CYBERAZIMUT
Internet exposure monitoring

Four questions
to ask on Monday morning

On 23 July 2026, an unauthorized person breaks in and takes control of a drinking water station serving 350 people. Yet this attack was not targeted.

How events unfolded
23 July 2026 at 7:30 a.m.

Saint-Noel, Bas-Saint-Laurent. Population 387.

The pro-Russia group Z-Alliance gets into the drinking water station's system, disables the water level alarms and changes the chlorine dosing, then posts a ten-minute video on Telegram. The employee on duty detects the intrusion shortly after 8 a.m. The water stayed safe to drink, but it was not a defence that protected the village: according to Radio-Canada, by setting the level probes to zero the attackers unintentionally triggered the automatic shutdown of the pumps.

Radio-Canada, 30 July 2026 · Le Soleil and Noovo, 31 July 2026. Investigation by the Surete du Quebec, the provincial police force.

The same day

Halton Hills, Ontario. Population 62,951.

The NoName group claims access to the Georgetown water treatment station and posts screenshots of its supervisory display. On 27 July it writes: "While officials talk about reliability, we are quietly inside their system." It was a cybersecurity expert, and then the press, who warned the municipality.

Radio-Canada · claim published by the group.

26 to 27 July 2026

More than 30 community water systems in Minnesota.

Pressure losses, boil water advisories, reversions to manual operation. On 30 July the FBI counts at least seven states affected; the count will reach twelve in early August, and attribution is still unsettled. The same day, the US cybersecurity agency describes a significant escalation in attacks against control equipment reachable from the internet.

Tenable · ABC News, 4 August 2026 · FBI alert and CISA sector alert of 30 July 2026.

What these attacks have in common

This was not an attack on Saint-Noel.

Twenty-two months before 23 July, the Government of Canada had written down what was going to happen.

"We assess that PRNS actors will likely attempt to disrupt vulnerable Internet-connected OT systems within Canadian critical infrastructure when the opportunity arises."

"This activity opportunistically targets internet-accessible devices and exploits basic vulnerabilities, such as insecure remote access software or the use of default passwords."

Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026. Information available as of 20 September 2024. "PRNS" stands for pro-Russia non-state, and "OT" for operational technology: the equipment that runs a plant, a water system or a building, as opposed to office computers.

The important word is not "Russia". It is "opportunistically" and "internet-accessible".

Nobody in an office overseas picked Saint-Noel. Nobody assessed its budget or its strategic importance. An automated sweep of the internet found an exposed sensitive service, and simply interacted with it. A village of 387 people, a town of 63,000, neither mattered: size never entered the equation. Besides, they were not the first.

Nine months earlier, the same Centre reported three Canadian incidents in the space of a few weeks: a water facility, an oil and gas company, a farming operation. Alert AL25-016, 29 October 2025.

The sentence that sums up the whole problem does not come from the attackers. It comes from a cybersecurity expert quoted by Radio-Canada, who alerted the police in the Ontario case: "I am the one who called to wake them up, because nobody knew.". A municipality can be inside a system that is being claimed publicly on Telegram, and learn about it from a third party.

Why did nobody know?

The problem is not protecting yourself. It is knowing what there is to protect.

This is not a hypothesis. It is a public auditor's finding, made in Quebec, then checked again three and a half years later.

0 of 3

Of three towns audited on their control systems, none had classified their assetsQuebec

In 2022, all three held data about that equipment, but none had ranked it by criticality. The first recommendation was to inventory and classify the assets: everything starts there. At the May 2026 follow-up, two towns reported 100% of recommendations applied or showing progress judged satisfactory. The third was at 43%, and the Commission is continuing its work with it.

This is not unwillingness, it is a question of hands. A municipality of 1,200 people has no information security officer: it has a general manager who does everything, and an IT supplier paid to keep things running, not to watch what is visible from outside. Among Canadian businesses, the share with staff dedicated to cybersecurity fell from 61% to 50% in two years; the survey does not cover public administrations.

Commission municipale du Quebec, the province's municipal oversight body: performance audit of 1 November 2022 and follow-up report of 21 May 2026. The towns are deliberately not named here: the point is not which one fell behind, it is that three and a half years are not enough. Staffing: Statistics Canada, Canadian Survey of Cyber Security and Cybercrime 2023 (12,462 businesses).

The Government of Canada puts it in one sentence. In its assessment devoted to water systems, the Canadian Centre for Cyber Security judges it almost certain that there are water system operators in Canada with devices exposed on the internet. The question it leaves open is which ones. Canadian Centre for Cyber Security, The cyber threat to Canada's water systems: Assessment and mitigation, information available as of 31 May 2025.

What monitoring like CyberAzimut's observes

Asset discovery

Subdomains, IP addresses, services and suppliers attached to the municipality, starting from a single domain name.

Exposed remote access

Remote desktop, access portals and perimeter firewalls, equipment management interfaces reachable publicly.

Email authentication

Who can write in the name of the town's domain, and which services actually send on its behalf.

Unintended leaks

Cloud storage left public, configuration files and logs reachable from outside.

Certificates and domains

Certificates approaching expiry, addresses still pointing at an abandoned service.

Report you can pass on

A dated document for the municipal council, the regional county municipality, or your insurer.

The analysis is entirely external: no software on your servers, no access to your systems, no interruption. It starts from a domain name and looks at your municipality the way someone looking for a door would.

What this is not, and it needs saying: we do not secure your water treatment plant. We do not talk to controllers, we do not enter your network, and we do not replace an on-site audit. We tell you what the world sees of your municipality from the internet, and we tell you again when it changes. You cannot protect what you do not know you own: that first step is the one nobody has time to take.

The four questions

They require no technical knowledge. They are put to your IT lead, to your service provider, or to both in the same meeting.

01Do we have a list of everything of ours that answers from the internet?

Good answerA dated list, reviewed on a known schedule, holding far more than websites: IP addresses, equipment, portals, supplier services.
Worth digging into"Yes, our two websites." The pumping station in the Halton area was not a website.

02Who, by name, keeps that list up to date, and how often?

Good answerA name, a frequency, and a written trace of the last update.
Worth digging intoA supplier's name with no written mandate. A managed services contract almost never covers monitoring of external exposure.

03Do our suppliers have remote access into our systems, and who knows about it?

Good answerA list of accesses by supplier, with an end date, and proof that those whose contract has ended are closed.
Worth digging into"We would have to check." That is exactly the pattern described by the Canadian Centre.

04When we last shut down a service, did we check its exposure?

Good answerYes, with a check made from outside, not from the town's network.
Worth digging into"It was unplugged." Unplugging a service and removing the address that points to it are two different acts. The second is almost always forgotten.

If the answers worry you, the first step costs nothing and has nothing to do with us: ask for that list in writing, with a date. Many municipalities find out at that moment that nobody keeps one.

Sources: Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026 (information available as of 20 September 2024) and alert AL25-016 of 29 October 2025, with the RCMP. Commission municipale du Quebec, performance audit report on the security of industrial control systems of 1 November 2022 and follow-up report of 21 May 2026. Radio-Canada (30 July 2026), Le Soleil and Noovo (31 July 2026) for Saint-Noel. CISA, sector alert of 30 July 2026. Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, 2023 (12,462 businesses with 10 or more employees, response rate 71%). KPMG Canada, survey conducted with Sago from 30 August to 25 September 2023 among 154 Quebec SMBs.
CyberAzimut · Facts verified as of 12 August 2026 · Quebec, Canada · Data hosted on Canadian soil · Observation catalogue aligned with NIST CSF 2.0 · cyberazimut.com