Big or small—Critical infrastructure under attack
Clean running water is a blessing many of us take for granted. We get water from our refrigerators, sinks, showers, and hoses. We turn the faucet on, and we know that we are going to get clean water. Most of us don’t give this a second thought. But there are entire, coordinated systems that deliver clean water to our homes. And the scary thing is just how fragile these systems are. A series of recent cyberattacks, very likely attributed to Iran, have demonstrated just how vulnerable these systems are. Facilities big and small are all in the crosshairs.
On July 28, 2026, Minnesota reported that a coordinated cyberattack targeted more than 30 of its water systems over a two-day period. Michigan experienced similar cyberattacks on nine of its water systems, and these states are not alone. As of July 30, 2026, the FBI received reports from at least seven states reporting cyber incidents related to their Water and Wastewater Sector. These attacks are so prevalent that on July 30, 2026, the FBI and the EPA issued a public service announcement sounding the alarm over cyberattacks targeting critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) issued its own alert that same day. The agency advised critical infrastructure owners and operators to take specific protective measures as quickly as possible. While attribution is not definitive, it is likely Iranian-based actors perpetrate these attacks. These threat actors do not discriminate by facility size—large and small water facilities are potential targets.
The threat actors are conducting these attacks by gaining remote access to internet-facing Programmable Logic Controllers (PLCs). After access is established, the threat actors alter device configurations, such as changing IP addresses and passwords. Changing passwords and swapping IP addresses may not sound like the dramatic action sequences of a James Bond film, but the real-world consequences of these seemingly mundane tactics are far more dangerous than any Hollywood plot—loss of pressure, boil water advisories, sustained manual operations, flooding, and loss of function and visibility into water systems can result.
Protecting our nation’s critical infrastructure is imperative. Critical infrastructure operators must take precautions to ensure their systems are secure. Before a cyber incident occurs, facilities should have disaster response plans and alternative ways to provide services if network security is compromised. Response plans must be in place to react to the incident as quickly and safely as possible. Facility size is not a differentiator. Threat actors are opportunistic and will potentially take advantage of any vulnerability.
When in doubt, businesses can consult with trusted external legal counsel for guidance on ensuring proper steps are taken in preparation for responding to a cyberattack. If you have any questions regarding your company’s position and potential for improvement, reach out to McDonald Hopkins’ national Data Privacy and Cybersecurity practice group.