Shielding Water and Wastewater Treatment Facilities from Cyberattacks

10:06:2026

BY Andres Giraldo

Shielding Water and Wastewater Treatment Facilities from Cyberattacks In July 2026, the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) issued a public service announcement (PSA) warning critical infrastructure asset owners and operators of malicious cyber actors conducting coordinated attacks against operational technology (OT) devices.  

The details are worth reading closely because they describe an attack that required neither a zero-day nor sophisticated tooling. The actors reached Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers (PLCs) directly over the internet. They changed the devices’ IP addresses and set new passwords. Operators lost visibility and control of their own equipment. Reported operational effects included loss of pressure and flooding, and at least one utility discovered that its ladder logic had been modified. The FBI noted that while it had observed this activity against the referenced Rockwell PLCs, operators should assume similar exposure applies to other brands. 

Utilities in at least seven states reported incidents to the FBI beginning July 26–27, 2026, Minnesota was hit hardest, with more than 30 community water systems affected. In Georgia, the Clayton County Water Authority which serves roughly 300,000 customers in the Atlanta area saw a drop in water pressure and issued a precautionary boil water advisory before restoring service within hours. 

Shielding Water and Wastewater Treatment Facilities from Cyberattacks

Officials have reported no impact to the safety of drinking water, and there were no widespread supply disruptions. Federal agencies have also not attributed the activity to any named country or group, though press reporting has raised the question. What did happen is that dozens of utilities temporarily lost the ability to see and control the pumps, valves, and chemical feed systems that keep water safe and, in several cases, had to fall back to manual operations to keep running. 

In this post, we’ll dive into what the FBI reported and what it reveals about these attacks. We’ll walk through the mitigation steps federal agencies recommend. And we’ll explore a security solution developed through a collaboration between SealingTech and Nozomi Networks. Designed for critical infrastructure asset owners and operators, the combined technology can help safeguard water and wastewater treatment facilities as well as other critical infrastructure from cyberattacks. 

Securing IT and OT Environments 

The federal guidance from the PSA deserves to be repeated, because it addresses the actual root cause. The FBI, EPA, and CISA recommend: 

  1. Remove PLCs from direct internet exposure. If a controller is reachable from the public internet, it will be found. Search engines for exposed industrial devices index them continuously. 
  2. Change default and shared passwords. Several of these intrusions came down to credentials that shipped with the device. 
  3. Route remote access through a VPN or a hardened gateway rather than exposing the controller itself. 
  4. Know how to run manual. The utilities that fared best had operators who could switch to manual control without a scramble. Practice it before you need it. 
  5. Know what you have. You cannot secure, segment, or report on network assets that have not been inventoried and for most small utilities, the inventory is a spreadsheet that stopped being accurate three integrator visits ago. 

Following the federal guidance results in good cyber hygiene and helps close the front door. However, it does not reveal whether someone is already inside—or whether that door has been propped open again by a maintenance laptop, a new SCADA integration, a vendor’s remote-support tunnel, or a well pump station that received network connectivity last year and never made it onto the network diagram. 

Almost every utility affected in July 2026 had the same underlying gap: no independent, continuous view of what was on the OT network and what changed. Hence, why the disruption was so disorienting. When your PLC stops answering and its IP has changed, the question: “is this a fault or an attack?” takes hours to answer when the only source of truth is the human-machine interface (HMI) that the attacker just took away from you. 

Detection can convert “we think we’re clean” into “we can demonstrate we’re clean.” It shortens the duration between compromise and discovery; it also identifies your internet exposed and end-of-life controllers before an adversary does. Plus, it leaves a forensic record you can hand to the investigators, federal officials, cyber investigators, or your insurer. 

Helping Create a Robust Framework of Protection 

Shielding Water and Wastewater Treatment Facilities from Cyberattacks

SealingTech’s AegisEdge MicroServers, the MS 100 and US 10, provide ultra-compact, flexible defense in operational technology and industrial control systems environments including critical infrastructure.

SealingTech and Nozomi Networks have partnered on a joint solution that runs Nozomi’s Guardian™ security sensor software on SealingTech’s AegisEdge MicroServers. It delivers real-time asset inventory, network visibility, threat detection, and compliance support. 

It is passive. Guardian sits on a mirrored port or a network tap and observes traffic. It does not poll your PLCs, inject packets, or sit inline with a process that has to keep running. For an operations team that has been told “no” to every security tool that might touch the control network, this is the distinction that makes deployment possible. 

Shielding Water and Wastewater Treatment Facilities from Cyberattacks

Water and wastewater treatment facilities in more than a dozen U.S. states faced coordinated cyberattacks in 2026.

It fits where water infrastructure actually lives. A distribution system is not a data center. It is a treatment plant plus dozens of well houses, booster stations, and lift stations. These are unmanned, un-air-conditioned, often with a single Ethernet drop and no spare outlet. We designed the AegisEdge MicroServer line around size, weight, power, and cost (SWaP-C) for exactly this reason. Combining Nozomi’s powerful Guardian platform with our compact US 10 or MS 100 enables operators to detect and remediate threats faster with enhanced network and endpoint visibility with AI-powered analysis and flexible form factor modularity. Both are TAA-compliant, and part of our secure supply chain solutions. 

As IT and OT systems become more interconnected, the boundary between them creates new attack vectors for evolving cyber threats. Federal reporting obligations are tightening. Rules under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) have been expected to be finalized in September 2026, and Safe Drinking Water Act (SDWA) requirements already apply. Utilities should review what they would be required to report, and to whom, in the first 72 hours of an incident. Accurate asset inventory is a prerequisite for reporting anything credible, which makes visibility a compliance investment as much as a security one. 

Enhancing Visibility Where It Matters Most 

Water and wastewater treatment facilities, energy grids, agricultural sites, transportation systems, communication networks, healthcare facilities, and defense systems are all at risk. 

SealingTech’s and Nozomi’s joint solution was built to close that visibility gap. Guardian’s AI-powered threat detection running on SealingTech’s compact, flexible AegisEdge hardware, provides OT operators the visibility they need to catch these threats early on and help keep the water flowing safely for everyone’s safety. 

Learn more about SealingTech’s and Nozomi’s joint solution. Contact a team member. 

Interested in taking a deeper dive into how SealingTech can help safeguard critical infrastructure? Download our white paper: AegisEdge MicroServers: Compact, Proactive OT Cyber defense. 

Resource: 

Get ultra-compact flexible OT defense that fits in the palm of your hand. See how by previewing our AegisEdge MicroServers video.

 

Related Articles

Describe, Don’t Script: A New Mindset for Testing AI

Typical software testing entails specifying exact inputs and expected outputs. However, that approach falls short with non-deterministic AI(opens in new tab) which can deliver different outputs in different runs even with the same input. General randomness, probabilistic…

Learn More

Adaptable Technology Trusted to Solve Customer Challenges Industry-Wide

SealingTech’s high-performance products and innovative solutions are built to perform across diverse missions, industries, and applications. Designed and assembled in Maryland, our platforms’ proven capabilities and reliability has made SealingTech a trusted cyber defense hardware provider of the U.S. Federal Government.  Though we’ve built our reputation…

Learn More

Two Journeys of Growth: Our SealingTech CASTLE Internship Experience

This summer, I have had the privilege of interning at SealingTech through its Cyber Advancement for Students, Leaders, and Engineers (CASTLE) Program along with fellow college undergrad, Eugene Cho. Under…

Learn More

Could your news use a jolt?

Find out what’s happening across the cyber landscape every month with The Lightning Report. 

Be privy to the latest trends and evolutions, along with strategies to safeguard your government agency or enterprise from cyber threats. Subscribe now.