A recent series of cyberattacks on water and wastewater utilities across the country serves as a reminder to businesses to consider both whether their systems are secure and the potential impacts to their operations if their systems are breached. Historically, most operational systems were not connected to the internet, including Programmable Logic Controllers (PLCs) running the Supervisory Control and Data Acquisition (SCADA) software systems used to control components of critical infrastructure. Today, many critical infrastructure systems rely on internet-connected operational technology to function, including systems controlling water, wastewater, natural gas, and electrical service. Internet connectivity has delivered significant benefits, including increased automation and processing and allowing operators to monitor data remotely. Connectivity has also increased security risks, as being connected exposes these systems to the threats and threat actors that are ubiquitous on the public internet. Unlike many other cybersecurity incidents, unauthorized access to critical utility systems can interfere with physical services that businesses and people rely upon, causing immediate, real-world harm to public safety and economic security.
Key Takeaways
- Recent cyberattacks targeting water and wastewater utilities demonstrate the cybersecurity risks associated with internet-connected operational technology, including Programmable Logic Controllers (PLCs) and Supervisory Control and Data Acquisition (SCADA) systems used to control critical infrastructure.
- Unauthorized access to operational technology systems can have immediate physical and operational consequences, including changes to equipment functionality, loss of water pressure, flooding, and interruption of critical services.
- Utilities and businesses in other industrial sectors should review the structure and connectivity of their operational systems, including how their systems interact with physical equipment and who has access to those systems.
- Businesses that rely on system integrators and other third-party vendors to maintain or configure their operational technology should conduct appropriate due diligence and implement access controls to ensure that user and administrator privileges are appropriately limited.
- Companies should review applicable federal and state cybersecurity incident reporting requirements and update and practice their incident response plans to address loss of remote access, equipment malfunction or unavailability, and service interruption impacts.
In late July 2026, water utility companies in at least 12 states reported cyberattacks on their operational technology to the FBI, including PLCs that control the pressure systems, valves, pumps, pressure control, and overall treatment processes of water systems. Minnesota officials reported that a coordinated cyberattack targeted the operational technology systems at more than 30 community water systems in the state.
According to the FBI and EPA, many operators not only lost access and visibility to their equipment, but in some cases saw changes to equipment functionality, leading to loss of water pressure and flooding. Many utilities were forced to switch to manual operations, issue precautionary notices to community members, and reduce operations while investigating the incidents. These measures came at significant cost and required diversion of resources from core business functions.
A number of reports have tied these cyber incidents to Iran-affiliated actors. In April, we highlighted a Joint Cybersecurity Advisory identifying specific threats from Iran-backed actors targeting critical energy infrastructure. This most recent attack on water and wastewater systems presents similar circumstances and highlights the growing focus on PLCs and other internet-connected operational technology as targets for hackers.
These attacks should raise alarms across industrial sectors. Other utilities, including gas and electric providers, use similar technology to control and monitor pressure, valves, and other pipeline functions that may also be vulnerable to attacks. In the context of natural gas, a cyber incident may require a company to temporarily halt services to the public in order to ensure that the pressure and flow of natural gas is safe. In a similar manner, a cyber incident affecting electric distribution systems may require a company to interrupt electrical service to avoid damage to distribution equipment and ensure public safety.
Moving forward, utilities and businesses in all sectors should review the structure and connectivity of their operational systems and the relationship their systems have with physical equipment. Businesses should carefully consider accessibility, control levels, and their overall cybersecurity posture. Companies should also be aware of applicable incident reporting requirements. Water utilities, natural gas infrastructure, and electrical distribution operate in highly regulated environments with different reporting requirements at the state and federal levels. For example, a natural gas incident is reported to the Pipeline and Hazardous Materials Safety Administration, and may also require reporting to a state’s Board of Public Utilities, whereas certain incidents involving water utilities are reported to a state’s designated water agency, such as the New Jersey Department of Environmental Protection. Companies that operate in multiple states should also be aware of the different cybersecurity incident reporting requirements under each state’s laws.
Businesses also should analyze how their physical equipment interacts with technology, identify who has access to their systems, and to what extent. In connection with the July water utility cyberattacks, the FBI noted that several victim companies relied on third parties to configure their networks. Utilities and other businesses that rely on different system integrators and vendors to maintain their equipment should ensure they do their due diligence, including vetting vendors and implementing access controls to ensure that user and administrator privileges are appropriately limited.
To be in the best position to respond quickly if or when a company experiences an incident, businesses also should review and update their incident response plans, and practice incident response scenarios that address loss of remote access, equipment malfunction or unavailability, and service interruption impacts.
To learn how to take proactive legal and security measures to protect your systems and prepare for a potential incident, please contact one of the authors or any member of McCarter & English’s Cybersecurity and Data Privacy team.
