top of page

How Hackers Exposed the Weak Links in America's Water and Power Grid

Justin Liu
Sep 6
5 min read

A Weekend in Minnesota

On July 26, 2026, technicians at more than 30 small water utilities across Minnesota discovered that their control screens changed by themselves. The passwords were reset, as were the IP addresses. At some water plants, the remote sensors and valves had ceased to work. Four days later, the FBI and EPA reported that water utilities in at least 7 states and as many as 12 had experienced nearly identical break-ins (FBI/EPA, 2026). Officials suspected Iran of being connected to the attacks, although no formal accusations were made (CBS News, 2026).


The attack did not contaminate water resources; some localities had their flow rates reduced for a short while, and some had to switch to manual mode. Some places also issued boil-water notices for residents (CNN, 2026). This attack was one of the most serious cybersecurity breaches of American water systems to date, and it demonstrated the overall vulnerability of the country’s access to potable water and electric-power plants.


A Decade of Warning Shots

In February 2021, hackers attempted to alter the sodium hydroxide levels at a Florida water treatment plant near Oldsmar, though a plant operator caught and reversed the change before it caused harm (“Turbulent Waters,” 2024). In November of 2023, an Iranian hacking group known as CyberAv3ngers gained control of a water utility in Aliquippa, Pennsylvania, using a default manufacturer’s password (“Turbulent Waters,” 2024). Two months later, in January 2024, a Russia-linked group calling itself the Cyber Army of Russia caused a water tower in Muleshoe, Texas, to overflow, sending tens of thousands of gallons of water into the street (Axios, 2024). In the meantime, Volt Typhoon, a Chinese state-sponsored hacking group, was found to have infiltrated the local public electricity and water utility in Littleton, Massachusetts, going undetected for nearly ten months (Daily Security Review, 2025). Each hacking attempt has a common feature: vulnerabilities.


The common vulnerability that allowed unauthorized access to water utilities in Minnesota and other locations was the default password on the Rockwell Automation MicroLogix programmable logic controller (PLC). Hackers scanned the internet for this particular type of controller that was connected to the internet and gained access to it (FBI/EPA, 2026). Federal agencies have concluded that this is a low-tech way of attacking water utilities that have weak cybersecurity, one that relies on finding an unlocked door rather than breaking through a wall (Cybersecurity Dive, 2026).


Why It Matters

There is a structural problem with the current state of water utilities in the United States and the way they address the issue of cybersecurity. Experts estimate that there are between 150,000 and 170,000 separate drinking water and wastewater systems in the United States (Smart Cities Dive, 2026). Approximately 90% of U.S. water utilities serve communities of fewer than 10,000 people (Smart Cities Dive, 2026). While the electric grid is controlled by regional grid operators subject to federal oversight, water utilities are managed by local authorities and tend to have limited cybersecurity resources, since cybersecurity spending must compete with more immediate local priorities such as schools and road repair.


A cybersecurity expert from Claroty noted that his home state of Minnesota has fewer than 100 electric utilities but over 1,000 water utilities, which have fewer cybersecurity defenses (Smart Cities Dive, 2026). The 2024 attack on the 14 million customers of American Water Works is yet another reminder that not only is the cybersecurity of the United States’ water utilities inadequate, but it is also potentially catastrophic (University of Chicago Harris School, 2024). According to official reports, the main goal of Volt Typhoon is not the data that is stored on the servers of water utilities but the opportunity to take control of these servers in the future (CISA, 2024). Experts believe that Volt Typhoon is preparing the ground to create chaos in the United States during a conflict with China over Taiwan (Industrial Cyber, 2025). An attack on the electricity grid could lead to blackouts that would affect multiple states, disrupting health care, defense, and commercial trade, causing economic damage and, in the worst case, loss of life (Industrial Cyber, 2025).


Where Things Stand

The United States currently deals with the cybersecurity breach in water utilities mainly on the federal level. After the events in Minnesota, the FBI and the Environmental Protection Agency directed water utilities to remove the vulnerable PLCs from the public network, change default passwords, and ensure that no unauthorized devices are attached to the network (FBI/EPA, 2026). Some grassroots initiatives have also helped to improve the cybersecurity of water utilities. For example, a University of Chicago cybersecurity initiative named DEF CON Franklin connects volunteer cybersecurity experts with rural water utilities to help them improve cybersecurity (University of Chicago Harris School, 2024). States such as New York have also provided funding for water utilities for cybersecurity projects; in particular, about nine million dollars was allocated for the development of a project in New York (New York State, Office of Governor Kathy Hochul, 2026).


On the federal level, however, the Cybersecurity and Infrastructure Security Agency (CISA) has suffered a significant blow due to budget cuts in 2025, losing approximately one-third of its workforce, according to reporting on the agency’s staffing reductions (Warner, 2026). Experts believe that the current strategy of the United States is not effective enough, as state-level utilities have neither the resources nor the personnel to improve their cybersecurity infrastructure on their own. Unlike the electric grid, which has operated for over a decade under mandatory federal reliability and cybersecurity standards enforced by the North American Electric Reliability Corporation, water utilities do not have an analogous system that would ensure consistent cybersecurity standards across states. For now, voluntary donations, pro-bono assistance from cybersecurity experts, and local initiatives are the only sources of support for most of the country’s smaller utilities.


Looking Ahead

Although water utilities have so far been the victim of repeated hacking attempts, no one has yet died because of this, and no poisonous substance has appeared in the tap water (CBS News, 2026). Perhaps this is why the response to all this was mostly measured ,  the events are treated as local emergencies rather than as a threat to the entire country. However, a decade is a long time, and multiple attempts, spanning a dozen or more states and involving at least three foreign actors, indicate that the situation is severe. The fact that state-sponsored hackers continue to test the defenses of critical infrastructure, and that this problem remains unresolved more than a decade after the first known intrusion near Rye Brook, New York, in 2013, raises a real question: how much longer can the country afford to treat each new warning as an isolated event rather than as part of a pattern that keeps repeating itself?




References


Axios. (2024, April 17). Russia-linked hackers behind Texas water tower cyberattack. https://www.axios.com/2024/04/17/russia-us-water-system-hacks-sandworm

CBS News. (2026, August). At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say. https://www.cbsnews.com/news/more-states-water-systems-cyberattacks-iran-backed-hackers/

CISA. (2024). Advisory AA24-038A: PRC state-sponsored actors compromise and maintain persistent access to U.S. critical infrastructure. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a

CNN. (2026, July 31). Sweeping cyberattack hits U.S. water systems. https://www.cnn.com/2026/07/31/politics/sweeping-cyberattack-us-water-systems

Cybersecurity Dive. (2026). What we know so far about the hacking campaign against U.S. water systems. https://www.cybersecuritydive.com/news/what-we-know-so-far-about-the-hacking-campaign-against-us-water-systems/828374/

Daily Security Review. (2025). Volt Typhoon energy grid cyberattack exposes U.S. infrastructure vulnerabilities. https://dailysecurityreview.com/security-spotlight/volt-typhoon-energy-grid-cyberattack-exposes-us-infrastructure-vulnerabilities/

FBI/EPA. (2026, August). Public service announcement: Malicious cyber actors targeting water and wastewater sector internet-facing programmable logic controllers, causing operational disruptions. Federal Bureau of Investigation. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions

Industrial Cyber. (2025). China's Typhoon cyber operations target U.S. critical infrastructure sectors in move toward large-scale disruption. https://industrialcyber.co/reports/chinas-typhoon-cyber-operations-target-us-critical-infrastructure-sectors-in-move-toward-large-scale-disruption/

New York State, Office of Governor Kathy Hochul. (2026, August 3). Governor Hochul announces more than $9 million in cybersecurity grants to help protect 153 water systems statewide. https://www.governor.ny.gov/news/governor-hochul-announces-more-9-million-cybersecurity-grants-help-protect-153-water-systems

Smart Cities Dive. (2026). Water utility cyberattacks expose vulnerability across U.S. cities. https://www.smartcitiesdive.com/news/water-utility-cyberattacks-expose-vulnerability-across-us-cities/826826/

"Turbulent Waters": When cyberattacks meet critical infrastructure. (2024). https://thecommentaryandyou.substack.com/p/turbulent-waters-when-cyberattacks

University of Chicago Harris School of Public Policy. (2024). DEF CON Franklin: Protecting rural water utilities from cyberattacks. https://harris.uchicago.edu/node/54596

Warner, M. R. (2026, June 24). Warner raises alarm on CISA workforce and budget cuts that are leaving our country vulnerable to threats [Press release]. U.S. Senate. https://www.warner.senate.gov/newsroom/press-releases/warner-raises-alarm-on-cisa-workforce-and-budget-cuts-that-are-leaving-our-country-vulnerable-to-threats/

Comments


bottom of page