World

Hackers targeted water systems in seven US states. Here’s how they tried to take control

Hackers tried to break into at least 30 municipal water systems in Minnesota on July 26-27, 2026. Since then, Michigan and five other states have reported similar cyberattacks.

The attackers did not try to infiltrate the computers that utility offices use. Instead, they tried to seize control of small computers in equipment like pumps and valves that deliver drinking water to millions of people.

The utilities countered the attacks by shutting down the control computers and sending personnel out into the field to operate equipment manually. Utility officials have said that water remained safe to drink.

As a scholar who researches cyber conflict, I find that the methods used in these incidents are typical of international cyberattacks. Initial suspicion has fallen on hackers allegedly aligned with Iran, but the U.S. government has yet to attribute the attack to anyone.

How can someone from far away seize control of a water system and possibly shut off the flow or taint the water?

There are about 152,000 public drinking water systems in the United States, according to the federal government. A municipality gets its water from lakes, reservoirs, rivers or underground aquifers.

Pumps move water through pipes to a treatment plant that filters and disinfects it. More pumps push the treated water into storage tanks, then through distribution pipes to homes and businesses. The entire system can span many square miles.

The hackers accessed small computers called programmable logic controllers at the water systems that operate all sorts of industrial equipment. The programmable logic controllers read sensors that measure conditions such as water pressure, water chemistry, tank levels and equipment status, and automatically operate pumps, valves and alarms. A household thermostat is a useful comparison: It reads the temperature and tells the heating or cooling system what to do.

The programmable logic controllers also transmit operational data to a utility’s central computer system. Workers use dashboards to monitor the information and send commands back to the controllers. The two-way communications can travel through wired networks, over radio or cellular links, or through internet connections.

Many utilities operate with small staffs, so remote connections allow an employee to monitor a distant pump or tank, receive an alarm after hours or let a vendor diagnose equipment without traveling to every site.

Controllers that use the internet may access it directly, or go through protective firewalls, secure gateways or virtual private networks. Direct access is more vulnerable because there are fewer defensive barriers. A hacker can find a controller by scanning the internet and finding its Internet Protocol, or IP, address, then try a weak or stolen password or exploit a known security flaw.

To reach a controller through a secure gateway or encrypted service, a hacker would have to steal remote-access credentials, or break into the gateway or private network, or get control of an operator’s workstation. The hacker could then use that foothold to reach the controller.

Attempted access can also be part of an intruder’s longer-term strategy to collect information, test defenses or establish entry for a later date.

Attacks on industrial control systems often follow a familiar sequence. Infiltration often begins with a quiet search for access. Attackers scan internet addresses for controllers, dashboards and outside companies that provide remote access services, looking for targets that are linked directly to the internet.

  • For more: Elrisala website and for social networking, you can follow us on Facebook
  • Source of information and images “independent”

Related Articles

Leave a Reply

Back to top button

Discover more from Elrisala

Subscribe now to keep reading and get access to the full archive.

Continue reading