All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
When hackers break into a water plant, the consequences can flow straight to your faucet. They can lock operators out, cut water pressure, flood facilities, and potentially allow untreated groundwater to seep into pipes.
Water and wastewater facilities in at least 12 states have reportedly been targeted in a hacking campaign that began in late July. New Jersey and Alabama are the latest states to confirm attacks, joining Minnesota, Michigan, South Dakota, and Georgia.[1]
Officials have reported limited disruptions and said the affected communities’ drinking water remained safe. But the FBI has identified a weakness that could allow the campaign to spread: similar network configurations installed by third-party vendors may give hackers a repeatable way into multiple facilities.
Thousands of devices are still exposed
Cyberattacks on tap
What residents should watch for
The nationwide attack blueprint
Modern water systems rely on programmable logic controllers, or PLCs, to monitor and operate equipment such as pumps, valves, and treatment systems. They are essentially specialized computers that turn automated instructions into physical actions.
According to a July 30 warning from the FBI and Environmental Protection Agency, attackers have been targeting Allen-Bradley MicroLogix 1100 and 1400 controllers that are directly exposed to the internet.
After gaining access, hackers changed device IP addresses and passwords. That left some operators unable to see or control connected equipment. At least one targeted organization also found changes to PLC project files across several sites.
The FBI’s warning suggests the intrusions may not be isolated security failures. Across several victims, investigators found similarities in third-party network setups that “may provide” hackers with an opportunity to multiply their successes when the same vulnerable hardware and network designs appear across multiple customers.
In other words, a contractor could install similar equipment using similar settings at several water facilities. Once hackers learn how to compromise one installation, they may be able to reuse parts of the same playbook elsewhere.
That does not necessarily mean one shared password caused every attack. The larger password problem includes industrial devices left directly accessible online, weak access controls, undocumented remote connections, and systems that may still use default or easily guessed credentials. This is not surprising, as an All About Cookies survey found that 82% of Americans use unsafe passwords.
Thousands of devices are still exposed
The size of that attack surface is difficult to determine, but internet-scanning company Censys found more than 10,000 internet-facing systems associated with manufacturers named in federal cyber warnings.
As of July 30, Censys identified:
- 4,148 Allen-Bradley hosts
- 4,117 Siemens SIMATIC S7-1200 controllers
- 2,072 Schneider Electric hosts
The Schneider Electric number covers the company’s hardware generally, not confirmed PLCs specifically. Censys also cautioned that exposure alone does not prove a device is vulnerable or has been compromised.
Still, the geographic data shows why federal officials are concerned. About 71% of the exposed Allen-Bradley devices identified by Censys were in the United States. Combined cellular carriers accounted for 59% of the exposed hosts.
CISA has identified cellular modems as a particular blind spot. A modem installed by a utility, contractor, or system integrator may provide remote access without appearing in the organization’s usual internet-exposure scans.
Federal officials are urging utilities to remove PLCs from the public internet, route necessary remote access through secure gateways and firewalls, replace default credentials with strong and unique passwords, and restrict connections to approved devices and IP addresses.
The FBI also recommends that utilities maintain the ability to operate systems manually. That can keep water flowing while compromised technology is investigated or restored.
Cyberattacks on tap
The latest incidents show how a digital intrusion can produce physical consequences.
The FBI says reported effects have included lost water pressure and flooding. A major drop in pressure could allow untreated groundwater to enter pipes, depending on the system and circumstances.
In Georgia, the Clayton County Water Authority reported that unauthorized cyber activity may have caused or contributed to a July 27 disruption affecting operational systems and water service. Some customers experienced reduced pressure, leading the utility to issue a precautionary boil-water advisory.
Service was restored within hours, and testing found no harmful bacteria. The authority subsequently said unauthorized cyber activity may have caused or contributed to the disruption.
The attacks reported in New Jersey were less disruptive. Water continued running in Cape May and Woodbine, and officials said testing found no effects on water quality. Woodbine reported that only its phone system was disrupted.
These distinctions matter. A cyberattack against a water utility does not automatically mean the water has been poisoned or contaminated. No facility identified in the current campaign has reported unsafe drinking water.
But an attack that disrupts pumps, pressure, monitoring, or communications may force a utility to issue an advisory while it verifies that the system remains safe.
What residents should watch for
Residents cannot personally fix the security of a municipal water system, but they can prepare for service disruptions and make sure they receive accurate information quickly.
Pay attention to:
- Sudden low or lost water pressure
- An unexpected service outage
- A precautionary boil-water advisory
- Announcements that a utility has switched to manual operations
- Requests to conserve water while systems are restored
A low pressure or outage does not immediately prove that hackers are responsible. Equipment failures, broken pipes, construction, and severe weather can produce similar symptoms. Check your water provider’s website, verified social media accounts, municipal alert system, and local public health department before acting on rumors.
Residents can also prepare before an outage. The CDC recommends storing at least one gallon of water per person per day for a minimum of three days. Households may need additional water for pets, medical needs, hot weather, or longer disruptions.
The current campaign has not created a nationwide drinking-water emergency. It has, however, exposed a nationwide security problem: when the same internet-connected equipment and vendor configurations appear in community after community, one successful intrusion can become a template for the next.