Cyberattacks Disrupt US Water Utilities, Exposing Critical Infrastructure Vulnerabilities
Multiple water and wastewater utilities across at least seven U.S. states have been targeted by cyberattacks exploiting unpatched, internet-exposed industrial control systems, leading to operational disruptions and a local state of emergency.

In a stark reminder of the fragility of critical infrastructure, water and wastewater utilities across at least seven U.S. states have been targeted by a wave of cyberattacks since late July. The FBI and Environmental Protection Agency (EPA) issued a joint alert on August 6th, highlighting that these attacks exploited internet-facing programmable logic controllers (PLCs) – the industrial computers that manage essential functions like pumps, valves, and water treatment processes.
These attacks, while not sophisticated, have had tangible impacts. Utilities reported disruptions including pressure loss and flooding, forcing some systems to revert to manual operations. The severity in one Minnesota community led to the declaration of a local state of emergency. Crucially, attackers did not rely on zero-day exploits or novel malware. Instead, they exploited basic security oversights: PLCs directly exposed to the public internet, many running outdated software that no longer receives security patches. Attackers gained access, altered configurations, changed IP addresses and passwords, and effectively locked operators out of their own equipment, with at least one incident involving modifications to the core control logic.
This incident echoes a similar series of attacks against water utilities in late 2023, which also prompted federal guidance. However, the current wave demonstrates an escalation in attacker ambition and methodology. Moving beyond mere screen defacement, attackers are now targeting dozens of systems simultaneously. This broader impact is facilitated by the common practice of third-party integrators deploying identical, vulnerable configurations across numerous small utilities, creating a widespread attack surface.
The root cause of these recurring vulnerabilities lies in systemic issues within the U.S. water sector. With approximately 50,000 community water systems, many are small, publicly funded entities where cybersecurity is a secondary concern to the primary mission of providing safe and reliable water. The aging infrastructure, often a decade or more old, requires capital investment for replacement that many utilities lack. Furthermore, cybersecurity regulations for water systems remain largely voluntary, creating an environment where basic security measures are often overlooked.
Despite the systemic challenges, the defenses required to mitigate these threats are neither complex nor costly. The FBI and EPA have outlined clear, actionable steps that organizations should implement immediately. Key recommendations include isolating PLCs from the public internet by routing remote access through secure gateways, enforcing strong, unique passwords to replace default or shared credentials, and implementing network segmentation with firewall rules to restrict device communication. Locking down control logic and practicing manual operations are also critical for resilience.
Asset visibility is paramount; many utilities are unaware of their own internet-exposed devices until an attack occurs. A comprehensive inventory often reveals forgotten modems and integrator-installed remote access points. Continuous monitoring of Operational Technology (OT) environments is essential to detect the subtle signals of intrusion—such as configuration changes or password resets—before they escalate into widespread operational degradation. The difference between detecting an intrusion early and a system failure can be the difference between a minor incident report and a public health crisis.
Water systems operate with minimal margins for error and often possess the fewest resources for defense. The repeated nature of these attacks suggests that threat actors are testing the resolve of the sector to implement basic security hygiene. The FBI and EPA have provided a clear roadmap; the onus is now on the utilities to act decisively and prove that these vulnerabilities can and will be addressed, safeguarding a vital public service.
This incident underscores a persistent challenge in securing industrial control systems: the gap between the criticality of the service provided and the investment in its cybersecurity. The attacks exploit not just technical flaws but also the economic and structural realities of the sector, highlighting the urgent need for both regulatory action and increased funding to bolster the resilience of America's water infrastructure.