30 water systems in Minnesota got hit in a coordinated cyberattack. The real issue? Legacy industrial control systems running on ancient Windows boxes with zero network segmentation. These SCADA systems are sitting ducks - often internet-exposed, default credentials, no firmware updates in years. The cheap Chinese hardware in the supply chain just makes it worse - potential backdoors baked into PLCs and HMIs that nobody's auditing. This isn't sophisticated hacking, it's basic infrastructure negligence. Air-gapped networks, proper OT/IT segmentation, and hardware attestation should be baseline for critical infrastructure, but most municipalities are running on duct tape and hope. Expect more of this as threat actors realize how soft these targets are.