Skip to main content

August 2026

Page 1

Utilities Section

Newsletter League of Nebraska Municipalities

August 2026

Hackers Hit U.S. Water Systems: Why recent cyberattacks are a wake-up call for critical infrastructure By Lockton Cyber & Technology Practice; August 2026 A series of coordinated cyberattacks targeting municipal water systems across the United States has renewed concerns about the vulnerability of critical infrastructure. Although no drinking water contamination was reported, the incidents demonstrated how cybercriminals can disrupt essential public services by compromising operational technology (OT) systems that manage water treatment and distribution. Between July 26 and 27, 2026, more than 30 municipal water systems in Minnesota experienced cyberrelated disruptions. Communities including Braham, Plymouth, South St. Paul, and Maple Plain reported issues affecting automated water and wastewater operations. Federal cybersecurity officials reported that attackers gained access to programmable logic controllers (PLCs), the industrial computers responsible for critical infrastructure processes. In several cases, operators were locked out after passwords were modified. Importantly, water quality was not affected, and operators maintained service through manual controls and contingency procedures. While no organization has officially

1335 L Street Lincoln, NE 68508 (402) 476-2829 info@lonm.org

been identified as responsible, preliminary assessments suggested a possible connection to Iranian-linked threat actors. No ransom demand was reported, indicating disruption rather than financial gain may have been the objective. The response quickly expanded to include state and federal agencies. Minnesota activated a statewide cybersecurity response, while the FBI and EPA issued nationwide warnings to water utilities. The broader lesson extends well beyond the water sector: attackers do not need to physically damage infrastructure to create significant operational disruption. Gaining access to OT environments and denying legitimate access can interrupt services and trigger emergency response actions. For executives and risk managers, these events are a timely reminder that cyber risk is business risk. As threat actors increasingly target operational technology and critical infrastructure, organizations must ensure their security controls, recovery capabilities, and insurance programs keep pace with the evolving threat landscape.

Key Steps to Reduce OT Cyber Risk • Isolate operational technology from the public internet wherever possible. • Eliminate default credentials and strengthen authentication controls. • Review and validate remote access and third-party connections. • Maintain tested manual and business continuity procedures. • Ensure incident response plans address operational technology environments. What Organizations Can Do Any organization that relies on industrial control systems should use this incident as an opportunity to reassess core cyber controls. The following measures remain among the most effective ways to prevent these events or limit their impact: • Segment IT and OT networks to reduce the likelihood of a compromise spreading into operational systems. • Require MFA for all remote access, particularly connections into OT environments. • Strengthen privileged access controls by restricting admin rights, rotating credentials, and eliminating shared or default passwords. Continued on page 2

Lash Chaffin Utilities Section Director Jackson Sash Utilities Field Representative


Turn static files into dynamic content formats.

Create a flipbook