Skip to content

The story arrived as usual. “Foreign hackers” breached “critical municipal water infrastructure,” leaving operators scrambling. What makes the story unusual is how they did it. There was no zero-day exploit and no custom malware. Instead, federal investigators have described attackers who found equipment sitting on the open internet, changed its passwords, and locked the operators out. That’s it.

If you have ever postponed a firmware update because the system was working fine, you already understand this story better than most. Here’s a look at what actually happened, why Pennsylvania has particular reason to pay attention, and why the fix is both well understood and stubbornly unfinished.

What Actually Happened

In late July, more than 30 municipal water systems across Minnesota were targeted in a coordinated attack over roughly 48 hours. Nine more were hit in Michigan. On July 30, the FBI and EPA issued a joint public service announcement confirming that water and wastewater utilities in at least seven states had reported incidents. By mid-August, the reported scope had grown to a dozen states or more.

The agencies were specific about the target: internet-facing operational technology, and in particular Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers: the small industrial computers that switch pumps on and off, fill reservoirs, dose chemicals, and log the data that regulators require.

The consequences were not abstract:

  • Operators lost visibility and control over equipment they are legally responsible for monitoring
  • Several utilities were forced onto sustained manual operation
  • At least one system, in Clayton County, Georgia, issued a boil water advisory
  • Reported operational effects included pressure loss (low pressure can draw untreated groundwater into distribution pipes)

Thankfully, no contamination of drinking water has been reported.

Okay, So How Did They Actually Get In?

Simply put, they didn’t break in; they logged in.

An internet-wide scan published in early August by Forescout’s Vedere Labs counted 4,407 internet-facing Rockwell and Allen-Bradley controllers, roughly 2,844 of them in the United States. Twenty-two sat in cities where utilities had reported attacks. Nineteen of those 22 were running firmware vulnerable to a flaw Rockwell patched in 2017 — though the researchers were careful to note that the described attacks didn’t require exploiting it at all. The controllers were simply reachable, and in many cases password protection had never been switched on.

Rockwell has been telling customers not to put these devices on the public internet since at least 2018.

So why are they there? Mostly for an unglamorous reason: many small and mid-sized utilities connect controllers to cellular routers so a handful of staff can monitor remote sites without driving to each one. It keeps costs down in chronically short-staffed systems. It also frequently leaves the industrial protocol underneath reachable by anyone who goes looking.

Pennsylvania Has Seen This Before

The Commonwealth was spared in the July wave, but it has already served as the national example.

In November 2023, the Municipal Water Authority of Aliquippa in Beaver County was compromised by CyberAv3ngers, a group affiliated with Iran’s Islamic Revolutionary Guard Corps. The intrusion hit a booster station’s programmable logic controller. Drinking water was never compromised because the utility switched to manual operation.

Aliquippa previewed what was to come.

State regulators have been active since. The Pennsylvania Public Utility Commission has issued a water and wastewater cyber advisory citing credible threat intelligence from the National Security Council, CISA, and the EPA that nation-state and criminal actors are targeting the Commonwealth’s utilities. In June, the PUC voted 5-0 to advance proposed regulations that would expand cybersecurity program standards, tighten incident reporting, and require annual compliance certifications from jurisdictional utilities.

The rules are coming. The question is who inside these utilities will be responsible for meeting them.

The Fix Is Known

Federal guidance is not complicated or expensive. Take controllers off direct internet exposure. Change default passwords. Route remote access through a VPN or gateway. Enroll in free federal scanning services. Run a tabletop exercise with the people who would actually respond.

None of those require a procurement cycle. Most require an afternoon and someone who knows how to do them.

That last point is the whole problem. A water authority serving 8,000 people does not have a security operations center. It often doesn’t have a full-time IT employee, either. CISA has noted that the targeting spans utilities of every size, including organizations with mature security programs, but the smallest systems have the least capacity to respond, and there are thousands of them.

Dr. Bruce Young, chair of the Department of Cybersecurity at Harrisburg University, said federal agencies have consistently provided water utilities with practical, foundational cybersecurity guidance. The more pressing questions are why many utilities have struggled to implement those recommendations and who should lead that work.

“The guidance has remained largely consistent because the fundamentals were sound from the beginning,” Young said. “The problem is not necessarily a lack of knowledge or technical capability; it is often a lack of clear ownership. A utility with only 12 employees may not be disregarding the guidance. More likely, no one has been specifically assigned, or given the time and resources, to carry it out.”

Solvable Problems Still Need People

Problems caused by exotic capability are hard to solve. Problems caused by exposure are solvable by people who know where to look, what to ask a vendor, and how to explain the risk to a municipal board in language that gets it funded.

Those people must come from somewhere. Pennsylvania has 1,886 community water systems, and 1,553 of them, or 82 percent, serve 3,300 people or fewer. Each one will eventually need someone who can answer a question the state will soon start asking formally.

If that sounds like work worth doing, explore Harrisburg University’s B.S. in Cybersecurity Operations and Management or M.S. in Cybersecurity Operations and Control Management. Both are offered in a hybrid format, which matters if you’re already working at one of the utilities in question. Have questions about HU’s distinctively workforce-focused academic experience? Start a conversation with the Admissions Team today.

ABOUT HARRISBURG UNIVERSITY

Harrisburg University of Science and Technology (HU) is an independent, nonprofit university offering degrees in advanced manufacturing, analytics, biotechnology, cybersecurity, nursing, and other critical fields. Accredited by the Middle States Commission on Higher Education, HU serves a diverse student body through bachelor’s, master’s, and doctoral programs that link research with practical applications. For information about HU’s affordable STEM degrees and professional development programs, call 717.901.5146 or email Connect@HarrisburgU.edu. Stay in the know by following Harrisburg University on Facebook, Instagram, LinkedIn, X, and YouTube.