2026 U.S. Water System Cyberattacks: 3 Lessons for Critical Infrastructure

water treatment facility

2026 U.S. Water System Cyberattacks: 3 Lessons for Critical Infrastructure

U.S. critical infrastructure cybersecurity made national and global headlines in July 2026 for the wrong reasons. Cyber actors targeted U.S. water facilities across multiple states in what became one of the broadest coordinated campaigns against the sector in recent years. U.S. officials were investigating possible links to Iranian threat actors, although the attacks had not been definitively attributed. 

So, what happened, and what lessons can we take away about cyber resilience in critical infrastructure?

U.S. Water System Cyberattacks: What Happened

The campaign came to light in late July 2026 after more than 30 community water systems in Minnesota were targeted in what state officials described as a coordinated cyberattack. According to the FBI, incidents were reported across at least seven states. Subsequent reporting indicated that facilities in at least a dozen states were ultimately affected.

The attacks prompted CISA to warn of increased activity targeting programmable logic controllers (PLCs), the industrial devices responsible for automating and controlling functions such as pumps, valves, and water treatment processes.

The threat actors changed PLC passwords and network settings, including IP addresses, preventing operators from remotely accessing and managing their own equipment. Some utilities reported flooding and reductions in water pressure following the intrusions. While there was no evidence that drinking water quality had been compromised, some communities issued precautionary boil notices.

CISA and the FBI urged critical infrastructure owners to remove publicly accessible PLCs and other OT assets from direct internet exposure and route necessary remote access through secure gateways.

The incidents underscore a fundamental point about resilience: Preventing well-known attack paths matters just as much as improving the response when an attack succeeds.

Lesson 1: The Lag Between Guidance and Action Is Unsustainable

One alarming detail was that some of the compromised control systems were reportedly still using default passwords. On its own, that's concerning. Viewed alongside years of government guidance, it points to a deeper problem.

In May 2024, more than two years before these attacks, the U.S. Environmental Protection Agency (EPA), CISA, and the FBI urged water utilities to take basic cybersecurity steps, including changing default passwords and reducing the exposure of operational technology to the public internet. EPA inspectors also reported finding drinking water systems that continued to rely on shared staff logins, failed to change default passwords, and had not addressed other fundamental security weaknesses.

The uncomfortable question is why known risks can remain unaddressed years after regulators identify them.

Part of the answer lies in the realities of the sector. Many community water utilities operate with small teams, aging SCADA environments, and limited cybersecurity expertise. Equipment may remain in service for decades, often with remote access solutions bolted on over time to simplify maintenance rather than designed around modern security principles.

Those challenges are real, but they don't change the underlying risk. The longer organizations take to close well-understood security gaps, the more those weaknesses evolve from theoretical risks into predictable attack paths. These attacks highlighted an unsustainable lag between identifying cyber risk and reducing it.

Reducing that lag means treating fundamental controls such as changing default credentials, securing remote access, and restricting internet exposure to OT as operational priorities rather than long-term improvement projects.

Lesson 2: Cybersecurity Competes With Every Other Form of Infrastructure Resilience

For many community water utilities, cybersecurity investments compete with replacing aging pumps, repairing leaking pipes, modernizing treatment equipment, and preparing for extreme weather. Every investment contributes to operational resilience, but limited budgets make it impossible to fund every priority.

The challenge is particularly acute for smaller systems. Many operate with only a handful of employees responsible for maintaining infrastructure, meeting regulatory requirements, responding to operational issues, and managing technology. Because many systems are owned by local governments or special districts, cybersecurity funding may also compete with broader public priorities such as schools, roads, and emergency services. Many utilities therefore rely on state agencies, industry associations, and external partners to help bridge cybersecurity capability gaps. 

Critical infrastructure operators will always face competing demands. The more important question is how limited cybersecurity resources can deliver the greatest reduction in operational risk.

That means prioritizing high-impact improvements like securing remote access, removing unnecessary internet exposure, strengthening identity controls, and validating incident response and recovery procedures rather than attempting to address every weakness at once.

Resilience isn't about eliminating every possible risk. It's about knowing which risks could have the greatest operational impact, reducing them, and testing whether the organization can respond when defenses fail.

Lesson 3: Fragmentation Complicates Critical Infrastructure Cyber Resilience

When discussions turn to the cybersecurity of critical infrastructure, it's easy to picture a coordinated system protected by consistent security standards. The reality is very different.

According to the U.S. Environmental Protection Agency, there are more than 148,000 public water systems in the United States, including around 50,000 community water systems that provide drinking water year-round. Each has its own governance, budget, technology stack, operational priorities, and level of cybersecurity maturity.

That fragmentation creates a significant resilience challenge. Larger utilities may have dedicated cybersecurity personnel, segmented OT networks, and established incident response plans. Smaller rural operators may rely on a handful of staff responsible for everything from pumps and treatment equipment to IT and regulatory compliance.

These differences help explain why raising the security baseline across the sector is so difficult. Guidance and best practices may apply broadly, but implementation happens locally. Every utility progresses at its own pace based on its resources, infrastructure, staffing, and competing priorities. 

From an attacker's perspective, those differences create opportunity. Attackers don't need every water utility to have weak cybersecurity. They only need enough vulnerable systems to find opportunities to attack.

Improving resilience therefore requires more than expecting every utility to solve the problem independently. Stronger security baselines, greater investment in modernization, and easier access to specialist cybersecurity expertise can help narrow the gap between large and small operators. Just as importantly, organizations can regularly test incident response capabilities and validate that critical controls work when they're needed.

Cyber Resilience Must Be Proven, Not Assumed

Cyber resilience is built long before an incident begins. Acting more quickly on security guidance, securing operational technology, and prioritizing investments where resources are limited all contribute to a stronger defensive posture.

But resilience also depends on confidence that people, processes, and technologies will perform when an attack actually unfolds.

In its response to the July attacks, the FBI specifically recommended that critical infrastructure organizations practice and maintain the ability to operate OT systems manually. It also called for business continuity and disaster recovery plans, fail-safe mechanisms, backups, and standby systems to be routinely tested.

Knowing how an organization will perform during an attack requires more than policies or architecture diagrams. It requires testing teams against realistic attacks, validating incident response and recovery procedures, and identifying weaknesses before adversaries do.

Cloud Range helps critical infrastructure organizations build and prove that capability across converged IT and OT environments. Through live-fire simulations, organizations can test detection and response, validate procedures, and measure how their teams perform before a real attack puts them to the test.

Learn how Cloud Range helps critical infrastructure organizations strengthen and prove cyber readiness.

Next
Next

4 Ransomware Trends Security Leaders Should Watch in 2026