Threats

Water Sector Cyberattacks

August 6, 2026 16:08 · 12 min read
Water Sector Cyberattacks

Cyberattacks on Water Utilities: A Preventable Threat

Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment.

Some of these attacks degraded operations, with utilities reporting pressure loss and flooding, several systems reverting to manual control, and one Minnesota community declaring a local state of emergency. The attackers didn’t use sophisticated methods, instead finding controllers exposed to the public internet, many of which were old and no longer receiving security patches.

A Familiar Pattern

This is not the first time the water sector has faced cyberattacks. In late 2023, attackers compromised controllers at water utilities across several states, including a widely reported incident in Aliquippa, Pennsylvania. The federal government issued guidance then, but the problem persists.

The difference between then and now is that attackers have grown in ambition, moving from defacing screens to disrupting operations across dozens of systems at once. They are exploiting the fact that third-party integrators often deploy the same vulnerable configuration across many small utilities.

Prevention is Possible

The uncomfortable truth is that these attacks were preventable. The reason they weren’t stopped is more structural than technical. The United States has roughly 50,000 community water systems, most of which are small, publicly funded, and run by operators whose primary job is keeping water safe and flowing. Cybersecurity ranks far below that, if it ranks at all.

The devices in question are often a decade or more old, and replacing them takes capital that these utilities don’t have. Rules governing water cybersecurity remain mostly voluntary, and attackers understand these economics perfectly.

Taking Action

Inaction is a choice. The defenses that work here cost little and require no exotic technology. The FBI and EPA guidance is sound, and every water and wastewater organization should act on it this week, not later.

Continuous monitoring of OT environments exists to turn signals into alerts within minutes instead of days. That difference is the difference between an incident report and a boil-water notice.

Water systems have the least margin for error and, too often, the fewest resources to defend themselves. The FBI and EPA have told us plainly what’s happening and what to do about it. The attackers are betting we won’t follow through. For the third time in three years, they’re testing that bet. Let’s finally prove them wrong.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free