Attackers Hit 30-Plus Water Systems at Once, and OT Security Became a Design Spec

On July 30 the FBI and CISA issued warnings within hours of each other: attackers had remotely accessed programmable logic controllers at water and wastewater systems in at least seven states, and in some cases had degraded water operations.

The same day, Minnesota IT Services disclosed that state, local and federal officials had responded to malicious activity targeting technology at more than 30 community water systems. Michigan reported attacks on nine of its systems two days later, saying all were operating safely.

How It Worked

The method was not sophisticated. Attackers reached internet-facing controllers, then changed IP addresses and passwords, taking monitoring and control functions offline. The FBI identified Rockwell Automation and Allen-Bradley PLCs as targeted hardware and noted that similar considerations apply to other brands.

Federal remediation guidance amounted to three items: disconnect PLCs from the internet, enable password protection, limit remote access. That such advice is still necessary in 2026 is the actual finding.

CISA’s earlier advisory on July 22 had warned of ongoing Iranian-affiliated targeting of internet-connected operational technology. The agency called out one category specifically, and it should get the attention of anyone who builds or integrates plant controls: cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans.

That’s a construction and commissioning artifact. A modem gets dropped in for remote startup support, the integrator moves on, the as-built never captures it, and it sits on the network for a decade.

Why 30 at Once Is the Real Signal

Sean Tufts, field CTO for industrial at Claroty, framed the scale problem plainly. “Minnesota has fewer than 100 electric utilities, but more than 1,000 water systems supporting roughly five million residents,” he said. “Many of those systems operate with small teams and tight budgets, which creates exactly the kind of uneven security environment attackers look for.”

Simultaneity across 30-plus systems implies a shared dependency, whether a common technology, a service provider, or a broader state-level IT backbone. Individual utilities can’t audit their way out of a shared vulnerability they didn’t procure.

The Spec Problem

Municipal water and wastewater is a large, steadily funded construction market. Treatment plant upgrades, pump stations, SCADA packages and instrumentation all move through the same procurement path they always have. Very few of those bid documents carry a meaningful OT security specification, and fewer still assign responsibility for the network hygiene of devices the contractor installs.

That’s changing whether the specs catch up or not. When CISA names system integrators as an exposure vector, the liability question follows.

The same exposure exists outside municipal work. Any process plant runs on the same controller families. A food manufacturing facility like the $1.2 billion Chobani plant going up in Rome, New York will commission dozens of PLCs across 28 production lines, and every one of them gets configured by somebody during startup.

The design question for the next capital program isn’t whether the controls are secure at handover. It’s who is contractually responsible for them a year later.

Leave a Comment