What's happened
Multiple states have reported coordinated cyberattacks that have targeted internet-connected controllers in water and wastewater systems. Agencies have said attackers have changed passwords and locked operators out, forcing utilities to revert to manual controls; officials have reported disruptions such as loss of pressure but said drinking water remains broadly safe.
What's behind the headline?
What is happening
Hackers have been accessing internet-connected programmable logic controllers that operate pumps, valves and alarms. When operators lose remote access, utilities are switching systems to manual control and dispatching staff to field sites. That keeps taps running but increases labour costs and operational risk.
Why this is systemic
- The US has roughly 152,000 public drinking water systems and 16,000 wastewater plants. Most are small, locally run and underfunded. That makes universal security expensive and slow to implement.
- Many PLCs were never designed to be internet-facing. Utilities have been exposing them for remote monitoring and vendor support, which gives attackers an easy entry point.
Who is driving the response
- Volunteer hacker teams such as DEF CON Franklin are moving from ad hoc help to formal support through the newly created Water Watch Center, which will focus on utilities serving fewer than 10,000 people.
- Federal agencies (FBI, CISA, EPA) are issuing guidance and alerts; some lawmakers are pushing statutory authority and funding to force and help upgrades.
Likely near-term outcomes
- Utilities will continue to disconnect internet access for vulnerable PLCs and revert to manual processes; this will reduce immediate risk but will increase operational strain and costs.
- Pressure will rise on Congress and federal agencies to fund retrofits, mandate minimum cybersecurity controls, and formalise rapid-response teams. Expect bipartisan bills and targeted grant programs within months.
Longer-term forecast
- Without sustained funding and a scalable delivery model, attacks will keep targeting small utilities because they provide the most reliable return on attacker effort. The Water Watch Center model will likely scale slowly; it will help many systems but will not replace federal investment.
Bottom line
This has moved water cybersecurity from warning to crisis management. The next six to 12 months will determine whether the US treats these incidents as isolated outages or as a structural failure that requires federal funding, regulation and long-term technical assistance.
How we got here
Federal agencies have warned for months that internet-facing programmable logic controllers (PLCs) leave water systems vulnerable. Small, local utilities often lack funding and staff to patch or isolate equipment, so investigators have found attackers scanning exposed PLCs and exploiting weak credentials.
Our analysis
The coverage agrees on the technical pattern but differs on emphasis and proposed remedies. The Independent reports that "malicious cyber actors" have infiltrated internet-connected water systems and highlights DEF CON Franklin's new Water Watch Center, quoting founder Jeff Moss that the program "spent two years with volunteer hackers in the trenches" to build a scalable model. Business Insider UK focuses on operational effects and technical detail: Kevin Morley of the American Water Works Association explains "it really depends on the device" being targeted, and Joshua Corman warns that "no water is no hospital in two to four hours." Axios frames the episode as one of the broadest coordinated campaigns to date and stresses the funding gap: "many U.S. water utilities lack the funding and personnel needed to secure critical infrastructure." CISA, the FBI and state agencies are cited across outlets advising utilities to disconnect PLCs and revert to manual control; the BBC and The Guardian repeat that officials have not publicly attributed all incidents, though several outlets report investigators suspect Iran-affiliated actors. TechCrunch and reporting from Poland were included in the source set but are separate examples of weak public-sector cybersecurity; TechCrunch documents mass website vulnerabilities in Poland to show how vendor neglect and unsupported software can expose critical services. Together the sources show a consistent technical pattern (internet-facing PLCs, changed passwords, locked operators out) and a divergence in solutions: volunteer hacker coalitions and rapid-response teams (Independent, Axios) versus calls for federal regulation, funding and standards (Axios, Business Insider, The Guardian).
Go deeper
- Which local utilities in my state have internet‑connected PLCs and who oversees their cybersecurity?
- How will federal funding or EPA authority change immediate protections at small water systems?
- What steps will my local water utility take to restore remote monitoring without exposing controls to the internet?
More on these topics
-
Minnesota - US State
Minnesota is a state in the Upper Midwest, Great Lakes, and northern regions of the United States. Minnesota was admitted as the 32nd U.S. state on May 11, 1858, created from the eastern half of the Minnesota Territory.
-
Iran (Islamic Republic of Iran) - Country in the Middle East
Iran, also called Persia, and officially the Islamic Republic of Iran, is a country in Western Asia. It is bordered to the northwest by Armenia and Azerbaijan, to the north by the Caspian Sea, to the northeast by Turkmenistan, to the east by Afghanistan a
-
United States - Country in North America
The United States of America, commonly known as the United States or America, is a country mostly located in central North America, between Canada and Mexico.
-
Cybersecurity and Infrastructure Security Agency - Agency
The Cybersecurity and Infrastructure Security Agency was established on 16 November 2018 when President Donald Trump signed into law the Cybersecurity and Infrastructure Security Agency Act of 2018.
-
Federal Bureau of Investigation - Law enforcement agency
The Federal Bureau of Investigation is the domestic intelligence and security service of the United States and its principal federal law enforcement agency.
-
Donald Trump - 45th and 47th U.S. President
Donald John Trump is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party, he served as the 45th president from 2017 to 2021.
-
Tim Walz - Governor of Minnesota
Timothy James Walz is an American politician who is the governor-elect of Minnesota. A member of the Democratic Party, he has served as the U.S. Representative for Minnesota's 1st congressional district since 2007.
-
Israel - Country in the Middle East
Israel, formally known as the State of Israel, is a country in Western Asia, located on the southeastern shore of the Mediterranean Sea and the northern shore of the Red Sea.
-
CISA - Wikimedia disambiguation page
CISA or Cisa may refer to:
-
Rockwell Automation - Company
Rockwell Automation, Inc. is an American provider of industrial automation and information technology. Brands include Allen-Bradley and Factory Talk software.
-
Michigan - US State
Michigan is a state in the Great Lakes and Midwestern regions of the United States. Its name comes from the Ojibwe word mishigami, meaning "large water" or "large lake".