Secretus logo

US Water Systems Cyberattacks: What Defenders Know

·7 min read

Cyberattacks against US water infrastructure expanded across multiple states during the weekend of 1–2 August 2026. Michigan reported malicious activity affecting nine water systems after Minnesota confirmed attacks involving operational technology at more than 30 systems. The FBI is investigating. Officials said the affected Michigan systems continued to operate safely and reported no known public health impact.

The event is serious because it reached systems used to monitor or control physical processes, but the public evidence does not support claims of poisoned water or a nationwide shutdown. One Minnesota community, Braham, temporarily relied on stored water after attackers shut down operating controls for its well and treatment plant; officials said water quality was not affected. Plymouth also restored water infrastructure communications after an attack.

What is confirmed

  • More than 30 Minnesota water systems had malicious activity involving their technology, according to state officials.
  • Michigan later reported nine affected systems and said operators addressed the issues without a known public-health impact.
  • The activity involved operational technology used to remotely monitor or control equipment; being counted as affected does not mean every utility lost water service.
  • The FBI and federal partners are investigating, and no culprit has been publicly identified by the FBI.

Attribution needs the same discipline as impact assessment. Federal agencies had already warned that Iran-affiliated actors were exploiting internet-connected programmable logic controllers across critical infrastructure. That warning makes the current activity relevant to defenders, but it does not by itself prove who conducted every intrusion reported in Minnesota or Michigan.

Why internet-exposed OT changes the risk

A conventional IT breach can expose files and accounts. An OT compromise can also alter a pump, sensor, human-machine interface or treatment process. Safety engineering and operator intervention can limit the outcome, but they should not be treated as a substitute for access control. A remote-management interface with a default password is still an internet-facing production control.

The EPA says observed activity against critical infrastructure has included configuration wiping, software-based mechanical sensor tampering and disruption of human-machine interfaces. The agency's inspection findings have repeatedly identified basic gaps such as default passwords, shared logins and access that remains active after an employee leaves. Those are fixable identity and exposure problems, even for utilities without a large security team.

Priority actions for water and OT operators

  1. Remove direct internet exposure. Inventory PLCs, HMIs, engineering workstations and remote-access gateways. Place remote access behind a managed, monitored control point rather than exposing device interfaces directly.
  2. Replace defaults and shared accounts. Use unique credentials, MFA where supported and named operator accounts. Disable stale vendor and former-employee access.
  3. Separate IT from OT. Restrict traffic between business networks and control networks with explicit allow rules. Do not let a compromised email or office account become an unrestricted route to plant controls.
  4. Preserve a known-good state. Keep offline backups of PLC logic, HMI projects, device configuration and the documentation needed for manual operation and recovery.
  5. Detect changes, not only malware. Alert on remote logins, firmware changes, controller-mode changes, unexpected writes, new accounts and configuration exports.
  6. Exercise safe operations. Test how operators isolate remote access, switch to manual control, validate water quality and communicate with authorities without making the physical process less safe.

What other organisations should learn

The lesson extends beyond water. Building controls, laboratory equipment, warehouse systems, cameras and industrial gateways often sit in the same blind spot: they are networked enough to be reached but not managed like ordinary endpoints. Security teams should know who owns each device, which external party can connect, what a malicious command could change and how the organisation would continue safely if the network disappeared.

The weekend's reports are a reminder that cyber resilience is not only about keeping data confidential. For critical infrastructure, the essential outcomes are safe operation, trustworthy process data and a rehearsed route back to a known-good state.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus