When you turn on the faucet and expect clean water, you probably don’t think about passwords, network connections, or the possibility that someone halfway around the world could be trying to access the systems helping deliver that water. Most people don't.
In a recent Spectrum News report on water plant cybersecurity, members of the public admitted they had not associated cybersecurity with their water supply.
Behind the scenes, however, treatment facilities increasingly rely on digital systems to monitor water quality, control pumps, operate valves, manage chemical treatment, and keep water moving through communities.
That technology has made water systems more efficient, but it’s also created another way for attackers to reach critical infrastructure.
The Environmental Protection Agency (EPA) says cyberattacks against public water systems are increasing. In 2025 alone, the agency identified cybersecurity vulnerabilities at 277 water systems and worked with those utilities to address weaknesses ranging from authentication problems to insufficient access controls.
For an industry responsible for one of life's most basic necessities, cybersecurity is no longer just an IT concern.
Modern water treatment looks very different from a purely mechanical operation. Water and wastewater facilities use operational technology (OT) to monitor and control physical processes. Depending on the facility, these systems can help operators monitor pumping stations, evaluate water quality, adjust equipment, collect data, and manage treatment processes.
NIST describes the water sector as undergoing a digital transformation, with utilities increasingly using connected sensors, network devices, data collection systems, and analytics to improve operations and service. Each new connection can provide useful information or remote functionality, but it can also expand the potential attack surface.
A compromise inside a water facility can have consequences beyond lost files or an inaccessible email account.
Whereas a compromised business network might expose sensitive information or interrupt administrative work, access to poorly secured OT could potentially interfere with pumps, valves, treatment equipment, sensors, or other systems involved in producing and distributing safe water.
EPA has warned that cyber incidents affecting water systems could disrupt treatment, distribution, and storage, damage physical equipment, or interfere with chemical levels. In other words, cybersecurity can become a public health and operational resilience issue.
Water infrastructure has already attracted the attention of nation-state actors, cybercriminals, and other threat groups.
In 2023, Iranian government-affiliated cyber actors compromised internet-connected programmable logic controllers (PLCs) used by multiple U.S. water and wastewater facilities. According to a joint federal advisory, some of the targeted devices were exposed to the internet and protected by default passwords or no password at all.
In April 2026, the EPA, FBI, CISA, and NSA issued another joint warning about ongoing Iranian-affiliated activity affecting U.S. organizations, including the water sector. Reported activity across critical infrastructure included configuration wiping, interference with mechanical sensor software, and disruption of human-machine interfaces (HMIs).
More recently, Spectrum News reported that attacks tied to Iran targeted more than 100 drinking water and wastewater systems across 12 states during the summer of 2026. The incidents prompted renewed attention to cybersecurity protections at water facilities.
Some cybercriminals are financially motivated. Other groups may seek to disrupt, demonstrate access, gather intelligence, or instill fear. Nation-state actors may see critical infrastructure as a strategic target that can provide leverage during periods of geopolitical tension.
Water is particularly significant because almost every part of a community depends on it. Hospitals need water. Manufacturers need water. Schools, farms, restaurants, data centers, emergency services, and homes need it. A disruption at a water utility can quickly become a problem that extends far beyond the facility itself.
The U.S. Government Accountability Office (GAO) has warned that attacks against water and wastewater systems threaten public health, the environment, and other critical infrastructure sectors. GAO has also noted that foreign governments and cybercriminal groups have already targeted U.S. water infrastructure.
This makes water systems attractive not necessarily because of the data they hold, but because of the service they provide.
A major metropolitan water authority may have dedicated cybersecurity personnel, whereas a small community utility may not.
The United States has nearly 170,000 drinking water and wastewater systems, according to GAO. These organizations vary dramatically in size, staffing, funding, technology, and cybersecurity maturity.
For smaller facilities, the same people responsible for keeping operations running may also be dealing with aging infrastructure, regulatory requirements, equipment maintenance, staffing shortages, and cybersecurity. That resource gap can make basic security improvements harder to implement consistently.
Water facilities cannot simply shut everything down whenever a security issue appears; treatment and distribution need to continue. Maintenance windows can be limited, and changes to operational systems must be evaluated carefully to ensure security improvements do not unintentionally compromise safety or availability.
Cybersecurity in this environment requires balancing protection with the reality that the underlying process must keep running.
Not every critical infrastructure compromise requires an advanced zero-day vulnerability.
Default passwords, outdated software, poorly controlled remote access, and weak network segmentation can create opportunities for attackers without requiring particularly sophisticated techniques.
EPA inspections have uncovered examples of drinking water systems using default passwords, sharing a single login among employees, and failing to revoke access for former employees. In a 2024 enforcement alert, EPA reported that more than 70% of systems it had inspected since September 2023 were out of compliance with certain Safe Drinking Water Act risk and emergency planning requirements.
It’s important to separate business systems from operational environments because cybersecurity maturity is not defined by how many security products an organization owns. It starts with understanding the environment and reducing opportunities for an attacker to gain access.
There is no single security product that can protect an entire water system. A more resilient approach uses multiple layers to reduce the likelihood that a single compromised account, device, or connection will lead to an operational incident.
For water utilities, that can translate into several practical priorities:
When cybersecurity is discussed in other industries, the conversation often centers on stolen credentials, ransomware, exposed customer records, or financial loss. Those risks exist in the water industry too, but they are only part of the picture.
Here, a digital system can be connected to a physical process responsible for delivering safe drinking water. And, most importantly, it helps protect something millions of people rely on without thinking twice about it. When everything is working correctly, most people will never know how much technology, security, and preparation are behind the simple act of turning on a faucet.
Clean water infrastructure is easy to take for granted because most of the technology behind it stays out of sight. As water facilities become more connected, utilities need security that accounts for both traditional IT and the operational systems responsible for keeping essential services running. That means knowing what is happening across the environment, reducing unnecessary exposure, preparing for incidents, and detecting threats before they have an opportunity to interfere with operations.
RADICL helps organizations strengthen their cybersecurity with 24/7 monitoring, managed detection and response, and hands-on security expertise. For organizations responsible for critical infrastructure and essential services, that visibility can help uncover suspicious activity early and provide the expertise needed to respond when something does not look right.
Why would hackers target water treatment facilities?
Water systems are critical infrastructure. Interfering with them can affect public health, businesses, government services, healthcare, manufacturing, and everyday life. Attackers may be motivated by money, geopolitical objectives, intelligence gathering, or simply the opportunity presented by an exposed system.
What is operational technology in a water facility?
Operational technology (OT) includes hardware and software used to monitor and control physical equipment and industrial processes. In water environments, OT can be involved in pumps, valves, chemical treatment, water quality monitoring, storage, and distribution.
Can a cyberattack actually affect drinking water?
Potentially, yes. Federal agencies have warned that access to vulnerable operational systems could allow attackers to disrupt treatment or distribution, damage equipment, interfere with monitoring, or manipulate process settings.
Want to strengthen the security protecting your critical systems? Talk to RADICL about building a more resilient cybersecurity program.