Hackers Are Reaching Through the Internet and Touching America’s Water
This cyberattack didn’t steal data. It changed water pressure.
When most people hear “cyberattack,” they imagine stolen passwords, ransomware or leaked customer information.
This attack crossed a much more disturbing line.
Hackers have been targeting internet-connected industrial controllers used by American water and wastewater utilities—and in some cases, the consequences moved beyond computer screens and into the physical world.
Water pressure dropped.
Equipment stopped responding normally.
Flooding occurred.
Water and wastewater facilities in at least seven states reported attempted compromises, according to federal authorities.
More than 30 community water systems in Minnesota alone were reportedly targeted during one coordinated wave. (Anadolu Ajansı)
The attackers weren’t simply trying to steal files from an office computer.
They were targeting machines that help control the water itself.
Meet the Computer That Controls the Physical World
The devices at the center of the federal warning are called:
Programmable Logic Controllers—or PLCs.
Most people will never see one.
But PLCs are everywhere.
They’re specialized industrial computers used to control physical equipment.
A PLC might tell a pump:
Turn on.
Turn off.
Run faster.
Run slower.
Open a valve.
Close a valve.
Maintain a particular pressure.
At a water utility, these systems can be part of the infrastructure responsible for moving and managing enormous amounts of water.
And attackers were reportedly reaching some of them through the public internet.
The Hackers Changed the Passwords
According to the FBI and EPA, attackers targeted internet-facing Rockwell Automation/Allen-Bradley PLCs.
They remotely changed things including:
IP addresses.
Passwords.
Those changes could prevent legitimate operators from monitoring or controlling equipment normally. (Anadolu Ajansı)
Think about what that means.
You’re responsible for operating a municipal water system.
You open your control interface.
The password doesn’t work.
Or the controller isn’t where your network expects it to be anymore.
Meanwhile, the equipment that computer controls is still connected to actual pumps, valves and water infrastructure.
The attacker didn’t merely lock you out of a computer. They potentially interfered with your ability to control a physical process.
Some Attacks Had Physical Consequences
Federal authorities say some malicious activity degraded water operations.
Reported consequences included:
Loss of water pressure.
Flooding.
That distinction matters.
Cybersecurity has spent decades warning that attacks against operational technology could eventually produce real-world consequences.
This is what that transition looks like.
Bits become pressure.
Commands become pump behavior.
Network settings become physical disruption. (The Wall Street Journal)
Fortunately, operators in affected systems were able in some cases to switch to manual controls or other alternatives.
There have been no reports that the latest attacks contaminated drinking water. (The Wall Street Journal)
But that’s not a reason to dismiss what happened.
It’s a reason to understand how close digital infrastructure now sits to physical infrastructure.
Why Would Anyone Put a Water Controller on the Internet?
There’s a legitimate reason.
Remote access is incredibly useful.
A small municipal utility may have limited personnel covering facilities spread across a large geographic area.
Instead of driving to every pump station, tank or treatment facility, operators can remotely:
Monitor equipment.
Check alarms.
Review pressure.
Diagnose problems.
Change settings.
Restart systems.
That can save enormous amounts of time and money.
But remote access creates a dangerous equation:
If you can control it remotely, somebody else may try to control it remotely too.
The problem becomes especially serious when industrial equipment was designed primarily for reliability and availability—not for surviving attacks from adversaries scanning the entire internet.
The Internet Is Constantly Being Scanned
One misconception businesses have is:
“Nobody knows our system is there.”
That’s increasingly meaningless.
Attackers continuously scan the internet looking for exposed:
Firewalls.
VPN appliances.
Remote desktops.
Cameras.
Servers.
Routers.
Industrial controllers.
Human-machine interfaces.
They don’t necessarily need to target your municipality by name.
They can search for a type of vulnerable device and discover your municipality afterward.
EPA and CISA have specifically warned that internet-exposed industrial interfaces can be discovered using publicly available internet-scanning platforms. (CISA)
In other words:
The attacker doesn’t need to ask:
“How do I hack this water utility?”
They can ask:
“Show me exposed industrial controllers.”
Then start working down the list.
Small Town Doesn’t Mean Small Target
This is one of the most important lessons.
A tiny municipal water authority may think:
Why would a sophisticated attacker care about us?
Because the attacker may not care who you are.
They care that you’re vulnerable.
And smaller utilities can sometimes be attractive precisely because they have:
Smaller IT budgets.
Older equipment.
Limited cybersecurity staff.
Legacy industrial systems.
Remote-access requirements.
Few people available overnight.
EPA has acknowledged significant cybersecurity weaknesses throughout the water sector. In work conducted during 2025, the agency identified vulnerabilities at 277 water systems and helped address hundreds of issues. (US EPA)
Cybersecurity isn’t only a Fortune 500 problem anymore.
A town with 2,000 residents can sit on the same hostile internet as a multinational bank.
There Is an Important Difference Between IT and OT
Businesses protect IT.
Email.
Microsoft 365.
Laptops.
Servers.
Customer databases.
Water facilities also operate OT—Operational Technology.
OT controls physical processes.
And securing OT requires a different mindset.
If an employee’s laptop crashes, that’s inconvenient.
If a water-treatment control system stops functioning, operators may have to maintain a public utility manually.
If an industrial process is incorrectly manipulated, equipment can potentially be damaged.
Availability and safety become just as important as confidentiality.
You aren’t only protecting information. You’re protecting physics.
Why “Just Patch It” Isn’t Always Easy
Industrial environments can contain equipment expected to operate for decades.
Some systems cannot simply be rebooted Tuesday afternoon because a software update became available.
Updates may need testing.
Maintenance windows may be limited.
Specialized vendors may be involved.
Old equipment may no longer support modern security controls.
And shutting down the system itself can disrupt operations.
That’s why protecting operational technology requires layers around the equipment—not simply antivirus installed on everything.
Federal Agencies Are Giving Water Utilities Very Basic Advice
And that’s perhaps the most concerning part.
Many of the recommendations aren’t futuristic cybersecurity technologies.
EPA, FBI and CISA have repeatedly emphasized fundamentals:
Remove operational technology from direct public internet exposure whenever possible.
Use strong authentication.
Change default passwords.
Strictly control remote access.
Maintain accurate inventories of IT and OT equipment.
Back up critical systems.
Monitor configuration changes.
Develop and practice incident-response procedures.
And maintain the ability to operate manually when digital systems become unavailable. (US EPA)
That last recommendation deserves attention.
Manual Control May Be the Ultimate Backup
We usually think about backups as copies of data.
Operational technology needs another kind of backup:
A way to operate without the computer.
Can employees run the system if remote access disappears?
Do they know how?
Are procedures documented?
When was the last time anybody actually practiced it?
EPA’s 2026 national cybersecurity exercise specifically challenged water utilities to operate when internet connectivity, telecommunications, SCADA remote access, cloud services and other digital systems became unavailable. (US EPA)
That’s excellent cybersecurity thinking.
Don’t merely ask:
“How do we prevent an attack?”
Ask:
“How do we keep operating after prevention fails?”
Every Business Should Ask the Same Question
You probably don’t operate a water-treatment plant.
But your business may have its own version of an exposed PLC.
A firewall with remote administration enabled.
An old server reachable from the internet.
A forgotten remote desktop connection.
A security camera with default credentials.
A building-access controller.
An HVAC system.
A vendor-maintained appliance.
A copier.
An IoT device nobody remembers installing.
Your MSP should know every internet-facing asset your organization owns and why it needs to be exposed.
If nobody can explain why something needs direct internet access:
It probably shouldn’t have it.
Healthcare, Law Firms and Schools Have Physical Dependencies Too
This matters beyond utilities.
Hospitals depend on building controls, medical infrastructure and network-connected equipment.
Schools operate cameras, door-access systems, HVAC equipment and other connected technology.
Law firms and SMBs increasingly occupy “smart” buildings containing network-connected access, environmental and security systems.
The traditional boundary between cybersecurity and physical security is disappearing.
A compromised account can open a file.
A compromised controller can open a valve.
Both are cybersecurity problems.
The Water Coming From Your Faucet Depends on Computers
That’s the uncomfortable lesson.
Modern civilization quietly depends on thousands of computers most people never see.
They move water.
Manage electricity.
Control manufacturing.
Coordinate transportation.
Operate buildings.
Run telecommunications.
And increasingly, some of those systems are connected—directly or indirectly—to the same global internet containing criminals, hacktivists and nation-state operators.
The latest water-system attacks didn’t create a national public-health disaster.
Operators contained the damage.
Manual systems worked.
Water continued flowing.
That’s good news.
But pressure loss and flooding should be treated for what they are:
A warning shot.
Because ransomware stealing files is expensive.
A cyberattack manipulating the physical systems keeping a city alive is something entirely different.
The next critical infrastructure breach may not appear on your screen.
You may notice it when you turn on the faucet.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #CriticalInfrastructure #DataProtection #ManagedIT #CyberSecurityAwareness