/
사이버 복원력

100+ U.S. Water Systems Attacked: What Happened and Why Zero Trust Matters

In a closed-door war game observed by WIRED, about 30 insurance executives played out a mock cyberattack on 5,000 U.S. water utilities. The effects spread fast. Refrigeration failed at food warehouses. Drug production slowed and put insulin supplies at risk. Data centers lost cooling, which took cloud services offline. Most alarming, 2,000 hospitals lost water. Some had to evacuate when their cooling systems failed.

The exercise, run by the insurance-industry group CyberAcuView and former CISA strategist Joshua Corman, modeled what could happen if China-linked Volt Typhoon launched a large attack on the U.S. water sector. Then, in July 2026, reality moved closer to the script.

Basic tactics, real-world disruption

On July 30, the FBI and EPA announced that water and wastewater utilities in at least seven states had reported attacks since July 27. The attackers reached Rockwell Automation Allen-Bradley programmable logic controllers (PLCs) through the internet. PLCs control pumps, valves, and other water equipment. Many of the targeted PLCs were linked to cellular modems, which let staff manage them remotely. But if that link is open to the internet, an attacker can reach the PLC too.

Once inside, the attackers changed device passwords and IP addresses, which locked operators out. Some utilities could no longer see or control linked equipment. At least one found changes to its PLC project files.

The attacks had real effects. Some systems lost water pressure. Some sites flooded. Several had to run manually. In Georgia, a disrupted pump station led to a precautionary boil-water advisory.

The known scope soon grew to at least 12 states. More than 30 water systems in Minnesota were targeted, along with systems in Michigan, Georgia, South Dakota, New Jersey, and Alabama.

AI widens the PLC threat

Less than three weeks after the FBI alert, federal agencies warned of a new threat. Attackers were targeting Siemens S7 PLCs with attack scripts built by AI and made to look like real monitoring tools. The agencies said the threat went beyond Siemens. Other PLC brands and key sectors, including water, also faced risk.

AI can make attacks faster and easier. But it didn't create the weak points: equipment open to the internet, old systems, weak access rules, and poor views into operational technology (OT).

A campaign wider than anyone knew

In late August, CISA put a number on the July campaign. Attackers had targeted more than 100 internet-exposed systems in the U.S. water and wastewater sector, most often PLCs connected directly to a cellular modem. The damage was limited. But the attacks showed that attackers could reach key water equipment, and that a simple tactic could work at scale.

The attacks didn't cause the disaster in the war game. But they showed a path to physical disruption. They also showed why the problem is hard to fix: water utilities can't quickly patch or replace every old controller, and they can't remove every connection used to run equipment from far away. The answer begins with seeing how these systems connect and containing a breach before it can disrupt water operations.

“There needs to be a move toward visibility and containment,” said Trevor Dearing, director of critical infrastructure solutions at Illumio. Getting there means better controls and Zero Trust policies. With Zero Trust, operators can see network connections, remove those they don't need, and control the rest. They can stop a breach before it becomes a disaster.

Water can't modernize overnight

The water sector includes large city utilities, small town systems, and rural providers, and their budgets and staff vary widely. Many small utilities don't have a cyber team. Many also run old PLCs that operate pumps, open valves, or manage key water treatment steps. Replacing every PLC is costly, and a patch may force a restart that halts water service. Not every water system can go offline during upgrades. Remote access adds risk, but it's often needed because equipment can span a wide area.

Project Watershed 250

The attacks have prompted a joint federal, state, and private-sector response. On August 31, the Office of the National Cyber Director (ONCD) and the state of Texas launched Project Watershed 250. The six-month pilot will give Texas water utilities free cyber tools and support from a dozen technology companies.

“Water systems are often underfunded and operate with tight budgets,” Dearing said. That can make it hard to replace every old controller. Project Watershed 250 may help close that gap. But tools and support can't control what each device can reach. Utilities also need to see and control the connections around their devices.

Five Zero Trust steps for reducing water-sector risk

CISA's Internet Exposure Reduction Guidance sets out four tasks: Find what is open to the internet. Decide what must stay online. Protect it. Then check again as the network changes.

The five steps below turn that advice into action:

1. Find what is exposed and connected.

First, list every IT and OT asset that the internet can reach. Include links used by vendors and other partners. Check virtual private networks (VPNs), cellular modems, and remote access tools. CISA also says to check IP addresses used by third parties. Don't assume those links are safe.

Then map traffic inside the network. “The conversation we have more often than anything is visibility: understanding what is connected to what and how it is communicating,” Dearing said.

A static network map isn't enough. Teams need a live view of which systems are talking.

2. Remove internet access that isn't needed.

Ask why each device is online. If it doesn't need direct internet access, disconnect it. A PLC, human-machine interface (HMI), or remote terminal unit shouldn't be open to the public internet. When remote access is needed, send it through a secure gateway, firewall, or VPN. Change all default passwords. Use unique usernames, strong passwords, and phishing-resistant multifactor authentication (MFA). Install security updates.

3. Limit each device to its job.

Remote access isn't the only risk. One valid login shouldn't open the whole OT network. Set rules for each PLC. List which workstations, gateways, data historians, and HMIs need to reach it. Block all other connections. Limit each allowed link to the protocol it needs.

“We talk about microsegmentation and segmentation,” Dearing said. “In the OT world, it is really about secure connectivity.”

Use secure industrial protocols when devices support them. Encryption and certificates can confirm who or what is connecting. But they don't replace access rules.

4. Protect systems you can't patch.

CISA says to patch systems that face the internet. It also says to replace products that no longer get support. But a water utility may need years to replace old equipment. Until then, isolate old systems and allow only the connections they need.

“A device could have 100 vulnerabilities because of its age,” Dearing said. “But if it's only connected to one other thing, and you can control that connection, then the exposure of that device may be quite low.”

This is often called virtual patching. It doesn't fix the flaw, but it can block many paths to the device and limit where an attacker can go next.

5. Plan how to contain an attack.

CISA says to watch network traffic for odd activity. It also says to check internet exposure often. Utilities need a plan to isolate a compromised system.

“If you lose control of the PLC, you need to be able to isolate it,” Dearing said. “You need a plan and a pretested set of isolation policies that you can put in place.”

An attack may first show up on a workstation or gateway. Teams must be ready to isolate it at once. The rest of the water operation must keep running.

Keep one exposed system from becoming a water emergency

In a water utility, Zero Trust protects more than data. It also protects the PLCs that run pumps, valves, and water treatment. “Water utilities may not be able to eliminate every vulnerability or replace every aging PLC,” Dearing said. “But they can gain a live view of how their systems connect and communicate. With that visibility, they can decide which systems need access and which connections to permit. Most important, they can stop one compromised device from putting the rest of the water operation at risk.”

The war game imagined 5,000 utilities hit at once. July showed how the first 100 were reached.

Whether it’s proactive or post-breach, start your breach containment journey with a custom demo today.

관련 문서

지금 일루미오 인사이트 체험하기

AI 기반 관찰 가능성을 통해 위협을 더 빠르게 탐지, 이해, 차단하는 방법을 알아보세요.