Advertisement

Advertisement

Hackers Target Water Infrastructure

By Deborah L. O’Mara | Sep 3, 2026
wastewater facility from above
Web Exclusive Content

One of the most egregious cyberattacks on the water and wastewater systems critical infrastructure sector occurred this summer, spanning some 12 states and more than 100 individual utilities, according to the Cybersecurity and Infrastructure Security Agency (CISA).

Advertisement

Advertisement

Advertisement

Advertisement

Advertisement

One of the most egregious cyberattacks on the water and wastewater systems critical infrastructure sector occurred this summer, spanning some 12 states and more than 100 individual utilities, according to the Cybersecurity and Infrastructure Security Agency (CISA).

The culprit? Internet-accessible digital programmable logic controllers (PLCs), which automate and gather data from valves, water flow and chemical treatment. Used for industrial control, PLCs present elevated risk when not secured properly, especially legacy devices that weren’t built for modern cybersecurity and threat vectors.

These intrusions threaten the water supply and can disrupt water operations and processes. Worker safety could also be at stake, as well as the possibility of equipment damage and the risk of a cascading effect across interconnected systems.

Multistate cyber takeovers

Cyber intrusions started in Minnesota in July and spread to Alabama, Georgia, Michigan, New Jersey, South Dakota and other locations. Threat actors used a variety of methods to gain access: deployed internet scanning services to identify vulnerable PLCs, exploited code and circumvented default or insecure credentials.

In a July 2026 statement released by CISA, the organization “urged critical infrastructure owners, operators and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet. Threat actors targeted exposed PLCs, modified passwords to lock out operators and disconnected the devices by changing IP addresses. This activity resulted in boil water notices in Georgia and sustained manual operations.” 

While this cyber breach applied to the PLCs of several vendors, CISA “advised all PLC owners and operators to apply relevant mitigations to reduce the risk to their devices and systems.”

Vulnerable PLCs

CISA, the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Department of Energy (DOE) and Environmental Protection Agency (EPA) released a Joint Cybersecurity Advisory to all PLC owners and operators who leverage OT in their industrial processes to implement specific mitigation strategies and proactive access controls to combat bad actors.

These mitigations, said CISA, are particularly important for owners and operators who work with third-party service providers or system integrators who may have remote access to PLCs, “as the asset owners may not realize that their systems are exposed and at risk.”

Recommendations included:

  • Disconnect the PLC from the internet and isolate whenever possible. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
  • Enable password protection and change default passwords.
  • Allowlist IPs to only permit remote access from known engineering laptops or other critical OT assets.
  • Enable all applicable security patches and updates.
  • Harden overall access controls and PLC services, protocols and ladder logic integrity.
  • Use automated tools to proactively monitor for anomalies.
  • With open systems and communications, hackers have shifted their attacks to increasingly vulnerable OT and industrial processes. Applying active safeguards is now an essential part of protecting every part of the security environment and critical infrastructure.

CISA and EPA developed a Water and Wastewater Systems Cybersecurity toolkit with information and resources organizations can use to boost security. They also have no-cost vulnerability scanning programs, cybersecurity assessments and a 24/7 hotline to assist water utilities in preventing, detecting, responding and recovering from threats or attacks.

About The Author

O’MARA writes about security, life safety and systems integration and is managing director of DLO Communications. She can be reached at [email protected] or 773.414.3573.

Advertisement

Advertisement

Advertisement

Advertisement

featured Video

;

Advertise with Electrical Contractor in 2026

Learn about the benefits of advertising with Electrical Contractor Media Group in 2026. View our full media kit at www.ecmag.com/media-kit.

Advertisement

Related Articles

Advertisement