The Password Problem Putting America’s Drinking Water at Risk

Hackers have targeted water facilities in at least 12 states, and federal investigators warn that similar third-party network setups may let them repeat successful attacks.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

When hackers break into a water plant, the consequences can flow straight to your faucet. They can lock operators out, cut water pressure, flood facilities, and potentially allow untreated groundwater to seep into pipes.

Water and wastewater facilities in at least 12 states have reportedly been targeted in a hacking campaign that began in late July. New Jersey and Alabama are the latest states to confirm attacks, joining Minnesota, Michigan, South Dakota, and Georgia.[1]

Officials have reported limited disruptions and said the affected communities’ drinking water remained safe. But the FBI has identified a weakness that could allow the campaign to spread: similar network configurations installed by third-party vendors may give hackers a repeatable way into multiple facilities.

In this article
The nationwide attack blueprint
Thousands of devices are still exposed
Cyberattacks on tap
What residents should watch for

The nationwide attack blueprint

Modern water systems rely on programmable logic controllers, or PLCs, to monitor and operate equipment such as pumps, valves, and treatment systems. They are essentially specialized computers that turn automated instructions into physical actions.

According to a July 30 warning from the FBI and Environmental Protection Agency, attackers have been targeting Allen-Bradley MicroLogix 1100 and 1400 controllers that are directly exposed to the internet.

After gaining access, hackers changed device IP addresses and passwords. That left some operators unable to see or control connected equipment. At least one targeted organization also found changes to PLC project files across several sites.

The FBI’s warning suggests the intrusions may not be isolated security failures. Across several victims, investigators found similarities in third-party network setups that “may provide” hackers with an opportunity to multiply their successes when the same vulnerable hardware and network designs appear across multiple customers.

In other words, a contractor could install similar equipment using similar settings at several water facilities. Once hackers learn how to compromise one installation, they may be able to reuse parts of the same playbook elsewhere.

That does not necessarily mean one shared password caused every attack. The larger password problem includes industrial devices left directly accessible online, weak access controls, undocumented remote connections, and systems that may still use default or easily guessed credentials. This is not surprising, as an All About Cookies survey found that 82% of Americans use unsafe passwords.

Thousands of devices are still exposed

The size of that attack surface is difficult to determine, but internet-scanning company Censys found more than 10,000 internet-facing systems associated with manufacturers named in federal cyber warnings.

As of July 30, Censys identified:

  • 4,148 Allen-Bradley hosts
  • 4,117 Siemens SIMATIC S7-1200 controllers
  • 2,072 Schneider Electric hosts

The Schneider Electric number covers the company’s hardware generally, not confirmed PLCs specifically. Censys also cautioned that exposure alone does not prove a device is vulnerable or has been compromised.

Still, the geographic data shows why federal officials are concerned. About 71% of the exposed Allen-Bradley devices identified by Censys were in the United States. Combined cellular carriers accounted for 59% of the exposed hosts.

CISA has identified cellular modems as a particular blind spot. A modem installed by a utility, contractor, or system integrator may provide remote access without appearing in the organization’s usual internet-exposure scans.

Federal officials are urging utilities to remove PLCs from the public internet, route necessary remote access through secure gateways and firewalls, replace default credentials with strong and unique passwords, and restrict connections to approved devices and IP addresses.

The FBI also recommends that utilities maintain the ability to operate systems manually. That can keep water flowing while compromised technology is investigated or restored.

Cyberattacks on tap

The latest incidents show how a digital intrusion can produce physical consequences.

The FBI says reported effects have included lost water pressure and flooding. A major drop in pressure could allow untreated groundwater to enter pipes, depending on the system and circumstances.

In Georgia, the Clayton County Water Authority reported that unauthorized cyber activity may have caused or contributed to a July 27 disruption affecting operational systems and water service. Some customers experienced reduced pressure, leading the utility to issue a precautionary boil-water advisory.

Service was restored within hours, and testing found no harmful bacteria. The authority subsequently said unauthorized cyber activity may have caused or contributed to the disruption.

The attacks reported in New Jersey were less disruptive. Water continued running in Cape May and Woodbine, and officials said testing found no effects on water quality. Woodbine reported that only its phone system was disrupted.

These distinctions matter. A cyberattack against a water utility does not automatically mean the water has been poisoned or contaminated. No facility identified in the current campaign has reported unsafe drinking water.

But an attack that disrupts pumps, pressure, monitoring, or communications may force a utility to issue an advisory while it verifies that the system remains safe.

What residents should watch for

Residents cannot personally fix the security of a municipal water system, but they can prepare for service disruptions and make sure they receive accurate information quickly.

Pay attention to:

  • Sudden low or lost water pressure
  • An unexpected service outage
  • A precautionary boil-water advisory
  • Announcements that a utility has switched to manual operations
  • Requests to conserve water while systems are restored

A low pressure or outage does not immediately prove that hackers are responsible. Equipment failures, broken pipes, construction, and severe weather can produce similar symptoms. Check your water provider’s website, verified social media accounts, municipal alert system, and local public health department before acting on rumors.

Residents can also prepare before an outage. The CDC recommends storing at least one gallon of water per person per day for a minimum of three days. Households may need additional water for pets, medical needs, hot weather, or longer disruptions.

The current campaign has not created a nationwide drinking-water emergency. It has, however, exposed a nationwide security problem: when the same internet-connected equipment and vendor configurations appear in community after community, one successful intrusion can become a template for the next.

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] New Jersey, Alabama Join States Targeted in Water Cyberattacks