Skip to content

The New Battlefield: Protecting America's Water System from Cyber Attacks

Cyberattacks against America’s water systems are becoming a growing critical infrastructure threat. From the 2021 Oldsmar attack to the latest attacks targeting water utilities across multiple states, these incidents reveal how vulnerabilities in operational technology can have real-world consequences—and why stronger cybersecurity defenses are essential.

K
Kaitlin Hogue
August 14, 2026
The New Battlefield: Protecting America's Water System from Cyber Attacks

The New Battlefield: Protecting America’s Water Systems From Cyberattacks

The war used to be fought on the battlefield—with bombs, guns, and aircraft. Today, another battlefield exists largely unseen: cyberspace.

As technology continues to advance, cyberattacks are becoming an increasingly serious threat to critical infrastructure. Water and wastewater systems are among the infrastructure Americans depend on every day. Yet, they can also contain aging technology, limited resources, and internet-connected operational technology that can create opportunities for attackers.

In late July 2026, more than 30 water and wastewater systems in Minnesota were targeted in a coordinated cyberattack. The campaign eventually expanded across at least 12 states, according to cybersecurity researchers and federal agencies. In Braham, Minnesota, attackers disrupted the computerized controls of the city’s water well and treatment plant, temporarily forcing the facility offline. Service was restored within approximately two hours.

The incident demonstrates that cybersecurity is no longer simply about protecting computers and data. When technology controls physical infrastructure, a cyberattack can affect the services people depend on every day.

How Did the Attack Occur?

The attacks targeted internet-connected operational technology, including programmable logic controllers (PLCs). PLCs are industrial computers used to control physical processes such as pumps, valves, pressure, and other equipment.

According to reporting on the campaign, attackers accessed internet-exposed industrial controllers and changed settings, passwords, and other configurations. In some cases, operators lost the ability to remotely monitor or control equipment. The FBI and EPA warned that the activity could result in operational disruptions, including loss of water pressure and flooding.

This is what makes attacks against operational technology particularly concerning. An attacker does not necessarily have to steal sensitive information to cause harm. If they gain control of a system that interacts with the physical environment, the consequences can extend beyond the network.

Why Are Water Systems Being Targeted?

Water systems are part of America’s critical infrastructure. Communities depend on them for drinking water, sanitation, firefighting, hospitals, manufacturing, and countless other essential activities.

Many water utilities, particularly smaller municipalities, face challenges that can make cybersecurity difficult. Limited budgets, staffing shortages, aging equipment, and long equipment lifecycles can make it difficult to modernize infrastructure and maintain strong security controls.

Internet connectivity can introduce another layer of risk. Remote access may be useful for monitoring and maintaining industrial equipment, but systems that are directly exposed to the internet can become potential targets.

The 2026 attacks demonstrate why organizations need to know exactly what devices are connected to their networks and how those devices can be reached from outside the organization.

The Vulnerability Problem

The recent attacks also highlight another important issue in cybersecurity: vulnerabilities can remain dangerous for years.

One example is CVE-2021-22681, a critical authentication-bypass vulnerability affecting certain Rockwell Automation Logix controllers. The vulnerability received a CVSS score of 9.8, placing it in the critical severity category. Its existence illustrates the risks associated with industrial control systems when authentication and network security controls are inadequate.

However, CVE-2021-22681 should not be confused with the specific MicroLogix vulnerabilities involved in the 2026 Minnesota campaign. Researchers have identified internet-exposed MicroLogix controllers among the equipment targeted during the attacks, while CVE-2021-22681 affects different Rockwell Logix controller families.

The larger lesson remains the same: a vulnerability does not stop being dangerous simply because it is several years old.

Organizations operating industrial control systems must continuously identify vulnerable and outdated equipment rather than assuming that older technology is safe simply because it has been in service for years.

This Isn’t the First Time

The 2026 attacks are not the first time a water treatment facility has been targeted.

In February 2021, the city of Oldsmar, Florida, experienced an attempted cyberattack against its water treatment system. A plant operator noticed unauthorized activity and saw someone remotely accessing software that controlled the water treatment process.

The attacker attempted to increase the concentration of sodium hydroxide to a dangerous level. The operator recognized the activity, stopped it, corrected the changes, and notified his supervisor.

Fortunately, the attack was stopped before the attempted manipulation could cause harm.

The Oldsmar incident demonstrated the potential consequences of compromising water treatment technology. The 2026 attacks demonstrate that the threat has not disappeared.

What Can Be Done to Prevent and Prepare for Future Attacks?

The FBI, EPA, and CISA have provided recommendations that water and wastewater utilities can use to strengthen their defenses.

  1. Remove Industrial Control Systems From Direct Internet Exposure

PLCs and other control-system devices should not be unnecessarily accessible from the public internet. Organizations should identify internet-facing equipment and remove unnecessary exposure wherever possible.

  1. Use Strong, Unique Passwords

Default, weak, or reused passwords can make industrial systems easier to compromise. Organizations should use strong and unique credentials and change default passwords before placing equipment into production.

  1. Restrict Network Access

Water utilities should use firewalls, network segmentation, and access-control mechanisms to restrict which systems can communicate with PLCs and other operational technology.

Separating operational technology from business networks can help prevent an attacker who compromises an ordinary workstation from moving directly into systems controlling physical infrastructure. CISA specifically recommends placing control-system networks behind firewalls and isolating them from business networks.

  1. Secure Remote Access

Remote access can be necessary for maintaining water systems, but it should be carefully controlled and monitored. Organizations should use secure remote-access methods, keep VPNs and other access technologies updated, and ensure that remote access is only available to authorized users and devices.

  1. Identify Vulnerable and End-of-Life Equipment

Organizations should maintain an accurate inventory of their technology, including PLCs, HMIs, servers, remote-access devices, and other operational technology.

Knowing what is connected to the network is critical. Recent research found thousands of internet-accessible industrial devices associated with water infrastructure, highlighting how difficult it can be to protect assets that organizations may not realize are exposed.

When equipment reaches end-of-life and no longer receives security updates, organizations should evaluate whether it should be replaced or isolated through additional security controls.

  1. Apply Patches and Monitor Vulnerabilities

Security teams should monitor vulnerabilities affecting their specific equipment and apply available patches or firmware updates when possible.

Organizations should also recognize that not every vulnerability can simply be patched. Legacy systems may have limited support or may require replacement. This makes network segmentation, access control, monitoring, and other compensating controls especially important.

  1. Conduct Tabletop Exercises

A written incident response plan is not enough. Employees should regularly practice how they would respond to a cyberattack.

Tabletop exercises can help utilities answer important questions before an emergency occurs:

  • Who is responsible for shutting down affected systems?
  • Who contacts law enforcement?
  • How will operators communicate if computerized systems become unavailable?
  • How will the organization notify the public?
  • How will water service continue during an outage?

Practicing these scenarios can reveal weaknesses before a real attacker does.

  1. Maintain Backups and Manual Operations

Utilities should maintain reliable backups and regularly test their ability to recover from an incident.

They should also maintain the ability to operate critical systems manually if computerized controls become unavailable. The Braham incident demonstrated why this capability matters: when automated controls were disrupted, personnel had to respond quickly to restore operations.

  1. Provide Recurring Cybersecurity Training

Cybersecurity is not solely an IT responsibility. Operators, engineers, administrators, contractors, and leadership all play a role in protecting critical infrastructure.

Regular training can help employees recognize suspicious activity, understand their responsibilities during an incident, and respond appropriately when something goes wrong.

Cybersecurity Is Everyone’s Responsibility

The attacks against water systems should serve as a warning to organizations responsible for critical infrastructure.

Cybersecurity cannot be treated as an issue that belongs solely to the IT department. In an industrial environment, cybersecurity and physical safety are closely connected.

A compromised password, exposed PLC, outdated device, or poorly secured remote connection may seem like a small technical problem. But when that technology controls pumps, valves, pressure, or water treatment processes, the consequences can extend far beyond a computer screen.

The 2026 attacks also demonstrate why preparation matters. Organizations should not wait until an attacker has already gained access to determine how they will respond.

Water utilities need to know what devices they have, where those devices are connected, which vulnerabilities affect them, who can access them, and what happens if those systems suddenly become unavailable.

The FBI, EPA, and CISA recommendations provide organizations with practical steps to reduce their exposure. But protecting critical infrastructure requires more than a checklist. It requires continuous monitoring, investment, training, planning, and cooperation between cybersecurity professionals and the people who operate these systems.

America’s water systems are essential to everyday life. As cyber threats continue to evolve, protecting those systems must become a shared responsibility between technology professionals, system operators, government agencies, and the communities they serve.

The battlefield may have changed, but the objective remains the same:

Protect the infrastructure that protects us.