Intelligence Analysis
US Water-System Cyberattacks Expose a Security Gap Across Industries
21 AUG 2026
/
3 min read

In late July, attackers breached operational technology (OT) at more than 30 municipal water systems across Minnesota, changing controller settings and locking operators out of their own systems. Within days, the FBI confirmed similar incidents at water and wastewater utilities in at least seven other states. The pattern points to a weakness in OT security that reaches well beyond the water sector — and it says as much about business continuity risk as it does about defense.
Why OT Security Failed Where IT Security Held
Operational technology cybersecurity protects the systems that run physical equipment: pumps, valves, motors, and treatment processes. That is a different job from securing the corporate networks that handle data, and the Minnesota incidents show what happens when it lags behind. Programmable logic controllers, the devices that actually control this equipment, often remain reachable through remote-access pathways that receive far less oversight than a company's core network. Attackers did not need sophisticated custom tools to reach physical processes; common, poorly governed remote-access configurations that many industrial organizations still rely on were enough.
Shared vendor practices make this worse. When several customers configure remote access the same way, a breach at one site can hand attackers a blueprint for the next. That is how one campaign touched dozens of utilities across multiple states without a custom intrusion built for each target.
Critical Infrastructure Vulnerabilities That Cross Sectors
The same exposure extends into manufacturing, energy, logistics, food production, and commercial facilities — anywhere PLCs and industrial control systems keep physical operations running. And the risk is not confined to direct targets. Companies depend on public water, power, transport, and communications infrastructure, so disruption to a single utility can affect hotel operations, office occupancy, data-center cooling, or site access even when a company's own network stays secure.
Business Continuity Risk Depends on Preparedness
CISA publicly confirmed that attackers changed passwords and IP addresses and forced some utilities into manual operations. What kept the disruption limited was not a lack of attacker capability, but the fact that affected utilities had stored water, manual controls, available staff, and rapid response plans ready to go. A facility with less spare capacity, fewer staff, or weaker manual procedures could have faced far more severe consequences from the same intrusion.
That distinction reframes business continuity risk for any organization that relies on industrial control systems. The real question is no longer only whether an attacker can be stopped, but how long operations can run manually once one gets through anyway. A practical starting point treats remote-access security as a business-continuity issue as much as a defensive one: map every pathway into OT systems, and test how long operations can run manually before a shutdown becomes necessary.
The complete strategic outlook contains the intelligence analysis behind these findings, including the sector- and region-specific risk breakdowns, and the complete set of implications and recommended safeguard measures.
Related
Sharpen your
view of risk
Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.
Intelligence & Insights
Intelligence
Worth Gathering
Employing a team of 200+ analysts around the world, Crisis24 is the only source you need for on-point, actionable insights on any risk-related topic.

Intelligence Analysis
Europe’s Extreme Heat and Wildfires Likely to Drive Recurring Seasonal Disruptions
Extreme heat and wildfires are becoming predictable features of Europe’s summer risk environment, increasing the likelihood of recurring operational disruption.
By Elizabeth Yin
September 10, 2026

eBook
Insider Threat Management Playbook
A practical guide to identifying, investigating, and mitigating insider risk through a connected, cross-functional approach.
September 8, 2026

Intelligence Analysis
Asia-Pacific Food Security Risks Rise Amid Middle East Conflict
Explore how Middle East conflict, rising fuel and fertilizer costs, and El Niño could threaten APAC food security and regional stability through 2027.
By Jacopo Di Bella
September 4, 2026

Article
Balancing Trust, Privacy, and Monitoring in Insider Risk Programs
A strong Insider Threat Management Program (ITMP) should be designed to identify risk, vulnerability, and anomalous activity, not to create an organization in which every employee is treated as a potential offender.
By Alexander Johnson
September 2, 2026



