Skip to main content

What Recent Cyberattacks Mean for Water Utilities

August 5, 2026

Written by: Nick Weaver, Director, Water and Wastewater
Bill Bateman, Principal, Cybersecurity and NERC Compliance

On Monday July 27th, 2026, reports began to circulate about potential coordinated cyber-attacks on water and wastewater utilities of various sizes in Wisconsin, including systems in Milwaukee, Madison, and Green Bay, which required some utilities to switch to manual operations or issue boil notices. According to a memo from the Minnesota Bureau of Criminal Apprehension, the attack likely aimed to “cause loss of system pressure” and in turn result in “potential contamination of water supply”.

Based on publicly available information, the attack has focused on Programmable Logic Controllers (PLCs) which serve a variety of purposes in the water treatment and distribution process, including monitoring pressure, controlling chemical dosing, and pump control. Due to increasing automation of systems over the last 25 years and the need to remotely monitor and control PLCs which are often done via an internet connection, these assets are attractive targets for hackers, particularly when aging infrastructure was never properly configured or updated to latest software patches.

To date, seven states have reported active cyber-attacks against water and wastewater systems. On August 1, more attacks were reported in Michigan and other states. While no official attribution has been made as to the origin of the attacks, there are indications that a state actor may be involved, and the FBI and other agencies have warned that Iranian hackers have previously targeted water and wastewater systems along with other critical infrastructure.

The Cybersecurity & Infrastructure Security Agency (CISA) recommends that utilities take the following mitigation steps:

  • Disconnect PLCs from the internet and enable remote access through a VPN or gateway device
  • Enable password protections and change password for any assets still using default credentials
  • Allow Internet Protocol (IP) access only from known assets such as engineering laptops or other critical operational assets

Additional resources from CISA can be found at:
https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology

Currently, no risks to public safety or significant compromise of systems have been reported. This is fortunate, but the attacks should serve as a wake up call to city managers, utility boards, finance staff, and other stakeholders that what has largely been viewed a theoretical risk is closer to reality and safeguards need to be in place to both protect systems from attack and ensure resiliency in the case of a successful compromise.

Unlike common ransomware or data breaches attacks, attacks on water systems have the potential to affect public health directly, whether through disruptions to service, alterations to treatment processes, or direct targeting of plant assets. Beyond the risk to public health these attacks can also affect industrial operations, electric generation, and digital infrastructure that depend on reliable water supplies for cooling or other processes. In some cases, such as electrical generation or data centers, loss of water for cooling could result in catastrophic damage to the facility being served.

Beyond taking control of systems, access to utility data can be used to glean information about the level of production occurring at commercial facilities being served by the utility, personally identifiable information used for billing and other purposes, and network design and potential vulnerabilities.

Cyberthreat risk is magnified by the historical underinvestment in cybersecurity by water and wastewater utilities, particularly in comparison to peers in the electric utility sector. The concern about a fragmented, unprepared, and large target set with significant potential for large scale disruptions is what keeps water and wastewater utilities on the radar of malicious actors and utility regulators alike.

Water and wastewater utilities, particularly smaller systems that may not have resources, technical ability, or response plans in place, represent attractive targets for these types of attacks, with the potential for more widespread attacks considered a question of when, not if due to the ability to create widespread disruptions across multiple sectors if successfully executed.

How GDS supports Water and Wastewater Utility Cybersecurity


GDS provides cybersecurity audit and design services to clients, historically focusing on ensuring that clients meet the robust security standards required by the North American Electric Reliability Corporation (NERC). We have extended our services to offer similar services to water and wastewater utilities, including:

  • AIWA Risk and Resilience Assessments (RRA), EPA Vulnerability-based assessment, and emergency response plan support meeting Section 2013 requirements and documentation required to meet mandate and board, lender, and regulator requirements.
  • Cybersecurity audit and control assessments benchmarked against AWWA guidance, NIST Cybersecurity Framework and CISA’s water and wastewater goals, with findings translated into prioritized action plan.
  • Enhanced security posture including helping scope penetration testing, OT network engineering, or SCADA hardening to meet your requirements.
  • Training and planning including security awareness, tabletop incident response exercises, and system recovery rehearsals
  • Governance and board reporting translating technical audit findings into financial and risk-management language that board members or officials need to make resource allocation decisions.
  • Expert witness and regulatory support for capital investment, cost recovery, or defending the prudence of a cybersecurity-related cost.

For more information or to discuss your needs contact:

Nick Weaver, Director, Rates and Regulatory nick.weaver@gdsassociates.com

Bill Bateman, Principal, Cybersecurity and NERC Compliance bill.bateman@gdsassociates.com