Defense & Security • July 31, 2026

Water-System Cyberattacks Put Manual Control Back on the Checklist

CISA’s warning after attacks on water utilities shows why internet-exposed industrial controls, passwords, and practiced manual operations are national-security issues.

Victor Talon

By Victor Talon • FrontPage Crew

Water-System Cyberattacks Put Manual Control Back on the Checklist

A federal warning about attacks on water and wastewater systems is a reminder that national defense does not begin and end at military bases. It also runs through pumps, pressure controls and treatment equipment that keep communities operating.

The Cybersecurity and Infrastructure Security Agency said operators should protect internet-connected operational technology after activity targeting programmable logic controllers. Reuters reported that more than 30 Minnesota water systems experienced coordinated disruption on July 26 and 27, amid a broader pattern affecting utilities in at least seven states. Federal investigators tied the activity to Iranian-affiliated cyber actors, while emphasizing that the investigation continues.

The reported effects were serious even though officials said drinking-water safety was not compromised. Attackers changed passwords, knocked equipment offline and caused operating problems that included pressure loss and flooding. Some facilities had to reset systems manually. That is precisely why a cyber incident affecting a small utility can become a public-safety event without contaminating the water itself.

The first defense is not glamorous. Operators should remove unnecessary industrial devices from the public internet, change default credentials, require stronger authentication, segment business networks from operational controls and maintain reliable backups of configurations. They also need current contact lists for federal and state responders. A system that can be restored only by the one employee who remembers an old password is not resilient.

Manual control is the second defense. Utilities should know how long they can operate pumps and treatment processes when digital management fails, which valves require physical access and what staffing is needed around the clock. Those procedures must be practiced before an emergency. A paper plan that has never been tested is not the same as an operating capability.

Attribution deserves discipline. Iranian-linked actors have a documented history of probing exposed industrial equipment, and the new alert identifies technical patterns that defenders can use. But public claims about who directed a specific attack should follow forensic evidence, not the political temperature. Officials should publish indicators and mitigation guidance quickly while separating confirmed attribution from assessment.

The operational lesson is clear regardless of the final name attached to the intrusion. Water systems are targets because they combine public consequence with uneven security. The next accountability check is whether utilities disconnect exposed controllers, fund basic cyber hygiene and prove they can keep water moving when the screens go dark.

Congress and state regulators should also ask which small utilities cannot afford these controls. Shared security services, emergency grants and regional exercises may be necessary where a town lacks a full-time cyber staff. Minimum standards work only when operators have a practical path to meet them.