KANSAS CITY, Mo., August 5, 2026. Cyberattacks on water and wastewater utilities have been reported in at least 12 states, including more than 30 systems across Minnesota in one weekend. Missouri has more than 2,700 public water systems. Kansas has more than 1,000.
The attackers never touched the water. They reached the small industrial computers that run pumps, wells, and valves, connected straight to the internet. They changed passwords to lock operators out and knocked equipment offline by changing addresses. Utilities that recovered went manual. No drinking water contamination has been reported. Federal investigators consider Iran the leading suspect, though attribution isn't confirmed.
"Hackers put up smoke screens so nobody thinks anything is going wrong, while they change the systems that actually run the place," said Sam Sapp, owner of Lockbaud. "The readout said normal. It wasn't."
The timing should bother any business owner. The Cybersecurity and Infrastructure Security Agency published an advisory on this weakness April 7 and updated it July 22. Minnesota was hit four days later. There is no vendor patch and none is coming. The only fix was taking the equipment off the internet.
That gap isn't unique to water utilities. "About 75% of our members are five or less employees, with most leaning toward the less. Very few, if any, have actual IT positions on payroll," said Stacie Bratcher, executive director of the Kearney MO Chamber of Commerce. "They deal with issues when they arise, often relying on those who provided the system to serve and protect the system."
Two things any small business can check this week:
- Find out what of yours is reachable from the internet: cameras, door access, thermostats, point-of-sale, anything a vendor set up remotely.
- Ask every vendor, in writing, who secures the system they sold you. Don't assume it's them.
"We need to make reviewing our own systems a routine instead of a reaction," Sapp said. "And we need to review them differently, because the old checklist never asked what was online."
Lockbaud is offering its Needs Assessment, at no charge through Sept. 30 to Missouri and Kansas water districts, municipalities, public safety agencies, school districts, and rural electric co-ops. One of its five areas is external attack surface. Requests go to connect@lockbaud.com or 816-208-2888.
Why this reaches past water utilities
The equipment in this story is called a programmable logic controller. It is a small, rugged computer that opens a valve, starts a pump, or holds a tank at a set level. Water plants use them. So do grain elevators, cold storage warehouses, manufacturing lines, building HVAC systems, and commercial irrigation. They were designed decades ago for closed networks, and many were never built to survive being reachable from the open internet.
What made this campaign work was not a clever exploit. It was exposure. The devices were online, often with default or unchanged credentials, and the attackers simply logged in. That is why there is no patch to install. A vendor cannot ship an update that undoes the decision to put a controller on a public address.
The same pattern shows up in ordinary offices, just with less dramatic equipment. A camera system a vendor set up for remote viewing. A door access controller reachable so the installer can adjust schedules. A thermostat, a label printer, a point-of-sale terminal. None of it looks like IT, so none of it gets reviewed like IT.
What the federal warning actually said
CISA published advisory AA26-097A on April 7, 2026, describing Iranian-affiliated actors targeting internet-exposed controllers across water, energy, and government facilities. The July 22 update expanded the affected manufacturer list and added fresh indicators for log review. On July 30, after the Minnesota incidents, CISA issued a direct alert urging the water sector to protect operational technology against this activity.
The core guidance has not changed across any of those updates. Take the controllers off the public internet, change default credentials, and put remote access behind something that authenticates. The advisory is written for utilities, but the first instruction applies to any business with a device a vendor can reach from outside the building.
Primary sources
Every claim above traces to public reporting or federal advisories. The originals are worth reading if you operate any of this equipment.
- CISA advisory AA26-097A, published April 7 and updated July 22, 2026, on Iranian-affiliated actors exploiting programmable logic controllers across US critical infrastructure
- CISA alert of July 30, 2026, urging the water and wastewater sector to protect operational technology against PLC-targeting activity
- MPR News, reporting on more than 30 Minnesota municipal water systems targeted on July 26 and 27
What this connects to
Cybersecurity for Kansas City businesses: finding what of yours is reachable from outside, and closing it before someone else finds it first.
Managed IT for chambers of commerce: practical support for member organizations where almost nobody has IT staff on payroll.
Managed IT services: ongoing monitoring and vendor accountability, so equipment reviews happen on a schedule instead of after an incident.