Skip to content
"VC3 has made it easier than ever before for our local government to serve our citizens by providing us with modern web tools and a team
of talented and courteous professionals.
City of Valdosta, GA

Find All the Resources You Need

Our resources & insights includes case studies, client testimonials, guides, checklists, blog articles and more!

 

8 min read

Cybersecurity Alert: Coordinated Cyberattacks Hit 30+ Water Systems

Cybersecurity Alert: Coordinated Cyberattacks Hit 30+ Water Systems

In late July 2026, more than 30 municipal water systems across Minnesota were targeted in a coordinated cyberattack over 48 hours. Nine more systems were targeted in Michigan. By the time the FBI issued a formal alert days later, the bureau confirmed the activity had reached at least seven states. And as of August 11, 2026, the reported scope has grown to at least 12 states, including Georgia, South Dakota, Alabama, and New Jersey.

This is not an isolated incident. It's the same pattern federal agencies and our own advisories to clients have been flagging for years: warnings of nation-state actors probing U.S. water systems and the security lessons water systems should take from the 2021 Oldsmar, Florida attack. What's changed is scale and speed: this time, attackers didn't hit one plant — they hit dozens at once, using the same exposed devices and default settings named in those advisories.

If you're responsible for a water system, special district, or other essential service, this is the moment to treat these warnings as urgent rather than aspirational.

[Download the Water Systems Cyber Readiness Checklist →]

What happened in the July 2026 water system cyberattacks?

The equipment that runs a treatment plant (the controls for pumps, valves, and chemical feeds) was reachable directly from the internet in the communities that were hit, often still using its factory-default password. Attackers used that opening to lock staff out and disconnect the controls, similar to someone changing your building's locks and cutting the phone line at the same time.

In Braham, Minnesota, this took the water plant offline for close to two hours before staff switched to running it by hand, with no impact to water quality or safety. More than 30 Minnesota systems were hit that same weekend. Days later, CISA (the federal agency that coordinates critical infrastructure security) confirmed the problem is national, noting a significant increase in threat actors targeting programmable logic controllers (PLCs) and warning that the targeting spans water entities of all sizes, including organizations with mature cybersecurity programs. CISA urged operators to get publicly exposed controllers off the internet as soon as possible.

Not every community escaped without visible impact. In Clayton County, Georgia, a system outage triggered a boil water advisory on July 27 and 28, and the water authority is now investigating whether cyber activity contributed. 

Officials believe the goal was disruption, not financial gain. No formal attribution has been issued as of August 11, 2026, but investigators are examining possible links to Iranian-affiliated actors, echoing the November 2023 attack on the Municipal Water Authority of Aliquippa in Pennsylvania, which CISA tied to the same kind of actor.

Why does this keep happening to water systems?

Federal inspectors have been finding the same gaps for years. In a 2024 enforcement alert, the EPA reported that more than 70% of the water systems it had inspected were in violation of basic Safe Drinking Water Act (SDWA) Section 1433 cybersecurity protections, as we covered in our Cybersecurity Strategies for Water Systems guide. Multi-factor authentication (MFA) is one of the simplest of those gaps to close, and Microsoft's research credits it with blocking 99.9% of account compromise attempts. 

Water systems are attractive targets for exactly the reasons they're hard to defend. They run 24/7 essential infrastructure, they often operate with lean IT teams, and much of their operational technology (OT) was never designed with internet exposure in mind. Attackers don't need a sophisticated exploit when a PLC is sitting on the open internet with a factory-default password.

What should water systems do to protect themselves now?

You don't need a large security team to close the gaps these attackers are using. Some of these recommendations take budget and a procurement cycle, and most water systems will phase them in over time. But if there's anything to be prioritized, it's the first two items since they close the exact opening used in Minnesota.

Based on the FBI's mitigation guidance and the pattern across these incidents, here's where to start

1. Get OT devices off the public internet.

If a PLC, HMI, or engineering workstation can be reached directly from an external network, that's the single biggest exposure to close. Route remote access through a secure gateway, jump host, VPN, or firewall — not a direct connection.

2. Eliminate default and reused credentials.

Most control devices ship with a default password that's meant to be changed at installation. If you're not certain yours were, treat them as unchanged and verify. Pair strong, unique credentials with multi-factor authentication (MFA) on any remote or external access path. 

3. Segment OT from IT — and from vendors.

The lateral movement seen in this wave of attacks depended on shared or poorly isolated networks. A DMZ between external-facing systems and core OT, plus firewall rules that allow only authorized control-system communications, limits how far one compromised account can reach.

4. Build in visibility.

Several affected utilities didn't know something was wrong until service was already disrupted. Logging and monitoring for unusual logins, unexpected commands, or configuration changes catches problems before they become outages, as does periodically comparing running PLC logic against a known-good version.

5. Practice operating manually.

The reason Braham's outage lasted close to two hours instead of much longer is that staff could fall back to manual control. Every community water system should know, and periodically test, how to keep essential services running if automated systems go down.

6. Get outside help if you don't have dedicated cybersecurity expertise in-house.

Most water systems don't (and shouldn't have to) have the expertise in-house. A managed security partner with experience in local government and critical infrastructure environments can monitor, harden, and validate these systems continuously, instead of leaving reviews to happen only after an incident makes the news.

[Send this Technical Water Systems OT/PLC Gap Checklist to your IT team →]

How urgent is this risk for small water systems?

No one is suggesting every water system has already been compromised, and this isn't a call to panic. But recent incidents and repeated federal advisories are a clear signal that the risk is active, not theoretical — and that waiting for an incident to force the issue is itself a risk to your operations, your budget, and the public trust your district depends on.

VC3 has supported local government technology for 30+ years and works with more than 1,100 municipalities and special districts. We help them move from reactive IT support to a proactive, layered security posture built for how local government and critical infrastructure actually operate. 

If you want a practical starting point, our Water Systems Cyber Readiness Checklists — one for district leaders, one for technical teams — walk through the exact areas covered above and help you identify what needs attention first.

[Access the Water Systems Cyber Defense Resources →]

Want to talk through what this looks like in your environment? [Talk with VC3 →]

Frequently Asked Questions (FAQs)

1. What happened in the recent water system cyberattacks?

More than 30 municipal water systems in Minnesota were targeted in a coordinated cyberattack over 48 hours. Nine systems in Michigan reported similar activity. The FBI's initial alert confirmed activity across at least seven states, and as of August 11, 2026, the reported scope has grown to at least 12 states, including Georgia, South Dakota, Alabama, and New Jersey. Attackers gained access through internet-exposed operational technology (OT) devices, often protected by default credentials.

2. Was drinking water impacted or unsafe?

No contamination of drinking water has been reported. In Braham, Minnesota, operators switched to manual controls and maintained service while restoring systems. In Clayton County, Georgia, a system outage led to a boil water advisory on July 27 and 28, and the water authority is investigating whether unauthorized cyber activity contributed. 

3. How did attackers gain access to these systems?

Federal officials found that many affected systems had control equipment exposed directly to the internet and, in some cases, still using factory-default passwords. These vulnerabilities allowed attackers to access and disrupt critical operational technology.

4. Are only large water utilities at risk?

 No. Federal agencies have identified exposed control systems at utilities of all sizes, and CISA noted that the targeting spans water entities of all sizes, including organizations with mature cybersecurity programs. Braham, Minnesota, where a plant was taken offline, serves roughly 1,800 people. Small and mid-sized water districts are often targeted because they may have fewer cybersecurity resources while still providing essential public services. 

5. Why are water districts a common target for cyberattacks?

Water systems operate critical infrastructure that communities depend on every day. Attackers view them as attractive targets because service disruptions can create public concern, operational challenges, and pressure on organizations to respond quickly.

6. What is operational technology (OT)?

Operational technology (OT) refers to the systems that control physical processes, such as pumps, valves, chemical feeds, and treatment operations. Unlike traditional IT systems, many OT environments were not originally designed to be connected to the internet.

7. What is the single most important step a water district can take today?

Removing OT devices from direct internet exposure is one of the most effective ways to reduce risk. Remote access should be provided through secure methods such as VPNs, firewalls, jump hosts, or other protected gateways.

8. Does multi-factor authentication (MFA) really make a difference?

Yes. MFA requires a second form of verification beyond a password, so a stolen or guessed credential isn't enough on its own to get in. Microsoft's research credits it with blocking 99.9% of account compromise attempts, and federal guidance consistently lists it as a foundational control. It is not, however, a substitute for getting equipment off the public internet. 

9. How can water districts detect problems before service is disrupted?

Organizations should implement logging, monitoring, and alerting for unusual login attempts, unexpected commands, and configuration changes. Regularly reviewing and validating control system settings can also help identify unauthorized modifications early.

10. What if our water district doesn't have dedicated OT cybersecurity expertise?

Many water districts operate with limited IT and security resources. Working with a managed security partner experienced in municipal and critical infrastructure environments can help provide continuous monitoring, risk assessments, and security guidance tailored to water operations.

Ready to chat about your Water System security strategy? [Talk with VC3 →]

Let's talk about how VC3 can help you AIM higher.