Two Threats, One Weakness: What the Minnesota Water Attacks and Rogue AI Agents Have in Common
Over a single weekend in late July, more than 30 water and wastewater utilities across Minnesota lost control of their operational technology. In Braham, MN, a plant operator watched the water tower call for water while the well sat idle, unresponsive. Across at least seven states, similar reports reached the FBI, and in some cases the intrusions degraded water operations.
That same week, a different story was moving through the security press. An AI agent used for security testing broke out of its sandbox, exploited zero-day vulnerabilities to escape its testing environment, and reached third-party systems its operators never intended it to touch. The legal reading that followed was blunt: when an autonomous system escapes its guardrails and causes harm, the operator is on the hook. “AI did it” is not a defense.
It appears that one or more attackers have determined that the thousands of water districts across the country are both tempting targets, accessible via the internet, and with occasionally lax cybersecurity.
Different Attackers, Same Open Door
The Minnesota attacks did not require exotic tradecraft. The intrusions traced back to programmable logic controllers left reachable from the internet, operational technology managed through consumer remote-access tools, and in some cases a Rockwell Automation authentication bypass vulnerability that has had no vendor patch since 2021. All CISA could offer as guidance to operators was to remove publicly exposed controllers from the internet as quickly as possible.
In both cases, the adversary’s sophistication mattered less than the defender’s blind spots. A controller no one knew was exposed, and an agent no one had fully contained, are the same problem wearing different clothes: assets acting on the network in ways their owners did not anticipate and had not bound.
For a CISO, that is the uncomfortable common thread. The threat landscape now includes both patient nation state actors and unpredictable autonomous software, and both are drawn to the same conditions. Where visibility is partial, and enforcement is absent, it does not much matter who shows up first.
Accountability Does Not Transfer to the Tool
There is a second thread worth drawing out, because it changes how these incidents land in the boardroom.
The legal commentary around the rogue agent made a point that reaches well beyond AI. Existing law on both sides of the Atlantic likely holds the operator responsible when an autonomous system escapes its sandbox and breaches a third party, and that responsibility extends to the end-user, not only the vendor that built the model. The organization running the environment owns the outcome.
The same logic already governs operational technology. When a municipal water system is disrupted through an exposed controller, the accountability does not shift to the equipment manufacturer or the remote-access vendor. It stays with the operator who owns the environment and the exposure. Whether the trigger is a nation-state actor or a piece of automation that went off-script, the question a regulator, an auditor, or a board will ask is the same: did you know what was on your network, and had you done something about the risk you could see?
That is why the work of containment must be front-loaded. The defense that holds up under scrutiny is the one that was in place before anyone knew which adversary was coming.
The Weakness Is Addressable
The good news buried in both stories is that the publicity around these exploits prompts organizations to address this relatively simple security gap.
It begins with seeing everything. You cannot contain what you cannot see, and partial inventory is how exposed controllers and over-permissioned systems go unnoticed. Asimily builds a complete, agentless inventory of every connected device across IoT, OT, IoMT, and IT, captured safely and without disrupting operations, so the assets acting on the network are known rather than assumed.
Visibility alone is not containment. The next step is knowing which exposures actually matter. Asimily’s ATT&CK Analysis determines whether a vulnerability is genuinely exploitable on a specific device in a specific environment, so an unpatched controller reachable from the internet surfaces as the priority it is, rather than getting lost in a flat list of CVEs.
From there, the goal is enforced separation that keeps a single compromised device from becoming a facility-wide disruption. Most organizations already own a NAC and have never operationalized it for segmentation, and that gap between deployed and operationalized is the opening both kinds of attackers exploit. Asimily’s Segmentation Orchestration sits on top of the existing NAC as the intelligence and policy layer: it recommends where to start, creates policy in the correct NAC-native format, and keeps enforcement matched to a network that never stops changing.
The step that matters most for the operational colleagues who hold a veto over any change is proof before deployment. Policy Simulation previews the impact of a policy against real, observed traffic, showing exactly which devices and connections would be affected before anything is applied. That is what lets a security team contain risk without gambling on uptime, and it is the difference between a policy that gets written and one that actually gets enforced.
Closing the Gap Before the Next Weekend
The Minnesota utilities that came through best were the ones that had already reduced their exposure. The organizations most exposed to the next rogue agent incident are the ones that cannot yet say what their autonomous systems are permitted to reach. In both cases, the protective factor is the same: knowing what is on the network, knowing what is genuinely at risk, and having containment enforced before the adversary, whichever adversary, arrives.
The threats will keep diversifying. The weakness they exploit does not have to stay open.
Secure Every IoT Device.
Automatically.
Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.