Pumps, Valves and a Password Nobody Changed
On July 26-27, 2026, hackers attempted to break into at least 30 municipal water systems in Minnesota, state officials confirmed. Since then, Michigan, New Jersey and several other states have reported similar cyberattacks, raising alarms about the vulnerability of America's drinking-water infrastructure.
Initial suspicion has fallen on hackers allegedly aligned with Iran. The U.S. government has not yet formally attributed the attacks to any actor.
What the attackers targeted — and how
The intruders did not go after utility office computers. Instead, they tried to seize control of programmable logic controllers — small industrial computers embedded in pumps, valves and alarms that deliver drinking water to millions of people. These controllers read sensors measuring water pressure, chemistry, tank levels and equipment status, and automatically operate the physical hardware. They also transmit operational data back to a utility's central dashboard, creating a two-way communications channel that can run over wired networks, radio, cellular links or direct internet connections.
The utilities countered by shutting down the control computers and deploying personnel to operate equipment manually in the field. Officials said water remained safe to drink.
A vulnerability hiding in plain sight
According to William Akoto, a scholar who researches cyber conflict and wrote about the incidents for The Conversation, the attack methods are typical of international cyberattacks on industrial control systems. The sequence is familiar: scan internet addresses for exposed controllers, locate a weak or default password, then issue commands or attempt to alter the controller's software.
Sophisticated malware is not always required. In 2023, the Cybersecurity and Infrastructure Security Agency reported that Iranian-linked hackers had targeted internet-connected Unitronics programmable logic controllers used by water utilities — and that some of those utilities were still running on the manufacturer's default password.
There are approximately 152,000 public drinking water systems in the United States, according to the federal government. Many operate with small staffs that rely on remote connections to monitor distant pumps and tanks or allow vendors to service equipment without traveling to every site. Controllers with direct internet access — without firewalls, secure gateways or virtual private networks — present the fewest defensive barriers: a hacker needs only to find the device's IP address and try a weak or stolen credential.
Scale and exposure
A single municipal water system can span many square miles, moving water from lakes, reservoirs, rivers or underground aquifers through treatment plants and into distribution pipes serving homes and businesses. The programmable logic controllers sit at every critical junction of that network. Gaining access to one can mean the ability to change passwords, issue commands or attempt to rewrite the controller's operating software.
Attempted access, Akoto notes, can also be part of a longer-term strategy — collecting information, testing defenses or establishing a foothold for a later, more disruptive operation.
---
CEO Times editorial read: The attack surface here was not built by sophisticated adversaries — it was handed to them by bureaucratic inertia. Default passwords on industrial controllers connected to the public internet is not a resource problem; it is a governance failure. America has 152,000 public water systems, most of them lightly staffed and under-resourced, operating critical infrastructure with the digital hygiene of a decade ago. The taxpayer funds these systems. The taxpayer drinks the water. Washington's infrastructure spending debates rarely reach the unglamorous question of whether a pump controller in Plymouth, Minnesota still ships with 'admin/admin.' The market has a word for that kind of risk: unpriced.



