100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month

In July, more than 100 water systems were targeted with cyberattacks, according to the Cybersecurity & Infrastructure Security Agency (CISA).
This news follows a recent wave of cyber incidents against water and wastewater facilities across the United States, including the confirmed attacks against Alabama, Minnesota, Michigan, New Jersey, South Dakota, and Georgia. However, it now appears that at least 12 states were impacted.
While the cyberattacks did not result in significant disruption, this targeted wave of incidents has generated concern for the security of the water sector.
Security Leaders Weigh In
Matt Hartman, Chief Strategy Officer at Merlin Group:
The fact that more than 100 internet-exposed water systems were targeted in a single month underscores that this is a systemic risk, not a series of isolated incidents. Water utilities often rely on operational technology that was never designed to be directly exposed to the internet, while attackers are also looking for weaknesses across the vendors that support these environments. The priority now should be exactly what CISA is emphasizing: identify internet-exposed assets, remove unnecessary exposure, change default credentials, patch supported systems, secure required remote access with controls like MFA, and continuously monitor for anomalous activity.
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint:
Recent incidents have exposed risks that have existed across critical infrastructure for years: internet-facing controllers, weak segmentation, legacy systems, third-party access, and limited visibility into operational technology. Recent attacks on U.S. water systems have exploited those same conditions, sometimes forcing operators to switch to manual processes.
AI expands existing attack paths by helping adversaries identify exposed assets, generate exploit code, chain vulnerabilities, and operate at greater speed and scale. The underlying weaknesses are poor security hygiene and years of uneven investment. Operators need to reduce direct internet exposure, enforce least-privilege access, monitor changes to controller logic, maintain offline configuration backups, and build incident response plans around physical operations. AI increases the urgency, but the vulnerabilities were already there.
It’s also important to note that regulations like DORA (Digital Operational Resilience Act) and NIS2 (Network and Information Security Directive 2) fundamentally shift cybersecurity from an organization-centric model to an ecosystem and supply chain model. This is especially important as critical infrastructure operators increasingly depend on AI systems, cloud providers, software dependencies, data providers, and third-party AI vendors.
John Gallagher, Vice President at Viakoo:
Malicious hackers and nation-state adversaries will often run live stress-tests against operators of critical infrastructure to test their defenses. AI makes these attacks faster and easier to launch, increasing the frequency of such attacks.
The increased volume and velocity of attacks means that passive advisory memos and slow cyber hygiene methods just won’t work anymore (if they ever did). What is needed is active, ongoing, and automated cyber hygiene of critical infrastructure systems to prevent the initial intrusions from being successful.
Many countries, such as the U.K. and the U.S., rely on distributed and heterogeneous forms of public utilities. Successful attacks on small or rural utilities does not translate into a broad threat to the public. However, these “warning shots” being fired by adversaries need to be taken seriously and more funding allocated to act on weak cyber defenses. Adversaries will always have an upper hand because of speed when cyber defense relies on bureaucratic budget cycles and multi-year legislative processes.
Louis Eichenbaum, Federal CTO at ColorTokens:
Many of these Operational Technology (OT) systems were never designed with cybersecurity in mind. They were built for reliability and availability, not to withstand modern nation-state cyber threats. Unfortunately, many remain internet-facing, poorly segmented, and inadequately monitored.
This is exactly why the cybersecurity conversation must move beyond prevention alone. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale.
Granular microsegmentation and zero trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack, but to ensure that a localized intrusion does not become a catastrophic operational event.
David Brumley, Chief AI and Science Officer at Bugcrowd:
Targets like these are attractive because they don’t have the right resources. That makes them both more vulnerable, and slower to respond to successful hacks. Many of the attacks start out simply to score political points, where Iran and other adversaries want to embarrass the U.S. The scary part is what happens afterwards, where an attacker may end up inside critical infrastructure.
Christopher Hills, Chief Security Strategist at BeyondTrust:
For many years, OT has prioritized uptime over security and threat actors know this, which is why they continue to compromise these OT environments in the way they do. We have seen this same type of attack with the Aliquippa Water Plant, where threat actors targeted the PLC that was broadcasting Modbus (Port 502) on the public internet. They leveraged this as their foothold into their PLC and then pivoted to the Human Machine Interface (HMI) which had default credentials that were never changed, and used this to install a lightweight web shell for persistence, ultimately defacing the HMI screen and attempting to shut down the pumps and disrupt water pressure. These types of legacy systems do not use modern technology or security to secure.
However, one thing remains: foundational security practices do not need modern security to take basics steps in security. Default admin and passwords are considered foundation security practices. Ensuring they are either turned off, managed, or at a minimum, rotated from their default/shipped state. This is where many organizations, including IT, tend to forget about the basics when it comes to foundational security. And in most IT environments, you have additional layers of security that typically help layer some of this access, which makes it harder in most IT environments. Unfortunately, this is not the case in OT. OT does not have these additional security layers to help protect them and are therefore vulnerable right from the start. This is why you see NIST creating a special project/team to address critical infrastructure and OT, because they know this is a weakness across all OT environments.
Understanding the convergence between IT and OT is so critical and Zero Trust Architecture excels in OT. Because OT environments cannot leverage modern security controls, it is imperative that these environments embrace Zero Trust architecture to create a security boundary from access both from the public web and internal access. This is a step in the right direction to create a buffer and gate any inbound and outbound access due to an OT environments lack of security controls. Obviously ensuring default login and passwords should already be a layer and managed or rotated, and any public facing, direct access should be turned off.
Threat actors already know our weakest infrastructure is our critical infrastructure, whether it be in our utilities sector or other OT. If we do not find a way to modernize these legacy systems, put modern security controls in place, and guard them against attacks, we will continue to suffer and see breaches and compromises across OT environments.
Jim Richberg, Head of Cyber Policy and Global Field CISO at Fortinet:
The ongoing targeting and successful exploitation of water systems is shining a light on a longstanding problem in the security of (especially) the small water/wastewater utilities that comprise 81% of all U.S. public water systems. Theses utilities account for 93% of violations for noncompliance with federal drinking water standards.
Setting requirements is part of the answer, but it needs to be matched with providing resources — which can ‘parachuted’ in from the state or Federal level but ultimately need to be built into utility rates (often set and approved by someone other than the utility) to be sustainable. And there are volunteers pitching in to help the sector, such as DEF CON Franklin. Many of these small utilities lack the expertise to address the problem on their own, so they need to rely on external expertise, both paid and pro bono.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







