Key Takeaways
- The recent water tower cyberattacks are a polite although necessary reminder that if software runs it, someone will probably try to hack it.
- Smaller organizations — whether they’re running a water system or a hosting company — often have more in common than you might think.
- There are plenty of guidelines. But if guidance alone isn’t enough, what is?
“Water tower hacked” probably wasn’t the box anyone expected to check off on this year’s bingo card, but here we are.
It started in June when hackers claiming ties to Iran said they breached several California water utilities. In late July, a “coordinated cyberattack” targeted the operations at 30 Minnesota water systems over the course of two days. Since then, at least nine water systems in Michigan have experienced attacks, and South Dakota has confirmed a cyber incident at a Rapid City wastewater lift station.
Days before the Minnesota incidents went public, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the EPA updated a cybersecurity advisory, warning the public that cyber actors were targeting internet-connected programmable logic controllers (PLCs) in U.S. infrastructure.
Fortunately, none of the reported incidents resulted in drinking water contamination. Pressure loss did occur at some facilities, which can allow untreated groundwater, or even sewage, to be pulled back into drinking water.
Federal authorities continue to investigate the incidents, but so far, there’s been no definitive answer as to who the culprit could be, though several government officials and cybersecurity experts are pointing to Iranian-affiliated hackers.
What Hackers Are Actually Targeting
If you’re wondering what a cyberattack on a water system looks like, it’s really an attack on the computers that run it.
Cyberattackers go after the computers that run everything, like controllers that monitor tank levels, operate pumps, and regulate water flow to the city. Many of the recent attacks don’t need sophisticated malware because it’s easy enough to get through weak passwords, internet-exposed remote access software, or outdated internet-connected equipment that wasn’t secure enough.
States Hit by Water System Cyberattacks
Darker shades indicate states where more affected water systems have been publicly reported.
The late-July attacks in Minnesota took multiple automated systems offline: In Braham, a city of about 1,700 people, officials asked residents to conserve water while the city relied on what was currently stored in its water tower.
Can Water Systems Actually Be Secured?
Right now, there’s no quick fix; only the work that should have happened before the attack. CISA’s recommendations are to follow best practices:
- Use strong, unique passwords
- Require a second step to log in (multi-factor authentication)
- Install security updates as soon as they’re available
- Limit which systems can be accessed over the internet
- Keep business computers separate from equipment that runs operations
- Monitor systems for anything unusual
None of this is groundbreaking. If you work in hosting, you’ve probably heard every one of these recommendations before.
The FBI and CISA said cyberattackers got in through a mix of issues — internet-exposed remote access, weak credentials, outdated tech. Small operators like Braham are pretty much the profile that the FBI and CISA say are most exposed.
Some states are taking matters into their own hands: Earlier this year, New York announced cybersecurity grants and regulations for water systems, including mandatory cybersecurity training.
When Best Practices Aren’t Enough
“Follow the guidelines” or “take a training” is easier said than done for many smaller businesses, and it’s really not unlike hosting teams. Like them, it’s not that SMBs don’t know what good cybersecurity looks like. They just struggle to keep up with government guidance and a piling list of industry standards.
In a CrowdStrike survey, two-thirds of SMBs said cost prevents them from upgrading their security tools, and 70% rely on outside experts or partners for cybersecurity guidance. Verizon's DBIR also found vulnerability exploitation now accounts for 31% of breaches as an initial entry point, which is up more than half from the year before.
To its credit, the EPA appears to understand that guidance alone isn't enough for the water systems throughout the U.S. right now. That's why it's offering free cybersecurity assessments and technical assistance so water systems can better identify and eliminate possible weaknesses.
If governments are willing to offer hands-on help for water utilities to implement better cybersecurity, could there be similar support for the technology that keeps the internet alive? Water systems and web servers aren't apples to apples. They're both managed by software and connected to the internet, though, so they already have a few things in common.




