Recent Cyberattacks on U.S. Water Systems Highlight Need for Cybersecurity Professionals

August 10, 2026
Cyberattacks on Water Systems. reewungjunerr. AdobeStock
reewungjunerr/AdobeStock

 

 

The FBI and EPA issued a joint public service announcement warning that malicious actors were disrupting water and wastewater utilities. Since July 27, facilities in at least seven states have reported cyber incidents that have disrupted or degraded operations.

The wave began when more than 30 Minnesota water systems were hit in a coordinated strike. Reports in Michigan and Georgia followed. The pattern put officials across multiple states on edge. Despite the attack, no drinking water contamination has been yet reported. Utility workers were forced to keep the pumps running by hand until authorized control was restored.

These incidents underscore how vulnerable critical infrastructure remains to cyber threats and the growing need for cybersecurity professionals who can keep these essential systems safe.

Why Water Systems are Cyber Targets

Water treatment plants are largely driven by programmable logic controllers (PLCs). These small, rugged computers open valves, run pumps, and monitor water pressure automatically. Many modern PLCs are connected to networks and IoT-enabled systems, creating potential pathways for attackers to reach the operational technology that controls critical infrastructure.

According to the FBI, cyber-attackers went after specific internet-facing Rockwell Automation controllers and changed IP addresses and passwords. This locked operators out of their own equipment while the machinery kept running, and normal mechanisms were still on the network, but invisible to the people authorized to control them.

Water is what security experts call “lifeline infrastructure”—a system that, if disrupted, can cause immediate and serious issues across sectors, especially for public health and safety. Healthcare facilities depend on a reliable supply of clean water for patient care, sanitation, sterilization, food service, cooling systems, and other essential operations. Manufacturing, emergency services, data centers, and other critical industries also rely on water to remain operational. That broad dependence, combined with the increasing connectivity of water systems, makes them an appealing target for nation-state actors and cybercriminals. This has led the EPA to flag water systems as attractive cyberattack targets.

Complicating this challenge is that many utilities are small and locally run. While the threat is on a national scale, the responsibility for defending it is often local. More than 90% of U.S. drinking-water systems are dedicated to serve fewer than 10,000 people, with many operating on limited financial, technical, and staffing resources.

How Cybersecurity Professionals Protect Critical Infrastructure

Defending water systems requires a layered approach that protects both the digital networks and the physical processes they control. Utilities divisions can reduce risk by securing internet-facing systems and PLCs, segmenting operational technology from business networks, enforcing strong authentication and access controls, keeping software and firmware updated, and continuously monitoring for suspicious activity. Just as important is having trained cybersecurity professionals who understand both IT and operational technology and can respond quickly when an attack occurs.

The Bureau of Labor Statistics projects 29% growth for information security analysts through 2034, adding roughly 52,100 jobs and pacing far ahead of the average for all occupations. The median salary sat at nearly $125,000 in 2024, with about 16,000 openings expected every subsequent year.

Demand, meanwhile, keeps outpacing supply. Industry researchers estimate a global workforce gap of roughly 4.8 million cybersecurity professionals. Critical infrastructure sectors are among the fastest-growing areas of the hiring market as attacks like these accelerate.

Certified professionals typically command higher pay than uncertified peers or those without an accredited degree. In regulated environments like water and energy, certifications and degrees increasingly serve as a signal of trust, expertise, and authority.

Education to Defend Critical Infrastructure

Those who thrive in cybersecurity possess hands-on experience with technology, whether they’ve wired a PLC or built a simulated electrical network. The strongest education branches classroom learning to real-world applications.

At Capitol Technology University, students pursue this hands-on work through labs, internships, and research projects. Our students are some of the most sought-after employees for defense contractors and agencies across the Washington–Baltimore corridor and beyond. Our alumni go on to build careers with leading technology companies, establishing themselves as founders, technicians, speakers, adjunct faculty, and more.

Capitol Technology University has been educating cybersecurity professionals for more than 25 years and is designated by the National Security Agency (NSA) as a National Center of Academic Excellence in Cyber Defense (NCAE-CD). Through our Bachelor of Science in Cybersecurity, students build the technical knowledge and skills needed to succeed in cybersecurity and critical infrastructure fields.

Explore what a degree from Capitol Tech can do for you! To learn more, contact our Admissions team or request more information.

 

Written by Jordan Ford 
Edited by Erica Decker