Clean water is supposed to be boring. Recent cyberattacks show why keeping it that way requires attention.
You turn on the tap and water comes out, but the complex systems working behind the scenes usually remain invisible. Recent cyberattacks have pulled back the curtain, revealing how much that reliability depends on aging technology, remote connections, and industrial computers managed by small teams.
What happened
Beginning around July 26, water and wastewater utilities in several states reported malicious activity involving operational technology.
Minnesota officials said more than 30 community water systems were targeted on July 26 and 27. The FBI later said utilities in at least seven states had reported similar incidents beginning July 27. Michigan confirmed activity affecting nine systems, while Rapid City, South Dakota, contained an intrusion involving a wastewater lift station. Wisconsin warned utilities but had not confirmed a successful compromise there.
The targets included programmable logic controllers, also known as PLCs. These are small industrial computers used to monitor or control pumps, valves, pressure systems, tanks, alarms, and other vital equipment.
According to joint reports from the FBI and EPA, attackers remotely accessed internet-facing PLCs to alter network addresses and passwords, locking operators out of their own systems. Losing visibility and control in this way is the digital equivalent of a burglar rekeying your front door on their way out. In at least one case, attackers went a step further by tampering with a PLC’s project file, the core blueprint that dictates how the controller operates.
This is a very serious attack: attackers interfered with technology that utilities depend on to control essential services.
Why water systems are vulnerable
Many smaller utilities operate with limited budgets, small technical teams, and equipment built before cybersecurity became a major concern.
Remote access allowed operators and vendors to monitor equipment and troubleshoot distant sites. But that convenience sometimes created security gaps.
Some devices remain reachable from the public internet. Other utilities rely on outdated controllers, shared passwords, old vendor accounts, forgotten cellular modems, or inaccurate network diagrams.
The FBI, EPA, CISA, and NSA have issued joint warnings about water infrastructure threats since 2024, when the EPA found that more than 70% of inspected water utilities failed to meet basic cybersecurity standards - things as simple as changing default passwords.
The lesson is clear: many utilities still lack protections that should be standard for critical infrastructure.
What needs to change
Protecting water systems is not a mystery. The problem is execution.
First, industrial controllers should not be directly exposed to the internet. Default and shared passwords should be eliminated. Remote access should pass through secure gateways, with multifactor authentication used at the VPN or access layer whenever the PLC cannot support it. Utilities should also search for forgotten connections. An old contractor-installed modem can become an attacker’s easiest route into a facility.
Second, business and operational networks must be separated. Some attacks begin with phishing or stolen office credentials and then move toward control systems. Others may target exposed PLCs directly. Traffic between the two environments should pass through tightly controlled gateways.
Third, utilities need visibility inside their operational systems. A firewall may show an attempted connection but not reveal that a PLC password, network address, operating mode, or project file changed at 2 a.m. Operators need alerts for unusual configuration changes, unexpected logins, new devices, and commands that do not match normal activity.
Fourth, utilities must rehearse incident response. Staff should know who disconnects remote access, who switches to manual control, who contacts federal and state agencies, and who communicates with residents. Those decisions should not be made for the first time during an emergency.
Finally, funding has to follow the warnings. A small utility cannot be expected to defend itself against sophisticated attackers using the same budget it relies on to repair pipes, replace pumps, and test water.
Cybersecurity funding should be treated like physical infrastructure funding. Replacing unsupported controllers, redesigning networks, improving remote access, and hiring qualified staff require sustained investment.
The bottom line
These attacks exposed something that is very important to address. Essential infrastructure still depends on aging, under-secured technology and small teams expected to defend public services with limited resources.
The urgent fixes are known: remove industrial equipment from direct internet exposure, secure remote access, separate networks, monitor configurations, maintain backups, rehearse response plans, and replace unsupported equipment.
Clean water should remain boring.
Keeping it that way will require sustained investment and recognition that cybersecurity is no longer separate from public health. It is one of the systems protecting it.
Sources: FBI, CISA, and EPA public advisories; reporting from CNN, CBS News, NBC News, The Washington Post, Time, Newsweek, Al Jazeera, AP, The Register, Forbes, Cybernews, NewsNation, and Cybersecurity Dive (July–August 2026).



