💙 Love us or your money back — first 3 months of service

NEWSROOM

Hackers Hit Water Systems in 12 States. Federal Warnings Went Out in April.

Neither Missouri nor Kansas has turned up on the list of affected utilities. Both states run thousands of systems on the same internet-connected equipment that was targeted everywhere else.

KANSAS CITY, Mo., August 5, 2026. Cyberattacks on water and wastewater utilities have been reported in at least 12 states, including more than 30 systems across Minnesota in one weekend. Missouri has more than 2,700 public water systems. Kansas has more than 1,000.

The attackers never touched the water. They reached the small industrial computers that run pumps, wells, and valves, connected straight to the internet. They changed passwords to lock operators out and knocked equipment offline by changing addresses. Utilities that recovered went manual. No drinking water contamination has been reported. Federal investigators consider Iran the leading suspect, though attribution isn't confirmed.

"Hackers put up smoke screens so nobody thinks anything is going wrong, while they change the systems that actually run the place," said Sam Sapp, owner of Lockbaud. "The readout said normal. It wasn't."

The timing should bother any business owner. The Cybersecurity and Infrastructure Security Agency published an advisory on this weakness April 7 and updated it July 22. Minnesota was hit four days later. There is no vendor patch and none is coming. The only fix was taking the equipment off the internet.

That gap isn't unique to water utilities. "About 75% of our members are five or less employees, with most leaning toward the less. Very few, if any, have actual IT positions on payroll," said Stacie Bratcher, executive director of the Kearney MO Chamber of Commerce. "They deal with issues when they arise, often relying on those who provided the system to serve and protect the system."

Two things any small business can check this week:

  • Find out what of yours is reachable from the internet: cameras, door access, thermostats, point-of-sale, anything a vendor set up remotely.
  • Ask every vendor, in writing, who secures the system they sold you. Don't assume it's them.

"We need to make reviewing our own systems a routine instead of a reaction," Sapp said. "And we need to review them differently, because the old checklist never asked what was online."

Lockbaud is offering its Needs Assessment, at no charge through Sept. 30 to Missouri and Kansas water districts, municipalities, public safety agencies, school districts, and rural electric co-ops. One of its five areas is external attack surface. Requests go to connect@lockbaud.com or 816-208-2888.


Why this reaches past water utilities

The equipment in this story is called a programmable logic controller. It is a small, rugged computer that opens a valve, starts a pump, or holds a tank at a set level. Water plants use them. So do grain elevators, cold storage warehouses, manufacturing lines, building HVAC systems, and commercial irrigation. They were designed decades ago for closed networks, and many were never built to survive being reachable from the open internet.

What made this campaign work was not a clever exploit. It was exposure. The devices were online, often with default or unchanged credentials, and the attackers simply logged in. That is why there is no patch to install. A vendor cannot ship an update that undoes the decision to put a controller on a public address.

The same pattern shows up in ordinary offices, just with less dramatic equipment. A camera system a vendor set up for remote viewing. A door access controller reachable so the installer can adjust schedules. A thermostat, a label printer, a point-of-sale terminal. None of it looks like IT, so none of it gets reviewed like IT.

What the federal warning actually said

CISA published advisory AA26-097A on April 7, 2026, describing Iranian-affiliated actors targeting internet-exposed controllers across water, energy, and government facilities. The July 22 update expanded the affected manufacturer list and added fresh indicators for log review. On July 30, after the Minnesota incidents, CISA issued a direct alert urging the water sector to protect operational technology against this activity.

The core guidance has not changed across any of those updates. Take the controllers off the public internet, change default credentials, and put remote access behind something that authenticates. The advisory is written for utilities, but the first instruction applies to any business with a device a vendor can reach from outside the building.

Primary sources

Every claim above traces to public reporting or federal advisories. The originals are worth reading if you operate any of this equipment.

  • CISA advisory AA26-097A, published April 7 and updated July 22, 2026, on Iranian-affiliated actors exploiting programmable logic controllers across US critical infrastructure
  • CISA alert of July 30, 2026, urging the water and wastewater sector to protect operational technology against PLC-targeting activity
  • MPR News, reporting on more than 30 Minnesota municipal water systems targeted on July 26 and 27

What this connects to

Cybersecurity for Kansas City businesses: finding what of yours is reachable from outside, and closing it before someone else finds it first.

Managed IT for chambers of commerce: practical support for member organizations where almost nobody has IT staff on payroll.

Managed IT services: ongoing monitoring and vendor accountability, so equipment reviews happen on a schedule instead of after an incident.

Free Needs Assessment through September 30

Available at no charge to Missouri and Kansas water districts, municipalities, public safety agencies, school districts, and rural electric co-ops. One of its five areas is external attack surface: what of yours is reachable from the internet right now.

Request a Needs Assessment

About Lockbaud

Lockbaud is a managed IT and cybersecurity provider based in Kansas City, Missouri, serving small and mid-sized businesses across the United States. Lockbaud works most often with accounting firms, law firms, and chambers of commerce, and backs its work with same-day support, zero-downtime onboarding, and a money-back guarantee. Founded and owned by Sam Sapp. More at lockbaud.com.

Media contact

Lockbaud Media Relations
media@lockbaud.com
(816) 264-1337

📞 Call now