The Romans built aqueducts so well that parts of them still stand nearly 2,000 years later. Gravity carried (relatively) clean water across mountains and valleys without a line of code, a network connection, or a password. Modern water systems are far more capable, but they also depend on digital controls that make them faster, smarter, and easier to operate remotely. Unfortunately, those same connections have created a new point of failure.
Federal agencies are investigating a coordinated series of cyberattacks affecting water and wastewater systems in a dozen states. Attackers have targeted internet-connected operational technology used to control treatment processes. In some cases, they changed passwords, modified network settings, and disrupted automated operations, forcing utilities to switch to manual control while officials assessed the damage. The attacks led to a flurry of small-town service disruptions, boil-water notices, and local flooding.
“With great connectivity comes great responsibility,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit focused on helping critical infrastructure withstand hackers. “Our dependence on connected technology is growing faster than our ability to secure it.”
A growing target
The incidents highlight a challenge that has been building for years. Many water utilities rely on operational technology that was designed long before cybersecurity became a central concern. Remote access capabilities, internet-connected industrial control devices, and limited cybersecurity staffing have expanded the attack surface, particularly for smaller municipal utilities. Federal agencies have repeatedly warned that water systems remain attractive targets for nation-state actors because they provide essential public services and often operate with constrained budgets.
These attacks are part of a broader pattern. The EPA, FBI, CISA, and the National Security Agency have issued multiple joint advisories warning that foreign-affiliated threat actors continue to target drinking water and wastewater systems. Their guidance consistently emphasizes basic but critical protections, including removing operational technology from direct internet exposure, implementing multifactor authentication, changing default passwords, maintaining offline backups, and regularly exercising incident response plans.
The EPA has also identified hundreds of cybersecurity vulnerabilities across water systems through its technical assistance efforts. Many of the weaknesses required straightforward remediation rather than sophisticated technology, reinforcing that foundational cyber hygiene remains one of the sector's greatest opportunities for improvement.
Why you should care: For industry professionals, the lesson reaches well beyond the water sector. Organizations should assume that operational technology is a target and regularly test how they would continue operating if automated systems became unavailable. Incident response plans should account for manual operations, executive decision-making, backup communication channels, and coordination with government agencies before an incident occurs.
Preparedness is often measured by what never happens. When critical systems continue operating despite an attack, that continuity is usually the result of planning completed long before the first alert arrives. |