor: if something shows up there and you run it, patch it that day. Not next sprint. That day.
Separate your operational systems from general staff machines. If your operations, database access, or infrastructure management tools share a network with regular staff computers, fixing that segregation is the highest-leverage thing you can do right now. It's not complicated for a 20-person org. It just requires someone to actually do it.
One more thing worth knowing: CISA has free assessment services specifically for under-resourced organizations, including nonprofits operating infrastructure-adjacent services. Their Cyber Hygiene Services page is worth reading before you call a vendor.
The honest read on this
The attacks on 100+ water utilities weren't a warning shot. They were a proof of concept — AI-powered attacks work at scale against under-resourced organizations with limited defenses. The attackers know it works now. They're going to keep going.
The window where your org could stay secure through obscurity is closing. That 116-company letter said months. Based on what we're already seeing in the field, that's not hyperbole.
We work specifically with small teams in public sector and NGOs to audit exposure and get the highest-risk issues addressed fast. No six-month roadmap. Two weeks, hands-on. If you want to know what you have and what to fix first, that's exactly what we help with.