What Makes Water Treatment Plants Vulnerable to Cyberattacks

Dr. Ravi Patel

Dr. Ravi Patel

July 7, 2026

What Makes Water Treatment Plants Vulnerable to Cyberattacks

In February 2021, an operator at a water treatment plant in Oldsmar, Florida noticed that the cursor on his computer screen was moving without his control. Someone had remotely accessed the plant’s control system through TeamViewer and was adjusting the sodium hydroxide (lye) concentration in the water supply—attempting to raise it from the normal 111 parts per million to 11,100 parts per million, a level that would have made the water dangerous to drink. The operator caught the change and reversed it; the plant’s existing manual checks would likely have caught it before distribution. No one was harmed.

The incident attracted significant attention precisely because it illustrated something that critical infrastructure security specialists had been documenting for years: water treatment facilities, along with many other pieces of critical infrastructure, are connected to the internet in ways that their operators don’t always fully understand, with security practices that don’t match the severity of the potential consequences.

The Architecture of Water Treatment Control Systems

Water treatment plants operate through Industrial Control Systems (ICS)—systems specifically designed to monitor and control physical processes. The core components are Supervisory Control and Data Acquisition (SCADA) systems, Programmable Logic Controllers (PLCs), and Human Machine Interfaces (HMIs) that allow operators to monitor conditions and adjust treatment parameters.

These systems were historically air-gapped—physically isolated from external networks—and designed with the assumption of physical security: only operators physically present in the facility could interact with the control systems. The shift toward remote monitoring and control over the past two decades changed this: utilities added remote access capabilities to allow operators to monitor and control systems from off-site, reduced staffing by enabling fewer operators to cover more facilities, and connected SCADA systems to business networks for operational data integration.

The remote access was often implemented with consumer-grade tools (TeamViewer, Windows Remote Desktop, VPNs without multi-factor authentication) and frequently without the cybersecurity controls that a network security engineer would consider baseline for any internet-connected system. The Oldsmar incident used TeamViewer with shared passwords among multiple users—a configuration that provides essentially no accountability and minimal access control.

The Vulnerability Profile of Water Sector ICS

The US Cybersecurity and Infrastructure Security Agency (CISA) and the Environmental Protection Agency have published multiple advisories documenting the specific vulnerabilities affecting water sector ICS. Several patterns recur:

Outdated operating systems. PLCs and HMIs in water utilities frequently run Windows XP or Windows 7—operating systems no longer receiving security updates. These systems were installed with expected operational lifetimes of 15–20 years and were not replaced when the underlying OS reached end-of-life because replacing functional industrial control hardware is expensive and disruptive. An ICS running Windows XP is vulnerable to known exploits that have been public for over a decade.

Default credentials. Industrial control devices are frequently deployed with vendor-default usernames and passwords that aren’t changed during installation. Shodan—the internet search engine for connected devices—regularly indexes water sector SCADA systems with default credentials accessible from the public internet. Security researchers have documented multiple water sector systems with default passwords as recently as 2023.

Flat networks without segmentation. In many utilities, the operational technology (OT) network controlling physical processes and the information technology (IT) business network are connected without meaningful segmentation. A breach of the IT network—through a phishing email, for example—can provide access to the OT network that controls treatment processes.

Limited monitoring and detection capability. Many utilities don’t have security information and event management (SIEM) systems or network monitoring that would detect anomalous activity in their OT networks. In the Oldsmar case, the intrusion was detected by an alert human operator rather than an automated security system—a detection method that doesn’t scale or operate during unstaffed hours.

Industrial control system network diagram showing potential cyber attack pathways through connected SCADA and IT systems

The Threat Landscape

The threat actors with demonstrated interest in water sector ICS include nation-state hackers, ransomware groups, and in some cases hacktivists. The nation-state interest is primarily geopolitical: compromising water infrastructure provides leverage in conflict scenarios and demonstrates capability. Several incidents attributed to Iranian-linked hackers against Israeli water systems in 2020 and to Volt Typhoon (a Chinese state-sponsored group) against US critical infrastructure including water utilities represent the high end of the threat spectrum.

Ransomware groups have been responsible for more frequent attacks against the water sector, primarily affecting IT systems and operational data rather than the control systems themselves—but with significant operational impact through the disruption of business systems that support operations. The 2021 ransomware attack on the Veolia North America water utility disrupted billing and business systems; several municipal water utility ransomware attacks have required temporary reversion to manual operations.

The specific concern with water treatment control systems is the potential for physical harm through manipulation of chemical dosing—the Oldsmar incident’s sodium hydroxide adjustment being the clearest example. Chlorine dosing, pH adjustment, and other chemical treatment parameters, if manipulated adversarially, could affect water safety before conventional testing catches the change. Physical safety systems and manual override capabilities provide important backstops, but their reliability depends on staffing levels, operator training, and whether the safety systems themselves were compromised.

The Resource and Capacity Problem

The structural challenge for water utility cybersecurity is that the sector consists predominantly of small utilities—thousands of community water systems serving fewer than 10,000 people, operated with limited IT staff and smaller budgets. The cybersecurity capabilities appropriate for critical infrastructure (dedicated security operations, network segmentation, endpoint detection, secure remote access architecture) require resources that most small water utilities don’t have and can’t justify against their operating budgets.

Larger utilities—major city water systems and large regional utilities—have made more significant cybersecurity investments and have the scale to justify dedicated security staff. The vulnerability profile that concerns federal regulators is concentrated in the long tail of small utilities where security investment is minimal.

The EPA’s 2023 attempt to require cybersecurity assessments as part of routine sanitary surveys (inspections water systems already undergo) was challenged in court by multiple states and set aside. The regulatory framework for water sector cybersecurity in the US remains weaker than for comparable critical infrastructure sectors like energy and financial services—a gap that CISA and EPA continue to attempt to address through guidance, technical assistance, and Congressional action.

What Practical Improvement Looks Like

The cybersecurity improvements with the highest impact for water utilities don’t require enterprise security infrastructure. The most frequent attack vectors—default credentials, unsegmented remote access, unpatched systems—are addressable with basic security hygiene measures:

Changing all default vendor passwords, implementing multi-factor authentication on remote access, patching or replacing end-of-life systems where feasible, and segmenting OT networks from IT networks through firewalls with restrictive allowlist rules would eliminate the majority of currently exploitable attack surface. These measures are not technically complex but require awareness, prioritisation, and in some cases modest capital investment that many small utilities haven’t made.

Federal and state programmes providing technical assistance and funding to small utilities for cybersecurity improvements are the most realistic path to addressing the concentration of vulnerability in the long tail of the sector. The physical consequences of a successful attack on water infrastructure—delivered to millions of people daily through a trusted distribution system—justify treating this as a priority that exceeds the immediate security budgets of the individual utilities responsible for it.

More articles for you