top of page

When the Tap Becomes a Target: What the Water System Hacks Reveal About America's Weakest Defenses


Cyberattacks struck water and wastewater utilities in at least seven states in late July 2026, locking operators out of the systems that monitor and control treatment plants.
Cyberattacks struck water and wastewater utilities in at least seven states in late July 2026, locking operators out of the systems that monitor and control treatment plants.

Suspected foreign hackers breached water systems in at least seven states in late July, locking operators out of the controls that run treatment plants and pumps. No drinking water was harmed. That is not the point. The attackers proved they can reach the machinery that keeps American taps flowing, and the smallest, least defended utilities are the front line.


At 1:30 in the morning on July 27, an alert sounded at the water utility in Cape May, New Jersey, a shore town of a few thousand residents. Staff arrived within the hour expecting a power problem. What they found was an intruder. Hackers had changed the IP address of the water department's computer system and temporarily locked officials out. The same night, more than 30 water systems across Minnesota reported similar intrusions. Within days, the FBI confirmed hits on utilities in at least seven states, and news reporting suggests the true number may reach a dozen.


Last week, this blog examined the first autonomous AI cyberattacks and warned that offense now moves at machine speed. This week's story is the other half of the equation: the defenders. Many of America's community water systems are small, underfunded, and protected by a part-time IT contractor, if anyone at all. When capable adversaries meet fragile targets, the result looks like the last two weeks.


What Actually Happened

Between July 26 and July 30, attackers remotely accessed internet-connected devices that operate and monitor water facilities. The FBI, the Environmental Protection Agency, and the Cybersecurity and Infrastructure Security Agency issued a joint warning describing the playbook: hackers changed administrator passwords and IP addresses, disabled alarms, and caused utilities to lose the ability to monitor and control their own equipment. Some facilities reported pressure loss and flooding, conditions that can allow untreated groundwater to seep into pipes. In a few cases, systems had to be shut down entirely.


The FBI has so far observed the activity against one common brand of programmable logic controller, the small industrial computers that open valves and run pumps. However, a broader federal advisory warns that other major controller brands are also being targeted.


Who did it? Federal investigators suspect Iran-linked hackers, and the tactics resemble a 2023 campaign by CyberAv3ngers, a group tied to Iran's Revolutionary Guard. Nevertheless, the FBI has made no formal attribution, and officials are examining whether another state actor could be mimicking Iranian tradecraft. Treat the Iran connection as probable, not proven.

"This is, unfortunately, modern warfare at this point." - Cape May Mayor Zack Mullock

The Soft Underbelly of National Security

Why water? Because water is where national security meets Main Street. A power grid operator has a security operations center. A rural water district has a supervisor with a pickup truck and a password that may not have changed since installation. Adversaries know this. The Cape May system is a case in point: it supplies not only four municipalities but also the United States' only Coast Guard Training Center. A town utility most Americans have never heard of sits directly in the supply chain of a military installation.


Thousands of small utilities connected their pumps and controllers to the internet over the past two decades because remote access is cheap and convenient. Few gained the security staff that should come with that exposure. The attackers did not need elite tradecraft. They needed exposed devices, weak passwords, and time.


Disruption Without Destruction: The Perception War

Here is the strategic logic that leaders must grasp. The attackers did not poison anyone. In Cape May, one official described the intrusion as hackers who essentially announced themselves and left. That restraint is not mercy. It is messaging.


In my opinion, these intrusions fit a pattern I have called the perception war. Adversaries do not need to defeat the United States militarily. They need to show, visibly and repeatedly, that the state cannot protect the basics of daily life. Every headline about a hacked water plant erodes public confidence and signals what a coordinated attack could do in a real crisis. For a middle power confronting Washington, holding water systems at risk is asymmetric leverage at minimal cost.


There is also an instructive irony. Cape May escaped serious harm because most of its water plant is not automated and not online. The town was saved not by cutting-edge technology, but by the absence of it. As organizations rush to automate everything with AI agents, these attacks are a reminder that every connection is a doorway.

"Cape May was saved not by cutting-edge technology, but by the absence of it."

What Utilities and Leaders Should Do Now

Federal guidance after these attacks is clear and achievable even for small operators:

  1. Disconnect what does not need to be connected. Remove control systems from the public internet wherever possible. If remote access is essential, put it behind a VPN with multifactor authentication.

  2. Change every default password today. The 2023 water intrusions succeeded largely through factory-set credentials. This remains the cheapest fix in cybersecurity.

  3. Practice manual operations. Train staff to run pumps and valves by hand. Cape May and Woodbine recovered quickly because their people could operate without the network.

  4. Report early and lean on partners. Small utilities cannot face state-linked adversaries alone. State cybersecurity cells, CISA, and the FBI moved fast in New Jersey because officials called immediately.


The Bottom Line

The water attacks caused no casualties and contaminated no supply. Some will file them away as a near miss. That would be a mistake. Adversaries just completed a live rehearsal against the most essential and least defended infrastructure in America, and they now know where the doors are. Leaders who act on this warning will decide whether the next 1:30 a.m. alert ends in resilience or in crisis.


OSRS can help. Our team provides intelligence-driven security research, critical infrastructure threat assessments, and strategic advisory services for government, law enforcement, utilities, and private-sector leaders. Contact us to schedule a briefing or an infrastructure security readiness assessment for your organization.


Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.


About the Author

Dr. Sunday Oludare Ogunlana is the Founder and CEO of OGUN Security Research and Strategic Consulting LLC and a Professor of Cybersecurity. A national security scholar specializing in intelligence studies, counterterrorism, and emerging technology threats, he advises government, academic, and private-sector organizations on security strategy.


Intelligence. Protection. Strategy.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page