BLACK mobile logo

california

community

How Hackers Attack Municipal Water Systems – And Why the Utilities are So Vulnerable

August 5, 2026

In late July 2026, cybercriminals launched coordinated attacks against at least 30 municipal water systems in Minnesota, with similar incidents subsequently occurring in Michigan, New Jersey, and other states. The attackers targeted programmable logic controllers—small computers that operate pumps, valves, and other equipment—rather than administrative systems, attempting to seize control of critical infrastructure serving millions of people. Utilities successfully defended against the intrusions by disconnecting automated systems and switching to manual operations, maintaining safe drinking water throughout the incidents.

Who is affected

  • Approximately 30 municipal water systems in Minnesota
  • Water utilities in Michigan, New Jersey, and several other states
  • Millions of people who depend on these water systems for drinking water
  • Water utility workers who had to operate equipment manually
  • Rural water utilities with limited cybersecurity resources
  • Rockwell Automation (manufacturer whose MicroLogix programmable logic controllers were targeted)
  • Small-staffed utilities operating critical infrastructure across roughly 152,000 public drinking water systems in the United States

What action is being taken

  • Utilities are shutting down control computers and sending personnel to operate equipment manually
  • Cybersecurity and Infrastructure Security Agency is urging water utilities to place equipment behind properly configured firewalls and safeguards
  • A group of volunteer cybersecurity experts is providing guidance to water utilities
  • The FBI and Environmental Protection Agency issued an advisory on July 30 about the attacks
  • Attackers are scanning internet addresses for vulnerable controllers and attempting to access systems

Why it matters

  • These attacks represent a significant threat to critical infrastructure that serves millions of Americans, demonstrating how vulnerable essential services like drinking water systems are to international cyberattacks. The incidents expose systemic weaknesses in water utility cybersecurity, particularly among smaller, resource-limited operations that may use outdated equipment with default passwords and direct internet connections. The attacks could potentially allow adversaries to shut off water flow or contaminate drinking water supplies, making them a serious national security concern. Additionally, the attacks highlight the broader vulnerability of approximately 152,000 public drinking water systems across the United States, many of which lack adequate cybersecurity defenses and resources.

What's next

  • Utilities should remove controllers and dashboards from direct internet connection and place them behind firewalls
  • When remote access is necessary, utilities should route communications through secure gateways or VPNs and require multiple levels of authentication
  • Utilities should change default passwords, disable unused remote-access services, and install vendor-approved updates
  • Water systems should separate operational networks from email and business systems
  • Utilities should back up controller programs, log remote-access activity, and practice restoring systems and operating manually
  • Smaller utilities may need government funding or shared cybersecurity services to defend themselves

Read full article from source: The San Diego Voice & Viewpoint

How Hackers Attack Municipal Water Systems – And Why the Utilities are So Vulnerable