loading min read

Cyberattacks have reached the waterline: What utilities should do now

Water utilities face rising cyber threats. Learn practical steps to strengthen resilience and protect critical operations.

Recent cyberattacks on municipal water systems show that even limited access to operational technology can disrupt essential services, making cyber resilience an urgent priority for utilities and local governments. Learn what measures can help your organization secure remote access, maintain critical operations, and recover confidently from an attack.

The current threat landscape

The most important lesson from the recent attacks is that adversaries do not need to “hack the whole city” to create operational stress. In the July 2026 water-sector campaign, federal agencies said malicious actors remotely accessed internet-facing Programmable Logic Controller (PLCs), changed IP addresses and passwords, and caused loss of monitoring and control functionality; operational effects reported to the FBI included loss of pressure and flooding. CISA’s July 2026 alert urged utilities to remove publicly exposed PLCs and other operational technology (OT) from the internet, noting that attackers were targeting water entities of all sizes and that undocumented cellular modems installed by operators, vendors, or integrators may not appear in routine scans.

Recent incidents show the pattern clearly. Minnesota confirmed a coordinated cyberattack against operational technology at more than 30 community water systems and activated a statewide response with CISA, EPA, FBI, state agencies, and local utilities; Minnesota officials said public health remained protected and they were not aware of active requests for residents to modify drinking-water use. New Jersey reported two municipal water utilities forced temporarily into manual mode after attacks disrupted automated controls and limited remote monitoring, with service uninterrupted and security strengthened afterward. Michigan officials said nine water systems were targeted, but systems continued operating safely and there were no known public-health impacts.

The attack path reflects the official pattern described by FBI, EPA, and CISA: exposed remote access or PLCs, weak or unmanaged access controls, loss of monitoring/control, and operational fallback to manual procedures.

Why municipal water and local infrastructure are attractive targets

Water is a lifeline service. CISA notes that Americans rely on safe drinking water and wastewater treatment every hour of every day, and that the sector supports other critical infrastructure and the national economy. EPA has warned that cyberattacks on drinking water and wastewater systems can disrupt treatment, introduce contaminants, damage equipment, and erode public trust; EPA also stated in April 2026 that the water sector remains an attractive target for groups seeking to disrupt U.S. critical infrastructure.

Municipal environments are also unusually exposed because they combine essential physical operations with legacy systems, remote maintenance needs, small teams, and constrained budgets. In 2024, EPA inspections found that over 70% of inspected water systems did not fully comply with Safe Drinking Water Act requirements, and some had critical cybersecurity weaknesses such as unchanged default passwords and lack of multifactor authentication (MFA) that could be compromised. That is why the highest-return defenses are often basic, procedural, and operational – not expensive platforms. EPA has said many improvements for water systems with limited technical resources are procedural rather than dependent on costly hardware or software upgrades.

Context from the last two years: water is the priority, but municipal risk is broader

The water-sector incidents sit within a broader wave of attacks on local government and municipally managed services

    • Arkansas City, KS: In September 2024, the town reported a cyber incident at its water treatment plant, switched to manual operations, and said the water supply remained safe and service was not disrupted.
    • Wichita, KS: A 2024 cyber incident impaired water metering, billing, and payment processing, while also affecting libraries, airport information displays, and municipal court services.
    • Columbus, OH: The city disclosed in July 2024 that a foreign cyber threat actor attempted to disrupt city IT infrastructure in a possible ransomware effort, prompting the city to sever internet connectivity while 911 and 311 remained operational.
    • St. Paul, MN: The city reported a 2025 cyber incident involving compromised accounts tied to a critical backup server, a citywide network shutdown, refusal to pay ransom, and exposure of about 43 GB of data involving 12,484 individuals.

The message for leaders is straightforward: water utilities are part of a municipal operating ecosystem. A water plant may be the headline, but billing systems, customer portals, emergency communications, public works, finance, procurement, and vendor access can become operational chokepoints.

Lessons learned for utility and business leaders

First, manual operations are a resilience capability, not an afterthought. The FBI and EPA explicitly recommend practicing and maintaining the ability to operate OT systems manually, including tested business continuity, disaster recovery, fail-safe mechanisms, backups, and standby systems. The recent incidents all reinforce the value of being able to continue service while automated systems are isolated or restored.

Second, the “unknown remote connection” is now a board-level risk. CISA warned that cellular modems installed by operators, vendors, or system integrators may not be documented or included in routine attack-surface scans, and federal agencies have repeatedly urged utilities to remove PLCs from direct internet exposure. This is a governance issue as much as a technical issue: leaders should know who has remote access, why it exists, how it is authenticated, and how quickly it can be disabled.

Third, attribution matters less than readiness. Federal reporting and advisories point to Iranian-affiliated actors targeting internet-connected OT across critical infrastructure, including government services, local municipalities, water and wastewater, and energy, but public reporting on the July 2026 multistate wave has repeatedly noted that formal attribution for those specific incidents was not publicly confirmed. Municipalities should prepare for nation-state, criminal, and opportunistic activity alike.

A practical, budget-conscious action plan

Whether you are critical infrastructure like a municipal water system or a small business, managing cyber risks starts the same:

    • 1. Reduce your online attack surface. Taking public-facing OT off the internet is the fastest risk reducer. Identify internet-exposed PLCs, HMIs, remote terminal units, cellular modems, and vendor remote-access paths, then place them behind a secure gateway, firewall, VPN, or equivalent controlled access point. CISA’s guidance is explicit: remote access should go through a VPN or gateway, not directly to the PLC.
    • 2. Fix identity basics before buying tools. Change default passwords, require unique credentials, remove shared accounts where possible, and apply MFA to remote access into OT networks; CISA, EPA, and FBI list default-password changes, MFA, strong passwords, and access controls among core water-sector actions. For small utilities, this is often the lowest-cost path to immediate risk reduction.
    • 3. Inventory IT assets, including vendor-maintained equipment. CISA, EPA, and FBI recommend inventories of IT assets (including OT assets), and CISA specifically warns that undocumented cellular modems and integrator-installed connections may be missed by routine scans. Leaders should require a simple asset list that includes owner, location, vendor, remote-access method, last patch or maintenance date, and whether the device is internet reachable.
    • 4. Segment, allow list, and monitor the operational boundary. Federal guidance recommends firewall rules or access control lists that allow only authorized communication between expected control-system devices, as well as logging and monitoring for unusual access or configuration changes. The goal is not perfection; it is to make it harder for a compromised city workstation, vendor laptop, or exposed modem to become a pathway to pumps and valves.
    • 5. Build recovery around clean backups and manual operating procedures. CISA recommends known clean PLC backups after disconnecting PLCs from the internet, and the FBI/EPA recommend reviewing PLC project files for unauthorized changes before restoring backups. Municipal leaders should treat PLC logic, Supervisory Control and Data Acquisition (SCADA) configurations, network diagrams, and manual runbooks as critical recovery assets.
    • 6. Exercise the incident response plan with executives, operators, IT, legal, communications, and public works. CISA, EPA, and FBI recommend developing and exercising cybersecurity incident response and recovery plans, while the recent Minnesota response shows the value of coordinated state, federal, local, tribal, and private-sector partnerships during a water-sector incident. The exercise should include practical questions: Who can authorize manual operations? Who calls CISA/FBI/EPA? Who speaks to the public? Who disables vendor access? Who validates water safety messaging?
    • 7. Bonus for critical infrastructure: Use free federal resources aggressively. CISA and EPA provide a water-sector toolkit with low- or no-cost cyber hygiene steps, no-cost vulnerability scanning for water utilities, EPA’s 24/7 Water Resilience Cybersecurity Help Desk, EPA no-cost cybersecurity assessments, and funding resources including the Clean Water State Revolving Fund, Drinking Water State Revolving Fund, and the State and Local Cybersecurity Grant Program. These resources are particularly important for communities that cannot fund a full-time OT security team.

Closing thought

Municipal cybersecurity has entered its operational era. For water utilities and local governments, the benchmark is no longer whether every attack can be prevented; it is whether the community can continue receiving safe service, restore systems from trusted backups, communicate confidently, and learn quickly. The municipalities that perform best will not necessarily be those with the largest budgets – they will be those that know their exposed assets, control remote access, practice manual operations, and treat cyber resilience as a core public-service obligation.

INSIGHTS
Discover More Assets

Related services

Our solutions are tailored to each client’s strategic business drivers, technologies, corporate structure, and culture.

Receive CohnReznick insights and event invitations on topics relevant to your business and role.
Subscribe
Any advice contained in this communication, including attachments and enclosures, is not intended as a thorough, in-depth analysis of specific issues. Nor is it sufficient to avoid tax-related penalties. This has been prepared for information purposes and general guidance only and does not constitute legal or professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice specific to, among other things, your individual facts, circumstances and jurisdiction. No representation or warranty (express or implied) is made as to the accuracy or completeness of the information contained in this publication, and CohnReznick, its partners, employees and agents accept no liability, and disclaim all responsibility, for the consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it.

"CohnReznick" is the brand name under which CohnReznick LLP and CohnReznick Advisory LLC and their respective subsidiaries provide professional services. CohnReznick LLP and CohnReznick Advisory LLC (and their respective subsidiaries) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CohnReznick LLP is a licensed CPA firm that provides attest services to its clients. CohnReznick Advisory LLC provides tax and business consulting services to its clients. CohnReznick Advisory LLC and its subsidiaries are not licensed CPA firms.

member of nexia

CohnReznick is a member of Nexia, a leading, global network of independent accounting and consulting firms. Please see the “Member firm disclaimer (Opens a new window)” for further details.

© 2026 CohnReznick Advisory LLC, All Rights Reserved.