Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity NewsInfrastructure:Electric,Gas & Water

100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month

By Jordyn Alger, Managing Editor
Water from a faucet
SHTTEFAN via Unsplash
August 26, 2026

In July, more than 100 water systems were targeted with cyberattacks, according to the Cybersecurity & Infrastructure Security Agency (CISA). 

This news follows a recent wave of cyber incidents against water and wastewater facilities across the United States, including the confirmed attacks against Alabama, Minnesota, Michigan, New Jersey, South Dakota, and Georgia. However, it now appears that at least 12 states were impacted. 

While the cyberattacks did not result in significant disruption, this targeted wave of incidents has generated concern for the security of the water sector. 

Security Leaders Weigh In

Matt Hartman, Chief Strategy Officer at Merlin Group:

The fact that more than 100 internet-exposed water systems were targeted in a single month underscores that this is a systemic risk, not a series of isolated incidents. Water utilities often rely on operational technology that was never designed to be directly exposed to the internet, while attackers are also looking for weaknesses across the vendors that support these environments. The priority now should be exactly what CISA is emphasizing: identify internet-exposed assets, remove unnecessary exposure, change default credentials, patch supported systems, secure required remote access with controls like MFA, and continuously monitor for anomalous activity.

Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint:

Recent incidents have exposed risks that have existed across critical infrastructure for years: internet-facing controllers, weak segmentation, legacy systems, third-party access, and limited visibility into operational technology. Recent attacks on U.S. water systems have exploited those same conditions, sometimes forcing operators to switch to manual processes.  

AI expands existing attack paths by helping adversaries identify exposed assets, generate exploit code, chain vulnerabilities, and operate at greater speed and scale. The underlying weaknesses are poor security hygiene and years of uneven investment. Operators need to reduce direct internet exposure, enforce least-privilege access, monitor changes to controller logic, maintain offline configuration backups, and build incident response plans around physical operations. AI increases the urgency, but the vulnerabilities were already there. 

It’s also important to note that regulations like DORA (Digital Operational Resilience Act) and NIS2 (Network and Information Security Directive 2) fundamentally shift cybersecurity from an organization-centric model to an ecosystem and supply chain model. This is especially important as critical infrastructure operators increasingly depend on AI systems, cloud providers, software dependencies, data providers, and third-party AI vendors.

John Gallagher, Vice President at Viakoo:

Malicious hackers and nation-state adversaries will often run live stress-tests against operators of critical infrastructure to test their defenses. AI makes these attacks faster and easier to launch, increasing the frequency of such attacks. 

The increased volume and velocity of attacks means that passive advisory memos and slow cyber hygiene methods just won’t work anymore (if they ever did). What is needed is active, ongoing, and automated cyber hygiene of critical infrastructure systems to prevent the initial intrusions from being successful.  

Many countries, such as the U.K. and the U.S., rely on distributed and heterogeneous forms of public utilities. Successful attacks on small or rural utilities does not translate into a broad threat to the public. However, these “warning shots” being fired by adversaries need to be taken seriously and more funding allocated to act on weak cyber defenses. Adversaries will always have an upper hand because of speed when cyber defense relies on bureaucratic budget cycles and multi-year legislative processes.  

Louis Eichenbaum, Federal CTO at ColorTokens:

Many of these Operational Technology (OT) systems were never designed with cybersecurity in mind. They were built for reliability and availability, not to withstand modern nation-state cyber threats. Unfortunately, many remain internet-facing, poorly segmented, and inadequately monitored.

This is exactly why the cybersecurity conversation must move beyond prevention alone. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale.

Granular microsegmentation and zero trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack, but to ensure that a localized intrusion does not become a catastrophic operational event.

David Brumley, Chief AI and Science Officer at Bugcrowd:

Targets like these are attractive because they don’t have the right resources. That makes them both more vulnerable, and slower to respond to successful hacks. Many of the attacks start out simply to score political points, where Iran and other adversaries want to embarrass the U.S. The scary part is what happens afterwards, where an attacker may end up inside critical infrastructure.

Christopher Hills, Chief Security Strategist at BeyondTrust:

For many years, OT has prioritized uptime over security and threat actors know this, which is why they continue to compromise these OT environments in the way they do. We have seen this same type of attack with the Aliquippa Water Plant, where threat actors targeted the PLC that was broadcasting Modbus (Port 502) on the public internet. They leveraged this as their foothold into their PLC and then pivoted to the Human Machine Interface (HMI) which had default credentials that were never changed, and used this to install a lightweight web shell for persistence, ultimately defacing the HMI screen and attempting to shut down the pumps and disrupt water pressure. These types of legacy systems do not use modern technology or security to secure. 

However, one thing remains: foundational security practices do not need modern security to take basics steps in security. Default admin and passwords are considered foundation security practices. Ensuring they are either turned off, managed, or at a minimum, rotated from their default/shipped state. This is where many organizations, including IT, tend to forget about the basics when it comes to foundational security. And in most IT environments, you have additional layers of security that typically help layer some of this access, which makes it harder in most IT environments. Unfortunately, this is not the case in OT. OT does not have these additional security layers to help protect them and are therefore vulnerable right from the start. This is why you see NIST creating a special project/team to address critical infrastructure and OT, because they know this is a weakness across all OT environments. 

Understanding the convergence between IT and OT is so critical and Zero Trust Architecture excels in OT. Because OT environments cannot leverage modern security controls, it is imperative that these environments embrace Zero Trust architecture to create a security boundary from access both from the public web and internal access. This is a step in the right direction to create a buffer and gate any inbound and outbound access due to an OT environments lack of security controls. Obviously ensuring default login and passwords should already be a layer and managed or rotated, and any public facing, direct access should be turned off. 

Threat actors already know our weakest infrastructure is our critical infrastructure, whether it be in our utilities sector or other OT. If we do not find a way to modernize these legacy systems, put modern security controls in place, and guard them against attacks, we will continue to suffer and see breaches and compromises across OT environments.

Jim Richberg, Head of Cyber Policy and Global Field CISO at Fortinet:

The ongoing targeting and successful exploitation of water systems is shining a light on a longstanding problem in the security of (especially) the small water/wastewater utilities that comprise 81% of all U.S. public water systems. Theses utilities account for 93% of violations for noncompliance with federal drinking water standards.

Setting requirements is part of the answer, but it needs to be matched with providing resources — which can ‘parachuted’ in from the state or Federal level but ultimately need to be built into utility rates (often set and approved by someone other than the utility) to be sustainable. And there are volunteers pitching in to help the sector, such as DEF CON Franklin. Many of these small utilities lack the expertise to address the problem on their own, so they need to rely on external expertise, both paid and pro bono.

KEYWORDS: critical infrastructure critical infrastructure cybersecurity cyberattack operational resilience operational security water water utilties security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Blurry photo of people moving through the mall

Violence Remains Top Concern for Retailers

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Events

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Three Key Learnings for CEOs from Last Month's ASUS Hack

    See More
  • TSA Will Discuss Security Protocols After Security Breach Last Month

    See More
  • Card in ATM

    Two-thirds of financial institutions faced cyberattacks in 2024

    See More

Related Products

See More Products
  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

  • SSCP.jpg

    SSCP Systems Security Certified Practitioner Practice Exams

  • 9781498767118.jpg

    Intelligent Video Surveillance Systems: An Algorithmic Approach

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing