Escalating Cyber Threats to U.S. Water Systems: Key Considerations for Critical Infrastructure Operators

Compliance or Consequences Environmental Blog
Aug 31, 2026

The Federal Bureau of Investigation (FBI) and the U.S. Environmental Protection Agency (EPA) have issued a series of cybersecurity warnings highlighting an increase in cyber activity targeting operational technology (OT) used by drinking water and wastewater utilities across the United States. These incidents underscore a growing trend: foreign threat actors are increasingly exploiting internet-connected industrial control systems (ICS) to disrupt essential public services and critical infrastructure.

For utilities, municipalities, industrial operators, and organizations that rely on industrial control systems, these developments present not only operational risks, but also significant regulatory, contractual, insurance, and litigation considerations. The recent alerts also reinforce the expectation that owners and operators of critical infrastructure maintain cybersecurity programs that address both information technology (IT) and operational technology environments.

Federal Agencies Report Coordinated Attacks on Water Utilities

According to a July 30, 2026, joint advisory issued by the FBI and EPA, multiple water and wastewater utilities in at least seven states experienced cyber incidents beginning on July 27, 2026. The attacks targeted internet-accessible Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs) used to control pumps, valves, storage tanks, pressure systems, and other critical treatment processes.

Federal investigators reported that attackers altered PLC network configurations and administrative credentials, causing operators to lose visibility into and control over affected systems. In at least one incident, threat actors reportedly modified PLC project files and operational logic.

The attacks resulted in operational disruptions, including pressure loss and flooding. EPA cautioned that pressure reductions can increase the risk of contamination by allowing groundwater intrusion into drinking water distribution systems. While several affected utilities were able to transition to manual operations, the incidents illustrate how relatively simple compromises of internet-facing industrial devices can produce significant operational consequences.

Notably, federal authorities warned that similar vulnerabilities may exist where third-party system integrators or managed service providers maintain remote connectivity to customer environments, potentially creating a common point of compromise across multiple utilities.

Broader Nation-State Activity Continues to Target Critical Infrastructure

The July incidents follow a broader pattern identified in an April 2026 joint cybersecurity advisory issued by the FBI, EPA, the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA), which described an ongoing campaign by Iranian-affiliated advanced persistent threat (APT) actors targeting operational technology across U.S. critical infrastructure.

According to the agencies, attackers have demonstrated the ability to:

  • Access internet-exposed PLCs and industrial control devices;
  • Manipulate supervisory control and data acquisition (SCADA) and human-machine interface (HMI) displays;
  • Modify or delete PLC configurations;
  • Exfiltrate PLC project files;
  • Interfere with software-based sensors; and
  • Disrupt industrial operations.

Federal investigators have associated aspects of this activity with tactics previously attributed to CyberAv3ngers, an Iranian-linked hacking group.

EPA has also continued to warn of cyber threats posed by other nation-state actors, including Chinese government-affiliated groups such as Volt Typhoon and pro-Russian hacktivist organizations targeting U.S. critical infrastructure.

Why Water Systems Remain Attractive Targets

Water and wastewater utilities continue to face unique cybersecurity challenges. Many operate legacy industrial control systems that were designed for reliability rather than cybersecurity and were not intended to be directly connected to the internet.

Federal agencies continue to identify recurring vulnerabilities, including:

  • Internet-accessible PLCs and remote access devices;
  • Legacy hardware and unsupported software;
  • Default or weak administrative credentials;
  • Inadequate segmentation between IT and OT networks;
  • Persistent third-party remote access; and
  • Limited monitoring of operational technology environments.

EPA assessments have identified cybersecurity deficiencies across hundreds of drinking water systems, while agency reports continue to emphasize that many utilities have yet to implement foundational cybersecurity controls that are expected under current federal guidance.

Regulatory and Liability Considerations

Cybersecurity has become an increasingly significant compliance issue for operators of critical infrastructure.

Community water systems serving more than 3,300 people remain subject to Section 1433 of the Safe Drinking Water Act, which requires covered utilities to conduct risk and resilience assessments, develop emergency response plans, periodically update those documents, and certify compliance to EPA.

Although the specific obligations vary depending upon the organization and applicable state law, a significant cyber incident may also trigger:

  • State data breach notification obligations;
  • Contractual notice requirements;
  • Cyber insurance reporting provisions;
  • Environmental reporting obligations;
  • Public disclosure requirements;
  • Regulatory investigations; and
  • Civil litigation arising from service disruptions, contamination events, or property damage.

Boards of directors, municipal leadership, and executive management should recognize that cybersecurity governance increasingly extends beyond traditional IT functions. Regulators and litigants alike are placing greater emphasis on whether organizations exercised reasonable oversight, maintained documented cybersecurity programs, and implemented appropriate risk management practices.

Practical Steps Organizations Should Consider

The recent federal advisories reinforce several immediate risk-reduction measures for organizations operating industrial control systems.

Organizations should consider:

  • Identifying and removing internet exposure for PLCs, HMIs, SCADA systems, and other operational technology where feasible;
  • Eliminating default passwords and shared administrator accounts;
  • Implementing multifactor authentication for remote access;
  • Segmenting operational technology from enterprise IT networks;
  • Reviewing PLC logic and configuration files for unauthorized modifications;
  • Maintaining current inventories of IT and OT assets;
  • Testing manual operating procedures to ensure continuity during cyber incidents;
  • Maintaining secure offline backups of operational configurations;
  • Reviewing remote-access practices of vendors, system integrators, and managed service providers; and
  • Updating incident response and business continuity plans to address operational technology events.

Because third-party vendors frequently maintain privileged access to industrial environments, organizations should also evaluate vendor cybersecurity requirements, contractual obligations, and incident notification procedures as part of broader supply chain risk management.

Looking Ahead

The recent FBI and EPA advisories demonstrate that cyberattacks against industrial control systems continue to evolve from isolated incidents into sustained campaigns directed at U.S. critical infrastructure. Many of these attacks exploit well-known vulnerabilities rather than sophisticated malware, highlighting the importance of basic cyber hygiene and disciplined operational security.

Organizations that operate critical infrastructure should use these alerts as an opportunity to reassess operational technology security, review regulatory compliance obligations, evaluate vendor risk management practices, and ensure that cybersecurity governance receives appropriate board and executive oversight.

Early investment in preventive controls and incident preparedness can significantly reduce operational disruption, regulatory exposure, and potential liability following a cyber incident.

Frantz Ward regularly assists clients in developing legally defensible cybersecurity programs, conducting risk assessments, responding to cyber incidents, and navigating the complex legal obligations that arise following attacks affecting critical infrastructure.

For additional information about the issues discussed in this alert or assistance evaluating your organization’s cybersecurity preparedness, please contact Michael R. Blumenthal or any member of our Environmental or Data Privacy & Cybersecurity Practice Groups.