When the Control Room Goes Dark: Security lessons from the 2026 Water Utility Attacks

A water treatment plant

When automation fails at a water or power facility, the fallback is people: operators who can run the plant by hand, and security teams who can protect them while they do it.

The 2026 water-sector attacks showed what this looks like in practice. Attackers targeted internet-facing programmable logic controllers (PLCs), affecting monitoring or control functions at some facilities. Utilities that could shift safely to manual operations limited the operational consequences. The lesson extends beyond water systems to electric, gas, and renewable operators with remote or lightly staffed sites.
 

What happened this summer

A Prosegur Security client interacting with a biometric access control system

In late July, Minnesota authorities disclosed a coordinated attack on more than 30 community water systems. [1] In the following weeks, additional incidents emerged in other states, and security researchers tracked affected utilities in at least 12. Reporting was still incomplete, so the full scope remained uncertain. [2]

A July 30 FBI and EPA alert said actors had remotely accessed internet-facing PLCs, changed IP addresses and passwords, and caused loss of monitoring and control functionality. The alert reported operational effects including pressure loss and flooding, and emphasized that a utility's ability to switch to manual operations shaped the impact. [3]

The most serious reported consequence was in Georgia, where the Clayton County Water Authority experienced a pressure drop that led to a boil-water advisory for about 300,000 customers. Service was restored within hours. [2]

Exposure remains a key risk factor. Forescout found more than 2,800 internet-exposed controllers in the United States of the type targeted in the attacks. Exposure alone does not establish compromise, but it expands the attack surface and should be addressed through secure, mediated remote access and strong access controls. [4]
 

 

Why manual fallback depends on people on site

A prosegur security officer

"Switch to manual" sounds simple. In practice, it means a utility has to put qualified people at facilities that were designed to run without them, often at night and with little warning.

Many modern sites are lightly staffed or unmanned. A pump station may see a crew once a week. A substation or solar array may go months between visits. When remote control is lost, those sites suddenly need someone to open valves, read gauges, check chemical levels and confirm that equipment is doing what the screen used to say it was doing.

That creates three problems at once.

  • Operators are stretched thin. A small utility may have only a few licensed operators. Sending them to multiple sites at once leaves each one working alone, focused on the process rather than on who else is around.
  • The site itself becomes a question mark. If the network was compromised, was the site also visited? A cut lock, an open cabinet or an unfamiliar vehicle can be the first sign that a cyber incident has a physical side, or that someone is using the confusion as cover.
  • Evidence starts disappearing. Every hour of manual operation without clear logs makes it harder to reconstruct what happened, satisfy regulators and file insurance claims.

Trained security personnel do not replace operators. Their job is to make it possible for operators to do theirs: securing the perimeter, controlling who enters, escorting crews, watching for anything out of place and documenting every movement on site.
 

 

How the layers work together during an incident

A power outage situation

The strongest response comes from three layers that share information in real time: OT threat monitoring on the network, a remote security operations center watching the sites, and officers who can be physically present. Here is how that looks in a scenario like this summer's.

Detection. OT managed detection and response (MDR) flags something unusual: a login to a PLC from an unfamiliar address, a configuration change outside a maintenance window, or controllers going silent. Analysts confirm it is not routine and alert the utility's operations team.

Correlation. The same alert goes to the security operations center watching the utility's cameras, alarms and access control. Operators there check the affected sites. Has anyone badged in? Is a gate open? Is there a vehicle near the fence line? This step answers a key question early: is this purely a network event, or is someone on site?

Deployment. As the utility moves to manual operations, officers are dispatched or redeployed to the sites that need people. They secure the perimeter before crews arrive, verify the identity of everyone entering and stay with operators while they work.

Operation. For the hours or days of manual running, the remote center keeps watching every site, including the ones without officers. It relays anything unusual to officers and operators. On the network side, MDR analysts track the attacker's footprint and support the utility's recovery.

Recovery and documentation. Access records, camera footage, officer logs and network data come together in one timeline. That record supports the investigation, regulatory reporting, NERC CIP evidence where it applies, and insurance claims.

The value is not in any one layer. It is in the handoffs. When these functions sit with separate vendors that rarely talk to each other, each handoff is a delay. That is why Prosegur runs guarding, iSOC remote monitoring and cybersecurity services as one coordinated operation.
 

Phase

OT MDR

iSOC

On-site officers

DetectionSpots anomalous controller activityReceives alert, checks site statusOn standby
CorrelationScopes affected devicesReviews cameras, alarms, badge logsChecks nearest sites if staffed
DeploymentAdvises on containmentCoordinates dispatchSecures sites, controls entry
OperationTracks attacker activityWatches all sites continuouslyEscorts crews, patrols, logs activity
RecoverySupports restorationCompiles video and alarm recordsHands over logs and observations
 

Lessons for every utility

A Prosegur Security officer on patrol

Water systems made headlines this summer, but the same questions apply to electric, gas and renewable operators. A few practical steps stand out.

  1. Find and close internet-exposed controllers. Many of this summer's intrusions started with devices reachable from the open internet, often with default or shared passwords. Knowing what is exposed is the first step.
  2. Write down the manual fallback plan, including security. Most utilities know which sites need people if automation fails. Fewer have planned who secures those sites, how quickly they can arrive and who controls entry.
  3. Rehearse it. Run a tabletop or field exercise that starts with a cyber alert and ends with crews operating sites by hand. Include operations, IT, OT and physical security in the same room.
  4. Connect cyber and physical alerts. Make sure a network alert at a site automatically prompts a check of that site's cameras, alarms and access logs, and the other way around.
  5. Control vendor and contractor access. Remote vendor connections and unescorted contractors are common entry points. For electric utilities, NERC CIP-003-9 now requires controls on vendor remote access even at low-impact sites.
  6. Keep one record. Plan now for how access logs, officer reports, video and network data will come together into a single incident timeline.

None of these steps require a major overhaul. They require the people responsible for cyber, physical security and operations to plan together before the next incident rather than during it.
 

 

The takeaway

This summer's attacks showed that automation can be taken away quickly, and that the fallback is always people. Utilities that kept water flowing had operators ready to work by hand. The next step is making sure those operators are protected, supported and able to focus on the process while someone else watches the perimeter and the network.

If you are reviewing your own fallback plans, you can learn more about how Prosegur supports energy and utility security for critical infrastructure, including on-site officers, 24/7 remote monitoring and cyber-physical security services.

 

Sources

  1. Minnesota IT Services. "MNIT activates statewide cybersecurity response to support affected communities and protect critical infrastructure." July 28, 2026.
  2. Tenable Research Special Operations. "Coordinated cyberattack on Minnesota water utilities: What you need to know." August 2026.
  3. Federal Bureau of Investigation and Environmental Protection Agency. "Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions." FBI PSA I-073026-PSA, July 30, 2026.
  4. Forescout Vedere Labs. "OT Security Analysis: Exposed Devices Attacked in US Water Systems." August 5, 2026.
  5. North American Electric Reliability Corporation. "CIP-003-9: Cyber Security—Security Management Controls." Mandatory subject to enforcement April 1, 2026.


Stay updated with the latest security trends and analyses by following Prosegur's blog.