How the 2026 Water-Utility Attacks Worked
The July attacks on water systems turned on internet-exposed controllers and a vulnerability public since 2021. An account of the compromise, how the access worked, and what closes it.
The short version
- 1.The compromise ran on exposure and a years-old vulnerability. Internet-facing controllers and CVE-2021-22681, an authentication bypass public since 2021, with no patch on the affected legacy models.
- 2.The access used the controllers' own engineering software. Attackers reached the devices directly over the internet and altered how they ran, in some cases locking operators out of their own equipment.
- 3.The countermeasures follow from the mechanics. Closing it means the exposure removed, the control network segmented, and remote maintenance behind multi-factor.
The water-sector attacks in late July 2026 drew attention less for their sophistication than for how little they required. What follows is an account of the compromise itself: the equipment that was reached, how the access worked, and what closes it.
This was an exposure problem worked with a vulnerability that has been public for years, and the countermeasures follow directly from that.
What actually happened
The compromise ran on internet exposure and a long-standing, unpatched flaw. Beginning the weekend of July 26, 2026, coordinated activity struck operational technology at water and wastewater utilities across at least seven states, with Minnesota most affected: more than thirty community water systems over a single weekend. The targeted devices were programmable logic controllers, the small computers that run pumps and valves, and they answered directly from the public internet.
The vulnerability was CVE-2021-22681, an authentication bypass in the affected Rockwell Logix controllers rated CVSS 9.8 and rooted in an insufficiently protected cryptographic key in the product itself. Public since 2021, it lets an unauthenticated attacker connect to an internet-facing controller and bypass verification, and many of the exposed units are legacy models with no vendor patch. The attackers connected using the controllers' own engineering software, then modified controller project files and operator displays; in some cases they changed device passwords and IP addresses, locking operators out of their own equipment. The FBI and EPA issued a joint advisory, and CISA had flagged the same internet-exposed-PLC targeting days earlier. Reported effects included pressure loss, degraded water operations, and at least one plant taken offline.
What the compromise turned on
- Internet reachability was the enabling condition. The controllers answered from the public internet, which is what put a decade-old vulnerability within reach at all.
- CVE-2021-22681 is public since 2021, rated CVSS 9.8, and unpatched on the affected legacy controllers. Where no patch exists, removing the exposure is the available fix.
What closes it
Because internet reachability was the enabling condition, removing it is what closes the gap. Take that reachability away and the same decade-old flaw is no longer exploitable from outside. The technical response is to move operational technology off any path that reaches it directly from the internet, and to place identity and segmentation between the business network and the equipment that moves water, with remote maintenance behind multi-factor authentication and any unpatched controller isolated from public reach. That is the core of a zero-trust model: access is granted by verifying the device or user, regardless of what network segment they sit on.
What closes the exposure
- With the controllers no longer answering from the public internet, the same decade-old flaw is no longer reachable from outside. Where no patch exists, that removal is the fix.
- Segmentation and identity sit between the business network and the equipment that moves water, so access turns on a verified device or user rather than network position.
- Remote maintenance runs behind multi-factor authentication, and any unpatched controller stays isolated from public reach.
Free help for small systems
There is free, hands-on help built for systems this size. The USDA Circuit Rider Program, run by the National Rural Water Association, has put drinking-water professionals in the field since 1980, covering operations, compliance, and disaster response. It is free to rural systems serving 10,000 people or fewer, was renewed under a five-year USDA contract in 2026, and is reached through a state rural water association.
Cybersecurity is now being built into that model directly. Alongside the White House Office of the National Cyber Director and USDA, the association has stood up dedicated Cybersecurity Circuit Riders to assess and strengthen cyber capacity at rural systems, with the program expanding to add personnel trained for that work.
The pattern is not new. In November 2023, an internet-exposed controller at a water authority in Aliquippa, Pennsylvania was reached and disabled at a pressure-regulating booster station, drawing a CISA advisory of its own. The recurring element across these incidents is the same one: operational technology that answers from the public internet.
The compromise was notable for how ordinary it was: known equipment, a known vulnerability, and direct internet exposure. That is also what makes the response knowable, and it starts with the exposure. Taken in that order, the risk is bounded.
Sources: FBI/EPA PSA on water-sector PLC attacks (2026); Tenable summary of CISA Advisory AA26-097A; WaterWorld on the 2023 Aliquippa, PA booster-station PLC attack; USDA Circuit Rider Program (NRWA); NRWA cybersecurity for rural water systems; and USDA Rural Development, 2026 Circuit Rider contract.
Have control systems that answer from the internet?
When the work runs wider than a single controller, across several sites, an aging fleet, or an audit that has to be answered, FEDLIN closes the exposure and keeps it closed inside your own environment. We work alongside your operators, at the scale a small system actually runs.
Subscribe to Security Insights
Get enterprise security tips, compliance guides, and best practices delivered to your inbox.