INSIGHT
What Utility Leaders Can Learn from the Recent Cyberattacks on U.S. Water Systems
Ryan Ferran, Josh Schmidt • September 2, 2026
Services: Penetration Testing Services, Incident Readiness, Cybersecurity Risk Assessments
If you run operations, IT, or security for a water or wastewater utility, the last month has probably felt uncomfortably close to home. Since late July, utilities in at least 12 states have reported coordinated cyberattacks on the programmable logic controllers (PLCs) and human-machine interfaces that keep drinking water and wastewater systems running. No utility has confirmed contamination of its water supply, but several were forced into manual operations, and at least one Georgia utility issued a boil-water advisory after attackers briefly disrupted its operational technology (OT) systems.
For an industry already stretched thin on budget and staff, this campaign is a clear signal that OT security can no longer sit at the bottom of the priority list.
What Happened, and Why It Matters to You
The first attacks surfaced in Minnesota, where more than 30 community water systems were hit over a single weekend in late July. Similar incidents quickly followed in Michigan, Georgia, South Dakota, and New Jersey, prompting a joint FBI and EPA advisory warning that malicious actors were remotely accessing internet-facing PLCs, changing IP addresses and passwords, and locking operators out of their own systems.
For your organization, the technical detail that should stand out is which devices were targeted. These were not sophisticated zero-day exploits. Attackers went after PLCs and human-machine interfaces that were directly exposed to the internet, often with weak or default credentials, a vulnerability class that has been documented for years and remains widespread across the sector.
Why Water Utilities Keep Showing Up as Targets
Your utility occupies a difficult position in the critical infrastructure landscape. A few realities make water and wastewater systems especially attractive to threat actors:
- Public health risk, low cost of entry. Disrupting treatment processes or stopping water service has immediate public health implications, giving attackers outsized impact for relatively unsophisticated intrusions.
- High consequence system damage. Gaining access to SCADA systems could allow attackers to trigger pressure overloads, damaging infrastructure across the entire service map.
- Legacy OT connected to the internet. Equipment installed years or decades ago, often without security as a design consideration, is increasingly bridged to internet-facing networks for remote monitoring.
- Inconsistent reporting requirements. Without a uniform federal mandate to disclose incidents, the true scope of exposure across the sector is likely larger than what has been publicly reported.
The Regulatory Runway Is Getting Shorter
Compliance deadlines are catching up with the threat. Community water systems serving between 3,301 and 49,999 people must certify updated risk and resilience assessments by June 30, 2026 under the America’s Water Infrastructure Act, and CIRCIA will soon require utilities to report significant cyber incidents to CISA within 72 hours. If your organization has been treating cybersecurity as a voluntary best practice, the window to get ahead of mandatory requirements is closing.
Building a Defense That Holds Up Under Pressure
Strengthening your posture does not require replacing every legacy system overnight. It starts with visibility and a few foundational controls:
- Inventory every OT asset connected to your network, including PLCs, HMIs, and remote access points, so you know what is exposed.
- Remove PLCs and HMIs from direct internet access, replacing open connections with secure gateways, firewalls, and multi-factor authentication.
- Segment IT and OT networks so a compromise on the business side cannot reach systems that control physical processes, and empirically test network segmentation
- Run tabletop exercises that walk your operations and leadership colleagues through a real incident, not just an annual training slide deck.
“The vulnerabilities behind this campaign aren’t new or exotic. Exposed PLCs, default credentials, and insufficient separation between IT and OT networks are issues we find in many assessments we run for water and wastewater clients,” said Ryan Ferran, BPM Cybersecurity Senior Manager. “Once you can see your OT environment the way an attacker does, deciding where to invest first gets a lot easier.”
Start With a Clear Look at Your OT Environment
You do not need to wait for a breach, or a compliance deadline, to take the next step. BPM’s Cybersecurity professionals work with water utilities and other critical infrastructure operators on OT and SCADA security assessments, penetration testing, and incident response planning built around the operational realities of utility environments, where safety and uptime come first. Let’s talk about where your environment stands today.
Ryan Ferran
Senior Manager, Advisory
Ryan holds degrees in Mathematics and Computer Science, which has provided the basis for his career in multiple technical fields, …
Josh Schmidt
Partner, Advisory
Josh started his career building IT systems in 2009 and has nearly a decade of experience working directly with clients …
Start the conversation
Looking for a team who understands where you’re headed and how to help you get there? Whether you’re building something new, managing growth or preserving success, let’s talk.