Water Utilities Attacks: What They Can Teach About Identity Security

by
Nametag
North Korea Blog Post Header

What Unverified Identity Costs Enterprises Every Year

An industry-by-industry breakdown of what unverified identity costs enterprises every year.

A Monday morning. Late July. Minnesota. A municipal water utility operator arrives at work to discover the water treatment pump isn't working. There's nothing wrong with the equipment; it's simply gone rogue. Soon, it's revealed that more than 30 community water systems have been similarly compromised. The city of Maple Plain declares a local emergency. Days later, the FBI and EPA issue a joint public service announcement noting that “utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations."

This sequence of events really happened. And the story told afterward was mostly about exposure: Operational Technology (OT) devices, including Programmable Logic Controllers (PLCs), reachable on the open internet with basic or no protections. But this framing skips past what allowed the attack to be successful: At no point in the PLC password reset sequence did anyone or anything confirm who was on the other end. In effect, being able to reach the device was accepted as permission to reconfigure it. 

The system never asked the one question that would have stopped everything: Is the person doing this really who they claim to be?

Why Utilities and Critical Infrastructure are Especially Vulnerable to Cyberattacks

The most important part of these water utility attacks has very little to do with water.

Every day, across every organization, credentials change hands on the strength of what device a person is holding. A request comes in, an MFA prompt is answered, and an approval goes through. Nowhere in that sequence does anyone actually confirm who is behind the request.

Utilities carry a sharper version of that same exposure because so much of their access runs through shared hands. The FBI specifically notes that utilities share integrators, and integrators hold remote access. That creates an opportunity for clever attackers. 

For example, an IT employee may take a call from someone claiming to be an engineer at your SCADA vendor who is locked out mid-maintenance-window. That help desk agent has to decide in real time, under pressure, whether the request is legitimate. But in the age of generative AI and $30 deepfake kits, it’s beyond trivial to convincingly fake an identity.

This problem isn’t unique to water utilities. CISA, the NSA, and the FBI have confirmed that Volt Typhoon (a state-sponsored group) successfully breached IT networks across numerous critical infrastructure domains, including communications, energy, transportation, and water, by stealing access to valid accounts. In some environments, they went unnoticed for at least five years because every system along the way saw a valid account and treated that as enough proof. 

What the Minnesota Water Attacks Reveal About Enterprise Identity

The gap that let all of this happen doesn't close until you know, with certainty, who is actually acting in a particular moment.

Today's identity tools do a good job of getting part of the way there. An identity provider like Okta or Microsoft Entra ID confirms that valid credentials and a trusted device are in play. That's critical, of course, but it only tells you which account is acting, not which person. The account is an artifact; the device is an artifact. Neither is a human, and both can be presented by someone who isn't who they claim to be.

That is the gap Nametag closes. Our workforce identity assurance engine confirms the real human behind high-risk actions, based on who they actually are. An employee locked out mid-shift can prove it's really them and get back to work through self-service account recovery. A helpdesk agent can retire the security questions and the gut instinct calls, and act on definitive proof right inside the ITSM workflow they use. Every verification leaves an auditable record tying a confirmed human to the action they took, so the answer to Who is actually here? stops being a guess and becomes a fact.

The attackers in Minnesota didn't break a lock, they simply walked through a door that never checked for the right person. And that door is propped open in a lot more places than water plants.

See how Nametag closes and locks that door by confirming the real human behind every high-risk action: request a live demo.

Secure your helpdesk against social engineering and impersonators.
Decline
Accept All Cookies