Close Menu
  • Breaking News
  • Business
  • Personal Finance
  • 2nd Amendment
  • Videos
  • Forum
  • More
    • Prepping & Survival
    • Health
    • Top Stocks
    • Stocks Portfolio

Subscribe to Updates

Get the latest news and updates directly to your inbox.

Popular Now
Jeff Bridges nearly played John Dutton before Kevin Costner landed ‘Yellowstone’ role Breaking News

Jeff Bridges nearly played John Dutton before Kevin Costner landed ‘Yellowstone’ role

By Dewey LewisAugust 6, 20260

NEWYou can now listen to Fox News articles! Jeff Bridges came close to ruling the…

WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

August 6, 2026
Twelve States Now Hit in attack on America’s Drinking Water

Twelve States Now Hit in attack on America’s Drinking Water

August 6, 2026
FDA approves first-ever mRNA flu vaccine for millions of older Americans

FDA approves first-ever mRNA flu vaccine for millions of older Americans

August 6, 2026
Facebook X (Twitter) Instagram
Trending
  • Jeff Bridges nearly played John Dutton before Kevin Costner landed ‘Yellowstone’ role
  • WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways
  • Twelve States Now Hit in attack on America’s Drinking Water
  • FDA approves first-ever mRNA flu vaccine for millions of older Americans
  • SEE IT: Mamdani booed off stage at New York City pro-police celebration: ‘Walked off in shame’
  • Preakness Stakes moves to a Sunday for the first time ever in major Triple Crown shakeup
  • ‘Absolute Cutest and Youngest of Our Drag Performers’
  • The Romeo Gen-2s – Which is Better?
Facebook X (Twitter) Instagram LinkedIn VKontakte
Thursday, August 6
Republican Investor
Banner
  • Breaking News
  • Business
  • Personal Finance
  • 2nd Amendment
  • Videos
  • Forum
  • More
    • Prepping & Survival
    • Health
    • Top Stocks
    • Stocks Portfolio
Subscribe
Republican Investor
You are at:Home » Twelve States Now Hit in attack on America’s Drinking Water
2nd Amendment

Twelve States Now Hit in attack on America’s Drinking Water

Press RoomBy Press RoomAugust 6, 2026No Comments16 Mins Read
Facebook Twitter LinkedIn Tumblr Reddit WhatsApp
Twelve States Now Hit in attack on America’s Drinking Water
Share
Facebook Twitter LinkedIn Pinterest Email

New Jersey confirmed Wednesday that two municipal water systems were hit by cyberattacks involving internet-exposed industrial control systems. Operators temporarily lost the ability to remotely monitor or manage parts of their plants and were forced to switch to manual operations.

According to the state, water service was not interrupted and the drinking water remained safe. Nobody got sick, nobody lost water, and employees at both utilities were able to keep the systems running.

That is the good news.

The bad news is that New Jersey passed one of the toughest water cybersecurity laws in the country nearly a decade ago. The state required water utilities to create cybersecurity programs, report incidents, carry cyber insurance and follow established security standards. Yet in August 2026, two municipal systems were apparently still running critical control equipment that could be reached from the public internet.

A suspected foreign cyber operation did not defeat some impenetrable military network. It found equipment that never should have been publicly accessible in the first place.

Two Water Systems Were Hit, but the State Will Not Tell Residents Which Ones

The New Jersey Cybersecurity and Communications Integration Cell responded to both attacks and is now working with the FBI and the Cybersecurity and Infrastructure Security Agency. NJCCIC chief Christopher Thoresen said employees at the affected utilities moved quickly to manual operations and that stronger access controls have since been put in place.

The state has not identified either utility.

That means New Jersey residents do not know whether their own water system was compromised. They are expected to accept assurances that everything remained safe without being told where the attacks happened, how long the attackers had access or exactly what equipment they reached.

Sources speaking to ABC News and 6abc said Iran remains the leading suspect, although the campaign has not been formally attributed. Investigators are reportedly considering whether another country could be copying Iranian methods to disguise its involvement.

New Jersey Already Had a Law Against This

New Jersey’s Water Quality Accountability Act was signed in 2017 and later strengthened in 2021. According to the New Jersey Department of Environmental Protection, the law applies to public water systems with more than 500 service connections, covering roughly 300 systems across the state.

The requirements were not vague.

Utilities were required to develop or update formal cybersecurity programs based on recognized standards such as the NIST Cybersecurity Framework, the CIS Critical Security Controls or the ISO 27000 standards. They had to submit those programs to the state, promptly report cyber incidents and maintain cybersecurity insurance.

The deadline for updated cybersecurity programs was May 7, 2022.

Four years later, New Jersey announced that two municipal utilities were compromised through internet-exposed control systems. Preventing public exposure of industrial equipment is not some obscure technical recommendation buried inside a 500-page manual. It is basic security. Any legitimate cybersecurity review should have identified it immediately.

That leaves only a handful of possibilities. The utilities submitted security plans they were not actually following. Their filings did not accurately describe their networks. The state never checked whether the plans matched reality. Or somebody discovered the exposure and decided convenience was more important than fixing it.

None of those explanations should make New Jersey residents feel better.

The state can point to its law, its standards and its compliance deadlines all it wants. If nobody verifies what is actually connected to the internet, the entire system becomes a paperwork exercise. A security plan sitting in a government filing cabinet does not protect a pump station.

Thousands of Industrial Controllers Are Still Sitting on the Open Internet

The equipment targeted in these attacks includes programmable logic controllers, commonly known as PLCs. These devices control physical processes inside water plants, factories, power systems and other critical infrastructure.

A PLC might monitor water pressure, operate a pump, open a valve or control the amount of treatment chemical being added to the system. It is not simply an office computer holding emails and spreadsheets. It is connected to machinery that can affect water pressure, treatment and distribution.

Georgia Tech cybersecurity professor Saman Zonouz compared the devices to industrial versions of household thermostats. A thermostat measures temperature and decides whether to run the air conditioner. A water-system controller measures pressure or chemical levels and decides whether to run equipment.

The concept is simple. The consequences of a bad command are not.

Zonouz and his research team searched for industrial controllers that could be reached directly from the public internet. They reportedly found more than 7,000 of them across water systems, hospitals, airports, energy infrastructure and military facilities.

The researchers contacted the owners and warned them that the equipment was exposed. Only about 30 percent removed the devices from the public internet.

That means roughly seven out of ten apparently did nothing, even after researchers showed them where the vulnerability was.

Zonouz said many of the devices could be accessed using default usernames and passwords that had never been changed. In other cases, dozens of controllers at the same facility were protected with the same password.

This is not some elite hacker burning through a billion-dollar security system. It is the industrial equivalent of leaving the key in the front door because walking across the room to unlock it every day would be inconvenient.

The FBI warned on July 30 that attackers were targeting Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 controllers. According to the bureau, utilities in at least seven states had reported incidents since July 27, with some attacks degrading water operations.

Attackers were reportedly changing passwords and network settings, causing operators to lose visibility and, in some cases, control over connected equipment. The disruptions included pressure loss and flooding. CISA also warned that Schneider Electric and Siemens controllers were being targeted.

The companies and model numbers may differ, but the pattern is the same: find an exposed controller, try the factory password and see what happens.

The Attacks Have Now Reached Twelve States

When we first reported on the attacks in Minnesota, more than 30 water systems in that state had reportedly been targeted. The FBI later said the campaign had reached at least seven states.

The number has now reportedly climbed to twelve.

Minnesota, Michigan, Wisconsin, Georgia and New Jersey have been publicly identified. The remaining states have not. Federal officials have also refused to identify most of the individual utilities that were compromised.

That secrecy leaves residents guessing about whether their own water system was involved, while the agencies responsible for protecting critical infrastructure hide behind vague statements about ongoing investigations.

This is no longer an isolated attack against one poorly secured town. It is a national campaign scanning the internet for exposed industrial equipment and testing whatever it finds.

The United States has more than 150,000 drinking water and wastewater systems, many of them serving small towns with limited budgets and only a few employees. These systems often rely on old equipment, outside contractors and remote monitoring because they cannot afford to keep a full staff at every facility around the clock.

Attackers do not need to carefully choose each town. They can scan the internet, locate exposed controllers and work through the list. Whether your community gets hit may come down to whether somebody connected a controller to the internet five years ago so an employee would not have to drive across town to check it.

In Georgia, a Water Outage Was Treated Like a Routine Pump Failure

Georgia showed how easily a cyberattack can be mistaken for an ordinary equipment problem.

At approximately 1 a.m. on July 27, a pump station serving northern Clayton County failed. Customers in Forest Park, Lake City, College Park and Morrow woke up to low pressure or no water. Crews restored pressure several hours later, and the Clayton County Water Authority issued a precautionary boil-water advisory.

Testing came back clean, and the advisory was lifted the following day.

For nearly a week, the incident appeared to be a routine pump failure. Then, on August 3, the water authority announced that it was investigating unauthorized cyber activity that may have caused or contributed to the outage. The investigation centered on the system’s programmable logic controllers.

About 90 miles away, Columbus Water Works confirmed that it had also been targeted on July 27. CISA alerted the utility to suspicious activity, operators switched from automatic to manual controls and officials said the water and infrastructure remained safe.

In both cases, employees were able to regain control. But Clayton County residents spent days believing a pump had simply broken before learning that the outage might have been connected to a multistate cyberattack.

That distinction matters.

Most people never think about what happens inside a water treatment plant. They turn the faucet, water comes out and they assume somebody competent is watching the system. That trust is part of what makes a modern society function.

When officials conceal the location and details of attacks, that trust begins to disappear. Residents are left wondering whether the system is safe, whether officials are telling the truth and whether the next warning will arrive before or after the water stops flowing.

The Real Defense Was an Employee Who Knew How to Run the Plant by Hand

Look at what prevented these attacks from becoming larger emergencies.

In New Jersey, employees switched to manual operations. In Columbus, operators took automated equipment offline and ran the system manually. In Clayton County, workers identified the problem and restored water pressure. In Minnesota, a technician walking through a facility noticed that the tower was calling for water but the pumps were not responding.

There was no magical federal cyber shield protecting these communities. There was no automated system that instantly blocked the attackers. The final line of defense was a human being who understood the equipment well enough to recognize that something was wrong and knew how to operate the plant without relying entirely on a computer screen.

Those employees deserve credit, but this is an incredibly thin margin of safety.

Water systems have spent years reducing staffing and installing remote monitoring because it is cheaper than keeping experienced operators physically present. The same remote access that allowed municipalities to cut costs is now providing attackers with a path into the system.

Every dollar saved by connecting an industrial controller to the internet instead of staffing a shift created a vulnerability. Communities are now finding out what those savings actually cost.

Every water utility in the country should be required to answer a basic question: Can this plant continue operating for at least 24 hours with every computer and remote connection turned off?

If the answer is no, then the computer system is not merely helping run the plant. The computer system has become the plant, and whoever controls it controls the water.

The EPA Says Local Water Systems Need to Take Responsibility

EPA Administrator Lee Zeldin responded to the attacks by pointing to the responsibility of private companies, municipal water systems and state governments. According to TIME, an EPA spokesperson referred reporters to those comments when asked about the federal agency’s role.

That may sound reasonable until you look at what a small-town water department actually is.

In thousands of American communities, the water department consists of a few employees responsible for repairing broken mains, reading meters, testing water and maintaining equipment that may have been installed decades ago. Their annual cybersecurity budget may be close to zero. Some are running controllers that are no longer supported by the manufacturer.

Replacing those systems is not as simple as buying a new laptop. It can require new controllers, outside engineers, network redesigns, equipment shutdowns and employee training. Small towns often do not have the money or technical staff to handle that alone.

Yet these same communities are now expected to defend themselves against foreign intelligence services and organized cyber operations.

Calling that “individual responsibility” is not a strategy. It is a federal agency distancing itself from the problem so it can blame local officials after somebody gets hurt.

CISA issued a warning about attacks against industrial controllers only days before this campaign began. The warning was timely and specific, but it landed in an industry where thousands of systems lack the staff, funding or authority to make major security changes.

The government warned them. Then it left them to figure it out on their own.

Water Infrastructure Still Has No Real Cybersecurity Enforcement

The electric grid operates under mandatory federal cybersecurity standards backed by inspections and financial penalties. The water sector largely operates under advisories, voluntary guidelines and repeated warnings.

The EPA’s own inspector general reviewed the public-facing networks of 1,062 drinking water systems serving more than 193 million people. The investigation found 97 systems with critical or high-risk cybersecurity vulnerabilities. Those systems serve approximately 26.6 million Americans.

That report was published in 2024.

Researchers later found thousands of industrial controllers exposed to the public internet and directly warned the organizations responsible for them. Most did not remove the equipment.

New Jersey attempted to address the problem with a state law, but the latest attacks show why passing a mandate is not enough. A water utility can submit a cybersecurity plan, buy an insurance policy and check every required box while still leaving a controller exposed to the internet.

Real enforcement would require somebody to verify the claims. Inspectors would need to scan networks from the outside, physically examine control systems, test whether default passwords are still being used and impose consequences when utilities refuse to fix obvious vulnerabilities.

Instead, government agencies keep releasing reports documenting the same failures year after year. Everybody acknowledges that the systems are exposed, and almost nobody forces the operators to secure them.

Then the attack happens, officials praise the employees who kept the plant running manually, and the government acts as though the system worked.

It did not work. The attackers got in.

The Immediate Risk Is Pressure Loss, Not a Hacker Pouring Poison Into a Tank

The most realistic danger from these attacks is not some movie scenario where a hacker instantly poisons an entire city. It is the loss of pressure, visibility and control.

Municipal water systems maintain positive pressure to keep contaminants outside the pipes. When pressure falls far enough, groundwater, sewage and other material surrounding cracked pipes or bad connections can be pulled into the system.

That is why utilities issue boil-water advisories after major pressure drops. The advisory does not necessarily mean contamination has been found. It means the conditions existed for contamination to enter.

Boiling water can kill bacteria, viruses and parasites. It does not remove fuel, pesticides, solvents, heavy metals or many other chemical contaminants. In some cases, boiling can make chemical contamination worse by evaporating water and concentrating whatever remains.

A camping filter designed to remove sediment and parasites is not automatically capable of handling chemicals. People need to understand what their equipment can and cannot do before an emergency.

When officials cannot immediately explain why the pressure dropped, guessing with the wrong filter is not a preparedness plan.

What You Should Do Before Your Local System Gets Hit

Store water now, not after the pressure disappears.

The standard minimum is one gallon per person per day for drinking and basic sanitation. Two weeks is a far more useful target, especially in hot climates or households with children, medical needs or animals.

  • Learn where the water inside your home is located. A typical water heater may hold 40 to 50 gallons. That water can be accessed through the drain valve near the bottom, provided contaminated water has not already entered the home’s plumbing. At the first credible warning of a system failure, fill bathtubs, pots and clean containers while pressure is still available.
  • Sign up for alerts from your local utility and find out how those alerts are actually delivered. Some systems rely heavily on Facebook posts or local news coverage. Keep a battery-powered radio and know which local stations carry emergency information.
  • Most importantly, stop assuming that a modern-looking utility has a secure network. Ask whether the plant can operate manually, whether employees are trained to run it without remote access and whether its industrial control equipment is exposed to the internet.

You may not get a useful answer, but the question needs to be asked.

Every Agency Warned About This Before It Happened

The EPA warned that water systems were vulnerable. Its inspector general identified critical weaknesses affecting systems serving tens of millions of Americans. CISA warned that foreign-linked attackers were targeting internet-connected industrial controllers. Georgia Tech researchers found thousands of exposed devices and personally notified the owners.

New Jersey passed a law, named recognized security standards and established hard compliance deadlines.

The warnings were issued. The reports were published. The deadlines passed.

Two New Jersey water systems were still connected to the public internet when somebody reached through those connections and blinded the operators.

The attacks have now reached twelve states, yet the federal government refuses to identify most of the affected utilities. Residents in Georgia spent nearly a week believing a pump had simply failed. The EPA says local systems have their own responsibilities, while small-town water departments are left to defend themselves against foreign cyber operations with outdated equipment and limited budgets.

The only reason this story is still about temporary outages and boil-water advisories is that operators in New Jersey, Georgia and Minnesota recognized the problem and knew how to run their equipment by hand.

That is not a national cybersecurity strategy. It is luck wearing a work uniform.

The next operator may not catch it in time. The next attacker may alter the alarms so everything looks normal while pressure drops. The next community may stay offline long enough for contamination to enter the distribution system.

When that happens, nobody is going to care how many cybersecurity frameworks were listed in a compliance filing or how many warnings the government posted online. They are going to need clean water.

By then, the only water you can completely trust may be the water you stored before the screens went dark.

Preparedness Resources

Start with a serious long-term water storage plan. One gallon per person per day is the minimum, two weeks is a more realistic goal and households in extreme heat should store more.

Review your water filtration and purification options and make sure you understand the difference between equipment designed for biological contamination and systems capable of reducing chemicals or heavy metals.

Identify alternative sources before you need them. That may include rainwater collection, a permitted well or nearby natural water sources you have already mapped and inspected. Our guide to finding food and water during a long-term urban disaster covers additional options.

Finally, build a reliable local information network. Utility alerts, battery radios, scanners and direct contact with neighbors can provide information long before a generic national news report. Read our guide to situational intelligence during a crisis for more on monitoring developing threats.

Related coverage:

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFDA approves first-ever mRNA flu vaccine for millions of older Americans
Next Article WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

Related Posts

Federal Court Strikes Major Blow Against National Firearms Act in FPC-Backed Lawsuit

Federal Court Strikes Major Blow Against National Firearms Act in FPC-Backed Lawsuit

August 5, 2026
FPC Moves to Block California’s “Glock Ban”

FPC Moves to Block California’s “Glock Ban”

August 4, 2026
Open AI Sam Altman Describes the World He Is Building for You

Open AI Sam Altman Describes the World He Is Building for You

August 2, 2026
Hacks Water Plants in attempt to Poison Water in 7 States

Hacks Water Plants in attempt to Poison Water in 7 States

August 1, 2026
The Federal Government Is Buying Pieces of Private Companies While the Cult Cheers

The Federal Government Is Buying Pieces of Private Companies While the Cult Cheers

July 31, 2026
Twelve States Now Hit in attack on America’s Drinking Water

Cyberattack Hits 30 Minnesota Water Systems as FBI Warns Attacks Have Spread Across Seven States

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Follow us
  • Facebook
  • Twitter
  • Instagram
  • Pinterest
Highlights
WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways Breaking News

WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

By Dewey LewisAugust 6, 20260

NEWYou can now listen to Fox News articles! A shocking dashcam video released by the…

Twelve States Now Hit in attack on America’s Drinking Water

Twelve States Now Hit in attack on America’s Drinking Water

August 6, 2026
FDA approves first-ever mRNA flu vaccine for millions of older Americans

FDA approves first-ever mRNA flu vaccine for millions of older Americans

August 6, 2026
SEE IT: Mamdani booed off stage at New York City pro-police celebration: ‘Walked off in shame’

SEE IT: Mamdani booed off stage at New York City pro-police celebration: ‘Walked off in shame’

August 6, 2026

Subscribe to Updates

Get the latest news and updates directly to your inbox.

About
About

Republican Investor is one of the top news portals to cover business, personal finance and second amendment news, follow us to get the latest news.

We're social, connect with us:

Facebook X (Twitter) Instagram LinkedIn VKontakte
Popular Posts
Jeff Bridges nearly played John Dutton before Kevin Costner landed ‘Yellowstone’ role

Jeff Bridges nearly played John Dutton before Kevin Costner landed ‘Yellowstone’ role

August 6, 2026
WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

WATCH: Dashcam captures the split second a routine Tennessee traffic stop goes sideways

August 6, 2026
Twelve States Now Hit in attack on America’s Drinking Water

Twelve States Now Hit in attack on America’s Drinking Water

August 6, 2026
Latest News
FDA approves first-ever mRNA flu vaccine for millions of older Americans

FDA approves first-ever mRNA flu vaccine for millions of older Americans

August 6, 2026
SEE IT: Mamdani booed off stage at New York City pro-police celebration: ‘Walked off in shame’

SEE IT: Mamdani booed off stage at New York City pro-police celebration: ‘Walked off in shame’

August 6, 2026
Preakness Stakes moves to a Sunday for the first time ever in major Triple Crown shakeup

Preakness Stakes moves to a Sunday for the first time ever in major Triple Crown shakeup

August 6, 2026
Copyright © 2026. Republican Investor. All rights reserved.
  • Privacy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.