For years, cybersecurity experts have warned that America’s critical infrastructure would eventually become a preferred target for nation-state hackers. That warning is no longer hypothetical.

Recent attacks against dozens of U.S. water and wastewater utilities demonstrate a growing willingness by sophisticated threat actors to move beyond traditional information technology (IT) networks and directly target operational technology (OT) environments. While none of the recent incidents resulted in unsafe drinking water, they exposed weaknesses in industrial control systems that could have had far more serious consequences.

The attacks serve as another reminder that cyber warfare is increasingly focused on disrupting the systems that support everyday life, including electricity, transportation, healthcare, communications, pipelines, and now municipal water systems.

The Recent Wave of Attacks

In late July, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA) issued joint warnings after multiple water utilities experienced unauthorized access to internet-facing industrial control devices. Several communities temporarily shifted operations to manual control while cybersecurity teams investigated the intrusions.

Many of the targeted facilities were small municipal utilities operating with limited cybersecurity staff and aging infrastructure. Investigators found attackers accessing programmable logic controllers (PLCs), modifying administrator credentials, changing configuration settings, and interrupting automated processes.

Minnesota experienced one of the largest concentrations of incidents, with more than 30 water systems reporting operational disruptions. Fortunately, water treatment operators were able to maintain safe drinking water through redundant monitoring systems and manual oversight.

Although the immediate impact was limited, the attacks demonstrated that adversaries are actively probing America’s critical infrastructure for exploitable weaknesses.

Why Water Utilities Are Increasingly Vulnerable

Water treatment facilities rely heavily on Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks to automate physical processes.

Unlike traditional enterprise networks, these systems control real-world equipment, including:

  • High-capacity water pumps
  • Chemical dosing systems
  • Pressure regulation valves
  • Storage tank levels
  • Filtration equipment
  • Chlorination systems
  • Distribution pumps

Many of these controllers were installed years or even decades before cybersecurity became a design priority.

Historically, these systems operated on isolated networks with little or no internet connectivity. Today, however, utilities increasingly depend on remote monitoring, cloud-based management platforms, vendor maintenance access, and internet-connected supervisory systems. Each new connection expands the attack surface.

In many cases, attackers did not exploit sophisticated zero-day vulnerabilities. Instead, they took advantage of exposed internet-facing devices, weak passwords, outdated firmware, and insufficient network segmentation.

Operational Technology Is Not Enterprise IT

One of the biggest challenges facing utility operators is that OT environments differ significantly from traditional IT networks.

Enterprise security teams are accustomed to regularly patching servers, replacing hardware every few years, deploying endpoint detection software, and restarting systems during scheduled maintenance windows.

Industrial environments operate under different constraints. Many PLCs remain in service for 20 years or longer. Some cannot be patched without interrupting water production. Others run proprietary operating systems with limited vendor support.

Even vulnerability scanning tools commonly used in enterprise environments can disrupt sensitive industrial devices if not carefully configured.

As a result, securing OT environments requires specialized expertise that blends cybersecurity with industrial engineering and process control.

Nation-State Activity Continues to Expand

Federal investigators have indicated that the recent activity resembles previous campaigns linked to Iranian cyber operators, although the investigation remains ongoing.

The tactics also align with a broader pattern seen across multiple adversarial governments.

China’s Volt Typhoon campaign demonstrated extensive efforts to establish persistent access inside U.S. critical infrastructure networks while avoiding detection.

Russian cyber operations have repeatedly targeted energy infrastructure in Europe and Ukraine.

Iranian-affiliated groups have increasingly shifted toward attacks on water systems, manufacturing, and municipal services.

Rather than conducting destructive attacks immediately, many threat actors appear focused on pre-positioning themselves within critical infrastructure. Maintaining persistent access provides strategic options during periods of geopolitical conflict or military escalation.

The Convergence of IT and OT Risk

Historically, cybersecurity programs concentrated on protecting confidential information, intellectual property, and financial assets. Critical infrastructure has changed that equation.

A successful ransomware attack against a hospital can delay surgeries; a compromised pipeline can interrupt fuel distribution; an attack on a power grid can leave entire communities without electricity.

Likewise, manipulating industrial control systems at a water treatment facility could disrupt chemical dosing, disable pumping stations, alter pressure throughout a distribution network, or interrupt service to thousands of residents.

Cybersecurity is no longer limited to protecting data, it is increasingly about protecting physical processes.

Lessons for Security Teams

The recent attacks reinforce several longstanding cybersecurity principles:

  • Asset Visibility – Organizations cannot protect systems they do not know exist. Maintaining an accurate inventory of OT assets, firmware versions, network paths, and remote access points remains foundational.
  • Network Segmentation – Operational technology should be isolated from enterprise IT wherever possible. Firewalls, industrial DMZs, and strictly controlled communication pathways reduce opportunities for lateral movement.
  • Secure Remote Access – Remote vendor access continues to represent one of the most common attack vectors. Multi-factor authentication, VPNs, least-privilege access, session logging, and time-limited credentials should be standard practice.
  • Continuous Monitoring – Traditional endpoint detection tools often provide limited visibility into industrial environments. Utilities increasingly rely on passive network monitoring, industrial intrusion detection systems, anomaly detection, and behavioral analytics specifically designed for ICS protocols.
  • Incident Response Planning – Perhaps the greatest success story from the recent attacks was the ability of many utilities to transition quickly to manual operations. Cyber incident response for industrial environments must include operational personnel—not just IT staff. Plant operators, engineers, and cybersecurity professionals need coordinated procedures for safely maintaining essential services during cyber incidents.

Preparing for the Next Generation of Threats

Federal agencies continue encouraging utilities to implement stronger cybersecurity controls, but technology alone will not solve the problem. Many smaller municipalities struggle with aging infrastructure, limited budgets, staffing shortages, and difficulty recruiting cybersecurity professionals with OT experience.

Addressing these challenges will require sustained investment in modernization, workforce development, public-private partnerships, and information sharing across government and industry. The attacks on America’s water systems should not be viewed as isolated events. They represent part of a broader campaign targeting the nation’s critical infrastructure.

As operational technology becomes increasingly connected, every utility – regardless of size – must assume it is a potential target.

The question is no longer whether attackers will attempt to breach critical infrastructure. The question is whether organizations can detect, contain, and recover from those intrusions before they affect the physical systems millions of Americans depend upon every day.

Related News

Kness retired in November 2007 as a Senior Noncommissioned Officer after serving 36 years of service with the Minnesota Army National Guard of which 32 of those years were in a full-time status along with being a traditional guardsman. Kness takes pride in being able to still help veterans, military members, and families as they struggle through veteran and dependent education issues.