Publication

When a Cyberattack on Water Becomes a Community Crisis

September 8, 2026

In late July, more than 30 community water systems across Minnesota were targeted in what state officials described as a coordinated cyberattack. Within days, the FBI reported similar activity affecting water and wastewater utilities in at least seven states.

Attackers remotely accessed technology used to monitor and control physical water-system equipment, changed passwords and network settings, and in some cases caused operators to lose visibility or control. Reported impacts included loss of water pressure and flooding.

Fortunately, the incidents did not result in widespread loss of safe drinking water. But they exposed something larger than a technical vulnerability: attackers found a repeatable way to reach technology controlling one of our most essential services.

What is a PLC, and Why Attackers Target It?

At the center of the attacks were programmable logic controllers, or PLCs. A PLC is a small industrial computer that tells physical equipment what to do. In a water system, it may control pumps, valves, tank levels, treatment processes, or water pressure.

Remote access is useful because operators, engineers, and vendors can monitor or troubleshoot equipment without traveling to every site. The risk increases when that technology is directly exposed to the public internet or remote access is not adequately protected with strong authentication, restricted access, network segmentation, and regular monitoring for suspicious activity.

Think of it this way: putting a PLC directly on the internet can be like putting a community’s water control panel outside the building. A lock helps, but without fences, cameras, and a few very protective dogs around it, an attacker has a much easier path to the controls.

Federal authorities again urged utilities to remove unnecessary internet exposure, strengthen remote access, use unique credentials and monitor operational systems. The recommendations sound basic because, in many cases, the weaknesses are basic.

Why Are Water Systems So Vulnerable to Cyberattacks?

Many local water and wastewater systems were not built as one modern digital environment. They evolved over decades. A treatment process was upgraded. A pump was replaced. An engineering firm installed a controller. Another vendor later added monitoring technology.

Different projects may have been completed under different funding sources, administrations and technical standards. Over time, those improvements can create a patchwork of old and new equipment that still has to work together every day.

Water utilities also operate under significant financial pressure. They must maintain aging pipes and pumps, meet regulatory requirements, replace expensive equipment, recruit specialized workers and keep rates affordable.

No mayor, council member or utility board wants to explain why water or wastewater rates need to increase. But repeatedly postponing modernization also creates risk.

Cybersecurity is no longer an add-on to water infrastructure. It is part of the infrastructure.

Who Is Responsible for Cybersecurity When Multiple Vendors Are Involved?

The attacks also highlighted a challenge common throughout local government: reliance on third parties. A community may own its water system, but an engineering firm may have designed it. A systems integrator may have installed the PLCs. Another company may provide remote monitoring.

Together, those arrangements create an important question: Who is responsible for cybersecurity when the community owns the infrastructure, multiple vendors maintain it, and no single organization sees the entire environment?

The FBI noted similarities in third-party network configurations across several victims, potentially allowing attackers to repeat successful techniques. Local governments need to understand who has remote access, how that access is secured, who monitors suspicious activity and how quickly vendors will respond during an incident.

Vendor risk is part of operational resilience.

Why Do Sophisticated Adversaries Target Critical Infrastructure?

Federal agencies have repeatedly warned that nation-state and nation-state-aligned actors are targeting U.S. critical infrastructure. The recent incidents have not been definitively publicly attributed to Iran, although Iranian-affiliated actors have previously targeted similar industrial technology in U.S. critical infrastructure.

The larger lesson is straightforward: advanced persistent threat actors look for systems that are both important and reachable. Critical infrastructure is attractive because disruption in the digital world can quickly become disruption in the physical world.

An attacker does not need to contaminate a water supply or shut down a major metropolitan system to create fear. Disrupt several smaller communities, interrupt operations, create boil-water notices or pressure concerns and publicize the incidents.

Suddenly the question becomes: Is our water safe?

How Does a Water Cyberattack Ripple Across a Community?

For residents, the inconvenience of losing water is obvious. For a community, the consequences are much larger.

  • Hospitals depend on water for patient care, sanitation and sterilization. 
  • Fire departments depend on adequate pressure. 
  • Schools, nursing homes and childcare facilities may be unable to remain open. 
  • Manufacturers can lose production. 
  • Restaurants and food processors may have to stop operations. 
  • Wastewater failures can quickly become public-health emergencies.

A cyberattack against a municipal water system can therefore cascade across sectors that were never directly attacked. If your organization cannot operate without services provided by local government, then local-government cybersecurity is part of your risk environment.

Why Smaller Communities Cannot Solve This Alone

Many small and midsize communities will never employ dedicated operational-technology cybersecurity teams. That does not make their infrastructure less important.

States are uniquely positioned to help close that gap through shared expertise, technical assistance, incident-response resources and funding that supports actual modernization.

Federal agencies are also providing guidance, assessments and exercises. The challenge is ensuring those resources result in practical improvements for utilities with limited staff and funding. Another assessment identifying problems a community cannot afford to fix does little to improve resilience.

What Should Business & Sector Leaders Do Now? The Impact Extends Beyond Government

Water and wastewater systems support hospitals, manufacturers, schools, universities, nursing homes, food processors and thousands of businesses. Leaders in those sectors should:

  • Understand how a significant disruption would affect their own operations and include that dependency in continuity planning.
  • Help policymakers understand the broader consequences of under-resourced critical infrastructure. 
  • Consider communicating with local, state and federal officials about the importance of ensuring water and wastewater systems have access to cybersecurity funding, specialized expertise, technical assistance and incident-response support.

That investment protects more than a utility. It protects public safety, economic continuity and community resilience.

The Bigger Lesson

The recent attacks exposed vulnerable technology, but they also exposed the gap between how essential water and wastewater systems are and the resources many communities have available to protect them.

Closing that gap will require stronger cyber hygiene, better vendor oversight, secure remote access and tested manual operations. It will also require recognizing that maintaining cybersecure operational technology is now part of maintaining the water system itself.

Water cybersecurity is not simply an IT problem. It is a community resilience problem, and protecting it is a shared responsibility.

How Ice Miller Can Help

Ice Miller's Tech, Privacy & Cyber Risk team helps utilities, local governments, and the organizations that depend on them turn cybersecurity risk into manageable resilience. Contact us.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Services & Industries

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights