Spyderweb Communications

Water Utility Cyberattacks Hit at Least Seven States: What Western Washington Systems Should Do Now

Back to Insights
August 6, 20268 min readSpyderweb Communications Team

Written by the Spyderweb water-systems security team — securing SCADA, PLC, backflow assembly, and meter-reading systems since 2003.

Spyderweb has worked inside water systems since 2003, and our team's water experience runs back to the late 1990s: pump houses, well fields, sewer lift stations, telemetry cabinets bolted to the block wall of a booster station in the rain. So when the FBI and EPA published a joint advisory on July 30 reporting that water and wastewater utilities in at least seven states had been attacked since July 27, we read every word of it. Nothing in it surprised us. That is the part that should bother you.

The details below come from the federal advisories and from utilities that have spoken publicly. Where attribution is unsettled, we say so plainly. But the technical story is settled enough, and it points directly at problems we have been fixing in water systems around Puget Sound for two decades.

What Happened to Water Utilities in July and August 2026?

Starting July 27, 2026, water and wastewater utilities in at least seven states reported intrusions into their control systems, according to a joint FBI and EPA public service announcement issued July 30. The attackers went after internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs, the small controllers that run pumps, valves, and chemical feed at thousands of American utilities. They changed device IP addresses and passwords, which locked operators out of monitoring and control. At least one utility found its ladder logic had been modified. Reported effects included loss of pressure and flooding at utility facilities. ABC News, citing unnamed officials, puts the count as high as a dozen states.

Minnesota took the broadest hit, with more than 30 community water systems affected. Plymouth lost remote communication with two water towers and fourteen sewer lift stations and sent staff out to watch them in person. Clayton County, Georgia issued a weekend boil water advisory after pump stations went down. Two New Jersey municipal systems were temporarily blinded and switched to manual operations without any service disruption, and Michigan reported a small number of consistent incidents. In every publicly known case, the drinking water itself stayed safe. The FBI's own caveat is still worth repeating: lose pressure in a distribution system and untreated groundwater can seep into the pipes. Anyone who has managed a cross-connection control program knows that is not a theoretical concern.

So who did it? There has been no formal attribution. Officials widely believe the activity is linked to Iran, and the tradecraft echoes the 2023 CyberAv3ngers campaign against Unitronics PLCs documented in CISA advisory AA23-335A, when an IRGC-affiliated group hit a booster station in Aliquippa, Pennsylvania. Some investigators are also weighing whether a different state actor is imitating that playbook. For a utility operator, the honest answer is that it barely matters. The defense is identical either way.

StateWhat Was ReportedOperational Impact
Minnesota30+ community water systems affected; Plymouth lost remote communication with two water towers and 14 sewer lift stations.Manual operations kept water flowing; Braham recovered in roughly 90 minutes. No water supply compromised.
GeorgiaClayton County Water Authority pump stations knocked offline; Columbus Water Works detected an intrusion.Weekend boil water advisory in Clayton County; water confirmed safe in both systems.
New JerseyTwo municipal systems "temporarily blinded," losing remote visibility into internet-exposed control systems.Manual operations; no service disruption reported.
MichiganA small number of consistent incident reports.No public-health impact reported.
At least 3 more statesFBI/EPA count "at least seven states" total; ABC News sources say up to a dozen. Details not yet public.Outcomes hinged on early detection and response and the ability to run manually.

How Did the Attackers Get In?

They walked in through the front door. These were internet-facing PLCs, reachable by anyone who went looking, many with password protection never even switched on. Nothing in the federal advisories describes exotic tooling; the story they tell is remote access to equipment that was reachable and poorly protected. CISA's July 30 alert described password lockouts, changed IP addresses, utilities forced onto manual operations, and one detail that deserves far more attention than it got: undocumented cellular modems, installed by operators, vendors, and integrators, giving the outside world a path into control networks the utility did not even know it had.

The federal advisories also called out cookie-cutter integrator setups. When one integrator wires fifty small utilities the same way, same remote-access recipe, same credentials, a working attack against one is a working attack against fifty. We have seen those installs up close. They are tidy, they are documented in a three-ring binder in the control room, and not one of them was designed with the assumption that someone hostile would come looking.

The scale of exposure is not speculation. An EPA Office of Inspector General passive scan of 1,062 drinking water systems found 97 systems serving roughly 26.6 million people carrying critical or high-risk vulnerabilities, and 211 more with externally visible open portals. If you have never checked what your own utility looks like from the outside, an external penetration test answers that question before someone on another continent does.

The Connected Systems Nobody Audits

SCADA is not the only wire into a water utility. Over the years we have secured backflow assembly management software, Badger and Sensus meter-reading systems, chart recorders that sprouted network cards, and telemetry links a vendor added during a service call and never wrote down. Let us be precise: none of those product lines were implicated in the July attacks. But they are exactly the class of connectivity CISA warned about, vendor-installed, cellular or internet-linked, and invisible on the network diagram taped inside the panel door. Every one is a door into your network, and you cannot lock a door you do not know you have.

Segmentation Is the Discipline That Stops This

A control network that cannot be reached from the internet cannot be attacked from the internet. That sounds too simple to be the answer, but it is most of the answer. The PLCs hit in July were compromised because they sat on public addresses. These systems should never have been reachable from the internet. Full stop.

Real segmentation means layer-3 firewalls standing between your layer-2 broadcast domains, so traffic moving between the office network, the SCADA front-end, and the field controllers has to pass a checkpoint that permits only what a water system actually needs. It means the control network is fully segregated: no path from a billing PC, an email inbox, or a vendor laptop straight to a pump controller. And it means zero direct internet exposure for any control device, with remote access handled exclusively through hardened, brokered paths that are logged and watched every time they are used. This is the FBI and EPA remediation guidance translated into an architecture: allow only expected control-system traffic, put a secure gateway in front of everything, and remove every inbound port from the public internet.

Getting there starts with knowing what you have. A thorough risk assessment maps every device, every modem, and every vendor connection; the security engineering work then puts the walls where they belong. In our experience, the mapping exercise always turns up at least one connection nobody in the room remembered authorizing.

How to Get Your Water System Off the Public Internet

This is the sequence we walk utilities through, distilled from the FBI, EPA, and CISA guidance and from years of doing the work in the field:

  1. Inventory every connection. List every path into your control network: the SCADA front-end, PLC serial-to-ethernet converters, cellular modems, vendor telemetry, and meter-reading and backflow software links. Include anything an integrator installed, documented or not.
  2. Check your exposure from outside. Verify from the public internet whether any controller, HMI, or portal is reachable. An external penetration test or exposure scan shows you exactly what an attacker sees.
  3. Change every default and shared password. Replace factory credentials on PLCs, HMIs, and modems with unique, strong passwords, and return controller key switches to run mode so logic cannot be changed remotely.
  4. Remove direct internet exposure. Take every control device off public IP addresses and close all inbound ports. Nothing in the control system should answer the open internet.
  5. Segment with layer-3 firewalls. Place firewalls between the business network, the SCADA front-end, and field devices, permitting only the specific traffic the control system requires to operate.
  6. Broker and monitor all remote access. Route any remaining remote access through a hardened, monitored gateway, log every session, and add 24/7 monitoring and endpoint protection on SCADA and HMI workstations.
  7. Rehearse manual operations. Confirm operators can run pumps, tanks, and treatment by hand, and practice it. Manual capability helped keep water service running through the July 2026 incidents.

Why Western Washington Water Systems Should Pay Attention

More than 6.2 million Washingtonians get their drinking water from public water systems, and most of those systems are small. The Washington State Department of Health has warned hundreds of drinking-water providers about this campaign. Here is the uncomfortable part: Washington has no general cybersecurity requirement for drinking water systems, and the state's Cybersecurity Action Plan covers only the 249 largest suppliers plus about 100 wastewater systems. If you run a small district in Pierce, King, or Thurston County, no state program is coming to secure your telemetry. That responsibility lands on you, and often on the same two or three people who also fix the leaks, read the meters, and answer the phone at midnight.

We do not say that to scold anyone. The small-system operators we have worked with are some of the most capable, resourceful people in this business, keeping water flowing on budgets that would not cover a big city's coffee service. The failure here belongs mostly to the vendors and integrators who shipped internet-exposed, copy-paste control setups to customers who trusted them. The fix, unfairly, still lands on the utility. From Tacoma to Olympia to Tumwater, the water systems serving Puget Sound communities match the size and profile of the utilities hit in July almost exactly. Since 2003, water systems have been core to the industries we serve, and they are where much of our experience was earned.

What Around-the-Clock Monitoring Actually Looks Like

The intrusions in this wave announced themselves: password lockouts, controllers changing IP addresses, sites dropping off SCADA. Braham, Minnesota isolated its affected system, restored a backup, and restarted its plant in roughly ninety minutes. Utilities without that kind of readiness found out when the pumps stopped answering.

That is the whole case for continuous monitoring on the SCADA front-end. SIEM-class monitoring that watches the control network's edge for exactly those signals. Endpoint protection on the HMI and SCADA workstations, because those Windows machines are the bridge between the office world and the control world and they get treated like neither. And a person on the other end at 2 a.m., because a two-operator utility cannot staff a night shift to read logs. This is what our 24/7 managed security service exists for: premium monitored security, watched around the clock by people who know what a lift station alarm should look like. It is one part of the water utility security services we have provided across Western Washington since 2003. Keep your manual-operations muscle, too. Several of the July utilities stayed in service only because operators could run their systems by hand, a continuity capability worth rehearsing on purpose rather than discovering under pressure.

If you want a starting point that is not a sales pitch, the two documents we hand people first are the joint CISA, EPA, and FBI Top Cyber Actions for Securing Water Systems and WaterISAC's 12 Cybersecurity Fundamentals. Both are free, short, and written for operators rather than security people.

If You Run a Water System Out Here, Let's Talk

If you operate a water system anywhere in Western Washington, whether that is a 300-connection district or a regional utility, we would genuinely like to hear from you. Since 2003, we have worked inside these systems: SCADA, PLC panels, telemetry, backflow assembly software, Badger and Sensus meter reading. We know what a well-level transducer feeds and why the integrator put the modem where they did. Bring us your network diagram, or the shoebox of vendor manuals that passes for one. The conversation costs nothing, and the FBI's advisory is reason enough to have it this month instead of next year.

Frequently Asked Questions

Are Washington water utilities being targeted by hackers?

Washington utilities were not named in the July 2026 federal advisories, but the Washington State Department of Health has warned hundreds of drinking-water providers about the campaign. The FBI reports incidents in at least seven states, and the exposure that enabled them, internet-facing controllers and vendor-installed remote access, is just as common in Washington systems. Treat the advisory as though your utility were named in it.

Does Washington state require cybersecurity for drinking water systems?

No, Washington has no general cybersecurity requirement for drinking water systems. The state's Cybersecurity Action Plan covers only the 249 largest water suppliers and roughly 100 wastewater systems, leaving most small districts responsible for their own defenses. Federal AWIA risk and resilience requirements apply only to systems serving more than 3,300 people, so the smallest systems fall outside those too.

What is OT network segmentation, and does my water system need it?

Segmentation separates your control network from your business network and the internet using layer-3 firewalls, so only expected, explicitly permitted traffic can move between them. The utilities attacked in July 2026 had control hardware reachable from the internet; a segmented system with brokered, monitored remote access presents no such target. If your SCADA and office computers share a network, you need it.

How do hackers actually get into water systems?

Mostly through internet-exposed controllers and leftover vendor remote access, not sophisticated exploits. In the 2026 wave, attackers reached internet-facing Rockwell MicroLogix PLCs, many of them poorly secured, some with password protection never enabled, then changed device addresses and credentials to lock operators out. Undocumented cellular modems installed during vendor and integrator visits are another common path into control networks.

What should a small water district do first after the 2026 FBI alert?

Find out what is exposed. Inventory every network connection into your control system, including cellular modems and vendor telemetry, then check what your utility looks like from the public internet. Change every default password, take directly exposed devices offline, and put a firewall between the control network and everything else. The FBI and EPA's first instruction is to remove control systems from the public internet.

Does Spyderweb work with small water systems, and where?

Yes. Since 2003, Spyderweb Communications has secured water utility systems, including SCADA, PLCs, telemetry, backflow assembly software, and Badger and Sensus meter-reading systems, and our team's water experience runs back to the late 1990s. We serve all of Western Washington, from Pierce, King, and Thurston counties across the Puget Sound region, and we welcome inquiries from utilities beyond that area.

Ready to Secure Your Business?

Get a free consultation with our Tacoma-based team. We've been securing Puget Sound businesses since 2003.