Cyberattacks on Critical Infrastructure Control Systems
Pro-Kremlin cybercrime network NoName

Cyberattacks on Critical Infrastructure Control Systems

3Si Analyst Team in Canada
Aug 10, 2026 Special Security Report

Between Jul 28 and Jul 31, 2026, hackers accessed systems that manage drinking water across the United States. Utilities in at least twelve states found that intruders had accessed the internet-connected controllers that operate pumps and valves, and several were forced to abandon their digital controls and run operations by hand. The water stayed safe to drink, but the attack showed how directly a remote intrusion can now touch physical infrastructure. This week's read looks at why these attacks differ from ordinary data breaches, what the recent cases reveal, and what they mean for any organization that depends on operational technology or on the utilities that rely on it.

Why This Is Different from a Data Breach

Most cyber incidents involve information exposure, such as records that are copied, encrypted for ransom, or posted online. An attack on operational technology (OT), the computers and controllers that run physical equipment, is a different problem, because the target is the machinery itself. In the water sector, that means the pumps, valves, pressure controls, and chemical dosing systems that treat and deliver water. When an intruder reaches those systems, they can change how the equipment behaves, which makes the potential consequences physical.

The notable part of these incidents is how the intruders got in. In the recent cases, the entry point was not a sophisticated operation, but internet-facing controllers left reachable from the open web, often protected by default or weak passwords. The Federal Bureau of Investigation (FBI) and the United States Environmental Protection Agency (EPA) reported that attackers accessed Rockwell Automation controllers and changed their addresses and passwords.

Staffing decisions also compounded the vulnerability of those devices. Some small-town utilities operate with only two or three staff, who take laptops home so they can respond to an emergency at any hour. Those personal and home devices became part of the exposure, because a compromised operator laptop can give an attacker the remote foothold needed to reach the control systems.

What the Recent Cases Show

Minnesota was hit hardest, with disruptions across more than 30 municipal water systems, and the number of affected states rose from seven to at least twelve within a week. Federal investigators have pointed to tradecraft consistent with earlier Iranian-linked operations, in particular a 2023 campaign by a group known as the CyberAv3ngers. In each case the pattern was similar: exposed controllers, altered settings, and utilities reverting to manual operation to stay in control.

Canada has seen the same category of attack. According to the Communications Security Establishment (CSE), in Oct 2025 the Russian cybercriminal group "NoName" infiltrated a municipal water treatment facility in Quebec and gained the ability to manipulate pumps, chlorine dosing, pressure controls, and monitoring equipment. The Canadian Centre for Cyber Security has assessed that the cyber threat to the country's critical infrastructure is almost certainly increasing.

What This Means for Businesses Across Sectors

Water is the most current example, but the exposure is far broader. Operational technology runs manufacturing lines, building systems, energy and pipeline operations, logistics, and healthcare equipment, and much of it was designed for reliability rather than for defence against remote attack. Any organization with internet-connected controllers, weak separation between its business and control networks, or weak credentials shares the same vulnerabilities as the water utilities.

There is also a second-order exposure for organizations that do not run this equipment themselves. A business depends on water, power, and communications whether or not it operates them, so an attack on a utility can halt work well beyond the utility's own business operations. Continuity planning that assumes these services are always available is risky.

The Role of Digital Investigative Intelligence

Digital investigative intelligence helps in two ways here. The first is visibility of exposure: the same open-source methods attackers use to find internet-facing controllers can be used defensively to identify which of an organization's systems are reachable from the open web before someone else finds them. The second is early warning. Threat actors, particularly hacktivist and state-linked groups, often announce targets, claim credit, and signal intent on public and semi-public channels. Monitoring that activity, along with sector-wide targeting patterns, gives security teams time to check their own exposure when a campaign begins to move through an industry.

Conclusion

The water-system attacks are a reminder that the distance between a remote intruder and physical infrastructure has narrowed. The fixes are largely basic: take control systems off the open internet, replace default passwords, separate business and control networks, and keep the ability to run critical operations manually. These attacks sit at the nexus of geopolitical conflicts and weak security hygiene; while an organization cannot change the former, it can control the latter.


About 3Si Risk Strategies

3Si provides security and emergency management consulting, threat risk assessments, security planning, and public safety advisory services.

Learn more about our services or contact our team.