Intelligence Analysis
US Water-System Cyberattacks Expose a Security Gap Across Industries
21 AUG 2026
/
3 min read

In late July, attackers breached operational technology (OT) at more than 30 municipal water systems across Minnesota, changing controller settings and locking operators out of their own systems. Within days, the FBI confirmed similar incidents at water and wastewater utilities in at least seven other states. The pattern points to a weakness in OT security that reaches well beyond the water sector — and it says as much about business continuity risk as it does about defense.
Why OT Security Failed Where IT Security Held
Operational technology cybersecurity protects the systems that run physical equipment: pumps, valves, motors, and treatment processes. That is a different job from securing the corporate networks that handle data, and the Minnesota incidents show what happens when it lags behind. Programmable logic controllers, the devices that actually control this equipment, often remain reachable through remote-access pathways that receive far less oversight than a company's core network. Attackers did not need sophisticated custom tools to reach physical processes; common, poorly governed remote-access configurations that many industrial organizations still rely on were enough.
Shared vendor practices make this worse. When several customers configure remote access the same way, a breach at one site can hand attackers a blueprint for the next. That is how one campaign touched dozens of utilities across multiple states without a custom intrusion built for each target.
Critical Infrastructure Vulnerabilities That Cross Sectors
The same exposure extends into manufacturing, energy, logistics, food production, and commercial facilities — anywhere PLCs and industrial control systems keep physical operations running. And the risk is not confined to direct targets. Companies depend on public water, power, transport, and communications infrastructure, so disruption to a single utility can affect hotel operations, office occupancy, data-center cooling, or site access even when a company's own network stays secure.
Business Continuity Risk Depends on Preparedness
CISA publicly confirmed that attackers changed passwords and IP addresses and forced some utilities into manual operations. What kept the disruption limited was not a lack of attacker capability, but the fact that affected utilities had stored water, manual controls, available staff, and rapid response plans ready to go. A facility with less spare capacity, fewer staff, or weaker manual procedures could have faced far more severe consequences from the same intrusion.
That distinction reframes business continuity risk for any organization that relies on industrial control systems. The real question is no longer only whether an attacker can be stopped, but how long operations can run manually once one gets through anyway. A practical starting point treats remote-access security as a business-continuity issue as much as a defensive one: map every pathway into OT systems, and test how long operations can run manually before a shutdown becomes necessary.
The complete strategic outlook contains the intelligence analysis behind these findings, including the sector- and region-specific risk breakdowns, and the complete set of implications and recommended safeguard measures.
Related
Sharpen your
view of risk
Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.
Intelligence & Insights
Intelligence
Worth Gathering
Employing a team of 200+ analysts around the world, Crisis24 is the only source you need for on-point, actionable insights on any risk-related topic.

Article
Insider Risk Lessons for Security Leaders Following Flight FZ1073
Crisis24 helps organizations assess insider risk and strengthen preparedness for incidents such as flydubai flight FZ1073.
By Graeme Hudson
October 2, 2026

Intelligence Analysis
Bangladesh’s Concurrent Dengue and Measles Outbreaks Strain Healthcare System
Bangladesh is confronting concurrent large-scale outbreaks of dengue and measles, intensifying pressure on an already strained health system, particularly in urban centers and high-burden districts.
By Crisis24 Health Intelligence Team
September 29, 2026

Case Study
Unauthorized Access to Sensitive Internal Data: A Coordinated Insider Threat Response
See how Crisis24 coordinated forensic, legal, security, and operational expertise to investigate and contain a complex insider threat incident.
September 23, 2026

Intelligence Analysis
Europe’s Extreme Heat and Wildfires Likely to Drive Recurring Seasonal Disruptions
Extreme heat and wildfires are becoming predictable features of Europe’s summer risk environment, increasing the likelihood of recurring operational disruption.
By Elizabeth Yin
September 10, 2026



