The Hack That Can Flood Your Street
By Eric Kamande
In some of the affected utilities, operators turned up to work and found they had lost the ability to monitor their own equipment. Remote access to the programmable controllers managing pumps, pressure and water flow had been seized. Settings had been changed. Some systems reported flooding. Others lost pressure entirely.
This was not a ransomware attack on a bank or a breach of a government database. According to a joint advisory from the FBI and the US Environmental Protection Agency issued in mid-2026, water and wastewater utilities across multiple states had been targeted through internet-exposed industrial controllers. The attackers changed IP addresses and passwords, locking operators out of the systems that keep water flowing.
Sophisticated? Not particularly. The barrier to entry for attacks on exposed industrial equipment is lower than most people assume. The consequences, though, extend well beyond a locked screen, and the vulnerability is not unique to any one country or sector.
The gap that grew while no one was watching
Industrial control systems were not built for the internet. For most of their history they didn’t need to be. A programmable logic controller (PLC) managing water pressure at a treatment plant, or a supervisory system monitoring electricity distribution, sat on closed networks accessible only to on-site engineers.
That separation has eroded. Remote monitoring, cloud-connected sensors, cellular modems and third-party maintenance access have created bridges between operational technology and conventional IT infrastructure. The business case was sound: engineers can diagnose faults from headquarters, utilities can reduce site visits, operators can see system-wide data in real time. The security implications lagged behind.
A compromised email account is a serious problem. A compromised controller can open a valve.
The 2015 attack on Ukrainian electricity distributors showed what this looks like at scale. Attackers worked their way into the industrial control systems of three regional power companies and issued commands that knocked out power to around 225,000 customers. The following year, a second campaign targeted Ukraine’s grid using Industroyer, malware engineered from scratch to speak the communication protocols used by power grid equipment. This was not a generic intrusion tool repurposed for infrastructure. Someone had built it specifically for this kind of target.
The 2021 Colonial Pipeline incident demonstrated that attackers don’t even need to reach operational systems to cause physical disruption. The ransomware hit the company’s IT environment, not the computers managing fuel flow, but Colonial halted pipeline operations while it assessed what had been compromised. That uncertainty itself was the weapon, and the lesson applies equally to a water treatment plant, a port logistics system or a hospital network facing the same ambiguity.
A different kind of threat
Not every attacker is motivated by money. State-sponsored groups have been found working quietly inside energy, water, telecoms and transport networks with no apparent interest in immediate disruption. The goal, security agencies across multiple countries have assessed, is pre-positioning: establishing access that could be activated to cause serious damage if geopolitical conditions demanded it.
This reframes the security problem in ways that conventional IT cybersecurity thinking struggles with. An intruder content to sit undetected for years, touching nothing, may already be precisely where they need to be. The question infrastructure operators now have to ask is not just “have we been breached?” but “could someone, right now, reach the systems that keep the service running?”
Resilience is not the same as defence
The response from regulators has increasingly emphasised resilience alongside prevention. Recommendations to water and energy utilities now typically include maintaining the ability to operate equipment manually, testing backups regularly, and ensuring fail-safe mechanisms actually work under failure conditions. The assumption embedded in this guidance is that some defences will eventually be defeated, and that the difference between a manageable incident and a serious one lies in whether a single compromised device can cascade into a system-wide failure.
Infrastructure operators also face an asset management problem with no clean solution. A modern utility, whether running water systems, an electricity distribution network or a telecoms backbone, may operate equipment spanning several decades. Some of it is too embedded in operations to replace quickly. Some of it no longer receives security updates. Every connected device that cannot be patched is a potential entry point that cannot be closed through conventional means.
The expanding surface
The sectors most exposed share a common challenge: connectivity that was added to systems built before modern cyber threats existed, managed by organisations whose primary expertise is operations rather than security, and protected by frameworks that were written when the physical and digital worlds were still largely separate.
A generation ago, disabling a water system required physical presence. Today, in some cases, it requires finding a controller with default credentials left exposed to the internet. The more that operational technology gets woven into networks it was never designed for, the more the security posture of essential services depends on decisions made by IT teams, equipment vendors, cloud providers and maintenance contractors who may never have visited the facilities they are inadvertently helping to expose
Get innovation insights from The FutureList weekly. Subscribe to our newsletter here