In today’s bulletin, Charlie gives an insight into the recent cyber incidents targeting water companies in the US, and advises on how water companies can strengthen their systems.
I have been on holiday for the last couple of weeks, but I have followed these attacks with interest. Having worked in the water industry for eight years, I have a particular interest in any incident which impacts the industry, especially incidents which are new and did not take place when I was responsible for emergency planning.
What happened?
Over the last week of July 2026, there were a number of reports of cyber attacks across several states in the USA. Water and wastewater utilities across at least 12 US states were affected, with more than 30 community water systems targeted in Minnesota and further incidents reported in Georgia, Michigan, New Jersey, and South Dakota. The attacks affected systems used to monitor and control water infrastructure, temporarily limiting the ability of some operators to manage equipment remotely. Reported impacts included reduced water pressure and temporary disruption to water services. Some communities were asked to conserve water, while precautionary ‘boil water’ notices were issued in parts of Georgia following a drop in pressure. Several utilities switched to manual operations while the incidents were investigated and services restored. Water quality testing was subsequently completed, and there were no confirmed reports of drinking water contamination.
Who did it
US officials and a number of cybersecurity researchers suspect that Iranian-linked hackers were responsible for the attacks, although this has not been officially confirmed. A group called the CyberAv3ngers, linked to Iran’s Islamic Revolutionary Guard Corps, was named as the group which conducted similar attacks on utilities in 2023, and a separate group called APT Iran also claimed involvement in the Minnesota attacks and said it had worked with CyberAv3ngers, although this claim was also not officially confirmed. The FBI, who are investigating the incidents, did not attribute the attacks to Iran or to a particular group in its public advisory. President Trump offered a very different assessment: “I would blame it on Minnesota and the governor (Tim Walz – a Democrat), the corrupt governor of Minnesota … Iran’s got bigger problems than worrying about Minnesota.” He perhaps does not want to publicise any further consequences of the Iran USA conflict.
What needs to be done to improve security
Many of the USA water companies are small community systems, and many have control systems which were built before the internet and use to control and operate their water systems. The internet is now used as the network conduit to control these systems, which often consist of multiple water production plants, water purification systems, water storage tanks, and a widespread distribution system which pumps water into the industry and people’s homes.
The system has a control room operator who monitors and supervises the overall system through the SCADA system. PLCs control individual elements of the process, such as pumps, valves, and other equipment. Most water systems operate automatically according to programmed logic and preset parameters, with the control room operator intervening when something goes wrong, equipment fails, or operating conditions need to be changed. Most water systems operate automatically and require intervention from the control room when something goes wrong, a piece of machinery breaks down, or equipment goes offline. Each of the SCADA systems and PLCs operates to preset parameters, but these can be changed remotely or, if necessary, the equipment can be operated manually.
The control systems were designed before the internet and were therefore built with functionality as the main driver rather than security. Companies originally operated their own wired or radio networks to connect devices. These have now often been replaced by internet and cellular communications. What has not always caught up is the security of these networks, and this has allowed hackers to penetrate them relatively easily. Figure 1 gives an overview of the configuration of the network.

The FBI and the Environmental Protection Agency (EPA) issued a Public Service Announcement outlining some of the issues which need to be addressed by critical infrastructure asset owners. These include:
- Disconnect PLCs from the public facing internet. Remove inbound port exposure, so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled.
- Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable.
- Only allow trusted devices and systems to connect to the PLCs. Keep PLCs in run mode when they are not being updated. Make sure the organisation can operate the OT system manually if the technology fails or is attacked. Regularly test manual controls, backups, standby systems, and recovery arrangements.
- Regularly check PLC programs and connected devices for unauthorised changes.
- Replace old equipment that is no longer supported.
Comment
To me, as someone who is not a technical cyber specialist, these are very much basic security precautions which any organisation running internet connected infrastructure should be carrying out. It shows that many utilities still have a long way to go before they can be considered basically secure.
The attacks on these water installations have some common features with the attack by the Russians on Polish renewable energy infrastructure in December 2025, which was described in a previous bulletin. The attacker targets SCADA and PLC controllers and either wipes them, changes the parameters, changes the password, or reconfigures them in such a way that they are no longer viable or able to be controlled over the network.
The ‘boil water’ notice issued by one company resulted from the impact of the attack lowering water pressure. Low pressure can potentially allow water surrounding a pipe to enter it, leading to contamination. Therefore, the need to boil the water was an indirect consequence of the loss of pressure, rather than the result of a direct attack by the hackers on water quality. This may be a feature of subsequent attacks, where the impact arises from an indirect consequence of the cyber attack, rather than from the attacker’s original intention.
The new legislation currently before the UK Parliament is the Cyber Security and Resilience (Network and Information Systems) Bill, which builds on the 2018 NIS Regulations and will place additional requirements on critical national infrastructure and on the relevant MSP companies which support them. This Bill will hopefully increase the resilience of our utilities and make them less vulnerable to future attacks.



