Seven States, One Weakness: What the US Water Utility Hacks Expose
On 30 July 2026, the FBI and the US Environmental Protection Agency issued a joint warning: since 27 July, water and wastewater utilities in at least seven US states had reported cyberattacks. The attackers went after a specific weak point — industrial control devices (programmable logic controllers, or PLCs) that were sitting directly on the internet. Once in, they changed the devices' IP addresses and set new passwords, locking operators out of their own equipment. Some utilities reported flooding and loss of water pressure, and the FBI warned that pressure loss can let untreated groundwater seep into pipes.
What makes this alarming is how unsophisticated it was. The attackers didn't need cutting-edge exploits — they found control devices exposed to the open internet and tampered with them remotely. The FBI also noted that several victims shared similar network setups supplied by the same third parties, meaning one successful break-in handed attackers a template they could reuse across other organisations. Investigations into who is responsible are still ongoing.
Why This Matters for Your Business
- Internet-exposed devices are everywhere, not just in water plants. Building management systems, HVAC controllers, door access panels, cameras, printers and NAS boxes are routinely connected to the internet for convenience — and forgotten. Every one of them is a potential front door.
- Losing control can hurt more than losing data. These attacks didn't steal files; they locked operators out of physical equipment. If a device your operations depend on stopped answering tomorrow, how long could you keep working?
- Shared vendor setups multiply risk. The FBI found victims with near-identical network configurations from the same suppliers. If your IT or equipment vendor uses one cookie-cutter setup across all their customers, a breach at one of them is a rehearsal for a breach at you.
- Old, unsupported hardware is a standing invitation. Devices past end-of-life no longer receive security patches, which is exactly why attackers seek them out. Ageing kit that "still works fine" is often the most dangerous thing on your network.
What Every Business Should Do Now
- Find out what's exposed. Audit every device reachable from the internet — not just servers, but controllers, cameras, modems and anything a vendor installed. You can't protect what you don't know about.
- Put devices behind a gateway. Nothing operational should face the internet directly. Remote access should go through a secured, monitored gateway or VPN — the FBI's own first recommendation.
- Kill default and shared passwords. The attackers set passwords on devices that had weak or absent ones. Strong, unique credentials on every device closes the easiest door.
- Restrict who can talk to what. Firewall rules and access control lists should only allow communication between devices that genuinely need it. Everything else gets blocked.
- Test your manual fallback. The utilities that coped best could switch to manual operations. Tested backups, documented recovery steps and a rehearsed continuity plan are what turn an incident into an inconvenience.
- Retire end-of-life equipment. Keep a rolling forecast of what goes out of support and when — and replace or isolate it before attackers find it.
How a Managed Service Provider (MSP) Helps
- Managed Services. A complete, current inventory of every device on your network — including the ones a contractor plugged in three years ago — with patching and lifecycle management handled for you.
- Security & SOC. Around-the-clock monitoring that flags unusual logins, configuration changes and lockouts the moment they happen, not days later when something floods.
- Backups & Disaster Recovery. Known-good configurations and tested recovery plans, so a tampered device can be restored and operations can continue while the incident is contained.
- Cloud & Network Architecture. Proper segmentation and secure remote access design, so operational equipment is never one guessed password away from the open internet.
- Compliance Management. Alignment with frameworks like the Essential Eight, so the controls that would have stopped these attacks are in place and evidenced — not assumed.
- Consulting. An honest review of your vendor and supplier setups, so a cookie-cutter configuration somewhere else doesn't become your problem.
The water utilities hit in July weren't targeted because they were valuable — they were targeted because they were reachable. That's the uncomfortable lesson for every business: attackers don't start with your industry or your size, they start with what's exposed. Knowing exactly what's connected, locking it down and rehearsing your fallback isn't a big-utility problem. It's the baseline for anyone whose operations depend on things that are plugged in.
Do you know exactly what's connected to the internet right now?
We'll find out in one assessment — before someone else does.
Talk to Modena360