The Utility No One Is Watching
Everyone is afraid of the wrong thing. One poisoned water bottle, caught by a single sip. Thirty breached utilities, nobody poisoned. The threat that kills is neither.
By Dr. Andrew G. Huff
Epidemiologist. Security engineer. Former Q-cleared scientist, Sandia National Laboratories. Ph.D. in Environmental Health Science, Emerging Infectious Disease & Epidemiology, DHS Center of Excellence Research Fellow. Former U.S. Army infantryman.
Bottom Line Up Front
Part I argued that most people cannot tell an attack from an accident. This part is about a subtler failure: telling the right hazard from the wrong one. Minnesota was not hard to reach, and that is the scandal. But the thing worth being frightened of in a compromised water utility is not the thing the headlines chose.
Seven judgments, each with my confidence on a 0 to 100 scale.
1. Manipulated chemical dosing cannot plausibly produce mass casualties in a system with functioning finished-water monitoring (with one exception, which I will not discuss). The limits are physical, not digital: pump capacity, tank inventory, residence time, and the fact that the water becomes undrinkable long before it becomes dangerous. High confidence, 95.
2. Deliberate poisoning of drinking water in America is real, and it is an insider threat requiring physical proximity, aimed at individuals rather than populations. The Wisconsin case in April is the model. High confidence, 88.
3. The credible casualty pathway is loss of pressure and loss of treatment, not addition of a chemical. The FBI and EPA said so themselves on 30 July, in one sentence almost nobody quoted. High confidence, 88.
4. The July 2026 campaign did not turn on a specific unpatched vulnerability. It turned on internet exposure and password hygiene. Moderate to high confidence, 85, and this corrects an implication I left in Part I.
5. There is no binding federal cybersecurity requirement on American drinking water utilities. None. The rule that existed was withdrawn in 2023 and never replaced. High confidence, 92.
6. The sector cannot describe its own security posture. The most-cited staffing and practice figures in the congressional record are from a 2021 survey. Moderate to high confidence, 80.
7. The utilities that came through Minnesota intact did so because a public works crew could run the plant by hand. That is the control that worked, it is not a cyber control, and it is walking out the door with the retiring workforce. Moderate confidence, 75.
If you take one thing from this piece: in drinking water, the mass-casualty events in the modern record come from what fails to be removed, not from what gets added. That is where a compromised controller connects to a body count, and it is precisely the pathway the coverage has ignored.
I. The Wrong Vulnerability
Start by correcting something, including something of mine.
In Part I, I wrote that a vulnerability disclosed and patched in 2021, an authentication bypass in Rockwell Logix controllers cataloged as CVE-2021-22681, still had thousands of affected devices reachable from the open internet when this campaign began. That is true. It is also, as written, likely to leave you with the wrong impression, and the wrong impression is the one most of the coverage is carrying.
CVE-2021-22681 affects the Logix family. CompactLogix, ControlLogix, GuardLogix, DriveLogix, SoftLogix. It is a cryptographic key-handling flaw that lets an unauthenticated attacker impersonate a trusted engineering workstation and rewrite controller logic. CISA scored it 10.0. It is a genuinely serious defect, and it is worth knowing about, not least because CISA did not add it to the Known Exploited Vulnerabilities catalog until 5 March 2026, five years after disclosure, with a federal remediation deadline of 26 March 2026.
But it is not the flaw in this campaign. The FBI and EPA public service announcement of 30 July names the targeted devices precisely: Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series. Those are a different product line. CVE-2021-22681 does not apply to them.
So, what did the attackers exploit? Read the PSA and it is almost anticlimactic. They reached internet-facing devices, changed the IP addresses, and turned on and set passwords. That is it. In many cases the password was not defeated. There was no password, and the intruder set one, locking the operator out of the operator’s own plant. The 2023 Aliquippa intrusion worked the same way: an internet-facing controller with the factory default still in place.
This matters because it changes what you should be angry about. A zero-day is a story about an adversary’s capability. A device on the public internet with no password is a story about our own choices. The through-line in this sector is not one unpatched CVE. It is exposure and credential hygiene, and those are not hard problems. They are cheap, boring, unglamorous problems that nobody is required to solve.
One more line from the PSA deserves more attention than it has received. Across several victims, the FBI noted, similarities in network setup provided by third parties may let an attacker multiply successes when the same vulnerable configuration exists across many customers. Translate that. Small utilities do not build their own control networks. They buy them from a regional systems integrator, who builds the same architecture for forty other towns. Compromise the pattern and you compromise the portfolio. That is a supply chain finding hiding inside an incident notice.
II. Fifty Thousand Front Doors
To understand why this sector is the softest life-support target in the country, you must understand its shape.
There are roughly 50,000 community water systems in the United States, the ones that serve people where they live, inside a universe of more than 150,000 public water systems once you count schools, campgrounds, factories, and highway rest stops. More than 92 percent of community systems serve 10,000 people or fewer. A very large share serves fewer than 3,300.
Now hold that against the institutional picture.
Capacity. A system serving 2,000 people may have three employees. Not three IT employees. Three employees. They run the plant, sample the water, fix the mains, bill the customers, and answer the phone. Cybersecurity is not a role that exists. When it happens, it happens because an operator read something, or because the integrator who installed the system happened to care.
Awareness. WaterISAC is the sector’s threat-sharing body. Membership starts at 125 dollars a year for the smallest systems and is free for many small systems through the National Rural Water Association. As of February 2026, roughly 680 water and wastewater systems were members. Against a sector of some 170,000 systems, that is about one percent.
Compliance. EPA reported that more than 70 percent of the systems it inspected after September 2023 were in violation of basic requirements under section 1433 of the Safe Drinking Water Act. Not sophisticated requirements. Sections missing from a risk assessment. On site, inspectors found default passwords never changed, single logins shared across a whole staff, and access never revoked for employees who had left.
Exposure. In November 2024 the EPA Office of Inspector General ran a passive scan of 1,062 drinking water systems serving more than 193 million people. Ninety-seven systems, serving about 26.6 million people, carried critical or high-risk cybersecurity vulnerabilities. Another 211, serving more than 82 million, rated medium or low with externally visible open portals. That is 308 systems and roughly 109 million Americans, found from the outside, without touching anything.
Put those four together and you do not have a sector with a security problem. You have a sector with no security function at all, in which the exceptions are heroic individuals rather than institutions.
III. The Modems Nobody Inventoried
I promised you the cellular modems. Here they are, with numbers.
On 30 July, the same day as the federal alerts, Censys published a snapshot of what is visible from the outside. It found 4,148 internet-exposed hosts responding to EtherNet/IP and identifying themselves as Rockwell Automation or Allen-Bradley equipment. Seventy-one percent of them, 2,945 hosts, are in the United States. Canada is a distant second at 11.5 percent.
The number that matters is the next one. Fifty-nine percent of those exposed Rockwell hosts sit on cellular carrier networks. Verizon Business. AT&T Mobility. T-Mobile USA.
Think about what that means physically. A remote well head, a lift station, a booster station, a water tower on the edge of town. There is no fiber out there and no reason to trench any. So, somebody, at some point, put a cellular modem in the cabinet so the plant could see the site. Maybe the utility did it. More likely the integrator did it, or the pump vendor did it during a service call, and it was never written down.
CISA named exactly this on 30 July, and the phrasing is worth reading twice. Even organizations with mature cybersecurity processes should validate their external connections, because the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.
An asset you do not know you own cannot appear in your risk assessment. It cannot be scanned, patched, credentialed, or decommissioned. It is a door in a wall you do not have on the floor plan. The utility does not know it is there. The state does not know it is there. Commercial internet scanning services find it in an afternoon.
A discipline note, since this series holds itself to one. Everything above is public, published by the researchers themselves with their methodology attached, and I am not going to tell you how to run the queries. The point is not that these devices are findable. The point is that they were findable for years and nobody with an obligation to look was looking.
IV. What Manipulated Dosing Can and Cannot Do
Now the question I said I would answer as an epidemiologist rather than a headline writer. If an adversary owns the controller that runs your chemical feed, what can they do to a human body?
The honest answer has three parts, and only the third one is frightening.
Chlorine and chloramine. EPA sets a maximum residual disinfectant level of 4.0 milligrams per liter. Most people can taste chlorine well below 1 milligram per liter; the smell of an over-chlorinated glass of water is a warning system that predates any SCADA alarm. To move from a taste complaint to a chemical injury you need to raise the dose by orders of magnitude, and the feed system will not cooperate. The pump has a maximum stroke rate. The day tank holds what it holds. Chlorine’s genuine acute hazard in a water plant is a gas release, which endangers operators and the neighborhood around the plant rather than customers at the tap, and much of the sector has moved away from gas chlorine toward hypochlorite for exactly that reason.
Sodium hydroxide. This is the Oldsmar chemical, used to raise pH so the distribution system stops leaching lead and copper out of old plumbing. The setpoint in that incident went from 100 to 11,100 parts per million, which sounds apocalyptic and is roughly a one percent caustic solution. It would be corrosive to drink. It would also be undrinkable: at that pH the water is soapy, bitter, and burns the mouth on contact. Nobody swallows a harmful volume of it by accident. And the engineering intervenes long before the chemistry does. Idaho National Laboratory’s case study on Oldsmar found it would have taken roughly 24 to 36 hours for the change to reach the public supply, through a clearwell and a distribution system that provide enormous dilution and delay, past continuous pH monitoring that exists at every plant of consequence. Oldsmar’s own officials said multiple safety systems would have stopped it. They were right, and the operator caught it anyway in about a second.
Fluoride. This is the one that has killed. And it deserves to be stated plainly rather than waved away, because it is the counterexample to my own argument. In May 1992 a malfunction at one of two water systems serving Hooper Bay, Alaska delivered fluoride at 150 parts per million against a target of 1.2. More than 260 villagers were poisoned. A 41-year-old man named Dominic Smith died on 23 May after vomiting, diarrhea, and numbness in his extremities. The New England Journal of Medicine published the investigation in 1994, and it remains the largest reported outbreak of acute fluoride poisoning from a public water system. In a separate incident, a fluoride overfeed at a well site near an elementary school in Portage, Michigan pushed the concentration to 92 milligrams per liter and sent seven children into nausea and vomiting.
So dosing manipulation can hurt people. It has. Note what those two events have in common and what they do not.
Both were equipment malfunctions, not attacks. Both happened at small systems. In both, the failure was not that the chemical went in; it was that nothing downstream caught it before people drank it. Hooper Bay killed a man because a village system in western Alaska in 1992 had no continuous finished-water monitoring standing between a stuck feed pump and a kitchen tap. That is a surveillance failure, and surveillance failure is an epidemiological problem before it is a security one.
Here is the synthesis. An attacker who owns the PLC does not own the chemistry. The bounds on a dosing attack are set by the feed pump’s capacity, the chemical inventory physically present on site, the hydraulic residence time of the plant and the distribution system, the continuous monitoring on the finished water, and the human palate. Every one of those bounds is analog. None of them can be edited from a keyboard in another country. And the attacker cannot know, from the outside, what any of them are at your specific plant.
None of that means nobody in America is poisoning water. Somebody was, four months ago. The case is worth your attention precisely because of how completely it differs from the thing everyone is afraid of.
V. The Man Who Could Actually Poison Your Water
On 14 April 2026, prosecutors in Dane County, Wisconsin charged Makoto Kuroda, a 41-year-old staff scientist at the University of Wisconsin-Madison’s Influenza Research Institute, with recklessly endangering safety and with tampering with a household product with intent to kill, injure, or endanger health. He is on administrative leave, his university access has been revoked, and he has not been convicted of anything. What follows is the account given in the criminal complaint.
Kuroda is alleged to have put roughly half a microliter of paraformaldehyde mixed with Trizol into a colleague’s half-finished water bottle, and about 1.5 microliters into each of the same man’s shoes. The two had worked together for about five years and had been friends. Kuroda told police the relationship soured after the other man was promoted, and that he had spent roughly a year wishing something bad would happen to him. He is alleged to have walked up to the colleague in the lab afterward and said, “I did it,” then emailed his supervisor in Japanese to the same effect.
Every detail of that is instructive, so take them one at a time.
He had to be in the room. There is no remote version of this attack. He walked to the bench where the bottle was sitting. Physical access was not one enabling factor among several. It was the entire method.
He targeted one named person. Not a population, not a city, not a customer base. A specific man whose promotion he resented. The dose was measured in microliters because the target was one human being and the vehicle was one bottle.
And it did not work. The colleague took a drink, noticed a strange odor and a bad taste, and stopped. He also noticed that his shoes smelled of chloroform. The Wisconsin State Hygiene Lab later found chloroform at a concentration the test strips could not quantify, and the complaint observes that because chloroform dissipates over time, a reading that high weeks afterward implies the original exposure was higher still. That is a serious attempt by a person who knew exactly what he was handling. It was defeated by a man’s tongue.
Now set that beside the thing this series is about. In the same season, an adversary with remote access to the industrial control systems of more than thirty water utilities across seven states poisoned nobody at all. A staff scientist with a badge, a grudge, and a shelf of reagents got one water bottle, and lost even that to the taste.
That is the true shape of the water-poisoning threat in this country. It is intimate. It requires proximity. It aims at individuals, and it is usually caught by the person drinking. It is a personnel problem rather than a network problem, and the two are almost never solved by the same people or funded from the same budget.
Two further observations, because I have not seen anyone else make them and both belong in this series.
The first is institutional. This happened inside a high-containment influenza research institute, an organization whose entire license to operate rests on the proposition that it can be trusted with dangerous material. Nobody noticed a staff scientist nursing a homicidal grudge for a year. Whatever else this case turns out to be, it is a personnel reliability failure inside biosecurity, and it belongs in the same file as the water utility that cannot locate its own cellular modems. The pattern running through this series is not that our defenses fail under pressure. It is that nobody is looking.
The second is about a tool. The complaint states that Kuroda used ChatGPT repeatedly to research harmful doses of paraformaldehyde and Trizol in humans and animals, and that the queries triggered warning pop-ups. Read that carefully, because it cuts both ways and the second way is the more interesting one. The guardrail did not stop him. It did create a timestamped, subpoenable record of intent that prosecutors can now put in front of a jury. That is not what the guardrail was built to do, and it may prove to be the more useful function.
So the poison is bounded, and the poisoner has to be standing next to you. What is left?
VI. The Pathway That Actually Kills
Read the operative sentence in the FBI and EPA announcement of 30 July, the one that went almost entirely unquoted.
“Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”
That is the federal government describing the actual mechanism, in public, in the middle of the incident. Not poisoning. Pressure.
Understand why pressure is the whole game. A drinking water distribution system is not a sealed vessel. It is tens or hundreds of miles of buried pipe with joints, valves, hydrants, service connections, and a certain number of leaks that the utility knows about and tolerates. What keeps the sewage, groundwater, soil bacteria, and the contents of the pipe next door on the outside is not the pipe wall. It is positive internal pressure. The water pushes out through the defects instead of the world pushing in.
Drop that pressure and the barrier inverts. Every leak becomes an inlet. Every cross-connection that a backflow preventer was quietly holding at bay becomes a pathway. This is why a utility issues a boil water notice after a main break: not because anything was added, but because for a period the system could not guarantee it was keeping things out. CISA reported on 30 July that the national campaign had already resulted in boil water notices and sustained manual operations.
Now the epidemiology, and this is the part where the record is unambiguous.
In the spring of 1993, Milwaukee’s Howard Avenue treatment plant suffered a failure of filtration performance. Nobody added anything to the water. Cryptosporidium oocysts, which are highly resistant to chlorine and must be physically removed, passed through. An estimated 403,000 people became ill. Sixty-nine died, overwhelmingly people with compromised immune systems. The cost of illness was later put at 96.2 million dollars. It remains the largest documented waterborne disease outbreak in United States history, and it was a removal failure.
In May 2000, in Walkerton, Ontario, contaminated groundwater carrying E. coli O157:H7 and Campylobacter reached a municipal supply after heavy rain, in a system whose chlorination and monitoring had failed. At least six people died, the provincial inquiry counted seven, and more than two thousand were made ill in a town of about five thousand. Again: nothing was added by an adversary. A barrier failed.
Set those beside Hooper Bay and the shape is clear. Deliberate or accidental addition of a chemical to drinking water has killed, in the American record, in single digits. Failure of treatment and containment has killed in the dozens and sickened in the hundreds of thousands, in single events.
So, place the threat correctly. An adversary who owns your controllers cannot realistically poison your city. What they can do is take your pumps offline, drop your pressure, flood a station, blind your operators to what the plant is doing, and hold you in that state long enough that the barriers you rely on stop being barriers. They do not need to put anything in the water. They only need to stop you keeping things out.
And that pathway has a delay built into it, which is why it will never make a good headline. Nobody collapses at the tap. People get sick over the following week, in a diffuse pattern that looks like ordinary gastroenteritis, and the excess only becomes visible if somebody is counting. Which brings us back to surveillance, and to the fact that the same institutions that are not doing the cybersecurity are also the ones that would have to do the counting.
VII. The Rule That Does Not Exist
Given all the above, a reasonable person assumes there is a rule. There is not.
In March 2023 EPA issued an interpretive memorandum requiring states to include cybersecurity in the periodic sanitary surveys they already conduct on water systems. It was not a new inspection regime. It added a topic to an existing checklist. Missouri, Arkansas, and Iowa sued, joined by the American Water Works Association and the National Rural Water Association. The Eighth Circuit stayed it in July 2023. EPA withdrew it in October 2023, citing the litigation. Its own page now says the agency encourages states to review water system cybersecurity voluntarily.
Nothing replaced it. In May 2026 the Government Accountability Office testified to the House Science Committee that federal efforts in this sector remain voluntary and reported something more damning: asked to assess its own legal authority, EPA concluded it has significant limitations in its ability to close the gaps it had itself identified, including the absence of any cyber risk-assessment requirement for wastewater systems and for smaller drinking water systems. The regulator’s position is that it cannot regulate this. That is not an outside critic’s claim. That is the agency’s own finding, in the congressional record.
What does exist is section 2013 of America’s Water Infrastructure Act of 2018, which amended the Safe Drinking Water Act to require community water systems serving more than 3,300 people to conduct a risk and resilience assessment, certify it to EPA, produce an emergency response plan within six months, and repeat the cycle every five years. Cybersecurity is within scope. But read what the obligation is. It is a duty to assess, plan, and certify. It imposes no security controls, mandates no specific practice, and the resulting documents are not shared outside the utility. It is a paperwork cycle, and more than 70 percent of inspected systems were failing even that. Systems serving 3,301 to 49,999 people had a recertification deadline of 30 June 2026, four weeks before the attacks.
The proposal to fix it has been sitting in committee for two years. H.R. 7922 in 2024, reintroduced as H.R. 2594 in April 2025, would create a Water Risk and Resilience Organization: a sector-led standards body overseen by EPA, modeled directly on the North American Electric Reliability Corporation that has governed grid reliability for two decades. Systems serving 3,300 or more would be covered. Penalties up to 25,000 dollars a day. Ten million dollars authorized. It has had no markup, no hearing, and no floor action that I can find.
Meanwhile the scaffolding that does exist is expiring. The two EPA cyber-resilience grant programs for water systems lapse after fiscal year 2026, having been authorized at 75 million dollars a year combined and appropriated a fraction of that; the first 9.5 million for midsize systems was announced in late 2025. And the Cybersecurity Information Sharing Act of 2015, the statute that gives companies liability protection for sharing threat information with the government, already lapsed once at the end of September 2025, was briefly revived, and now expires again on 30 September 2026. That is fifty-nine days from the publication of this piece.
Assemble it and the position is this. The sector is being attacked in at least seven states. The regulator says it lacks the authority to require anything. The bill that would fix that has not moved in two years. The grant money runs out in eight weeks. The information-sharing law runs out in nine. And the federal cybersecurity agency’s proposed budget for infrastructure assessments is a little over half of the current year’s budget.
VIII. What Actually Worked in Minnesota
Against all that, notice what held.
South St. Paul found a problem early on a Monday, moved public works staff onto manual operations, and never interrupted water or wastewater service. Braham noticed a well misbehaving, isolated the system, brought up a backup, and had the plant running again in about ninety minutes. Aliquippa in 2023 lost a pressure-regulating pump and kept serving water. In each case the intrusion succeeded and the consequence was contained.
The FBI’s own list of impact factors tells you why. The extent of impact, the PSA says, depended on what the controller was doing, which model it was, what function it supported, and the capability to switch to manual operations.
That last one is not a cybersecurity control. It is a person who knows the plant well enough to run it without the screens. It is institutional muscle memory, and it is the single most effective defense this sector currently has. It is also the one that is quietly disappearing, because the operators who learned the plant by hand are retiring and the ones replacing them learned it through an HMI.
The rest of the fix list is not exotic. It is the federal recommendations, and they cost close to nothing:
• Take the controller off the public internet. Broker every remote connection through a secure gateway with no inbound port exposure.
• Find the cellular modems. All of them, including the ones a vendor installed during a service call in 2019. Then authenticate them, log them, and consider a private APN or a site-to-site tunnel.
• Set unique, complex passwords on every device, and revoke access when people leave.
• Use access control lists so a controller will only talk to the devices it is supposed to talk to.
• Put the physical key switch in RUN and leave it there except during a validated download.
• Compare running PLC logic against known-good logic. The FBI reported at least one victim finding modified project files after noticing ladder logic discrepancies across several sites.
• Keep a rolling twelve-month end-of-life forecast and replace the gear on it.
• Practice manual operations. Then practice them again with the person who normally does it on vacation.
• Join WaterISAC. It is 125 dollars for the smallest systems and free for many. About one percent of the sector has done this.
None of that requires a new statute. All of it requires somebody whose job it is to care, and for most of the 50,000 that person does not exist.
IX. Red Team
The strongest objections to what I have argued, and my answers.
“You just told an adversary that dosing attacks do not work and pressure attacks do.” I told them what the FBI and EPA published on 30 July and what the epidemiological record has said since 1993. Any competent adversary already models this; the mechanism is taught in undergraduate water treatment. The people who did not know are the public and the legislators who fund the defense, and they are the ones who set the budget. Keeping defenders ignorant to keep attackers ignorant is a trade that only ever works one way.
“You are minimizing. Poisoning the water is a real threat.” Contamination is a real threat. Dosing manipulation through a compromised PLC is a bounded one, and I gave you the bounds and the one case where it killed. If you want to worry about contamination, worry about the pathway that has produced mass casualties, which is the barrier failing rather than the poison arriving. That is not minimizing. It is aiming.
“Ninety-five out of a hundred is too confident on the dosing question.” Possibly. It rests on the assumption that finished-water monitoring is functioning and that somebody is watching it, and Hooper Bay is the proof that this assumption fails at small systems. If you asked me the same question restricted to systems serving under 3,300 people with no continuous monitoring, I would drop it to about 60. That is a real caveat, and it points at exactly the systems this piece is about.
“You corrected yourself on the CVE. Why should we trust the rest?” Because the correction is the product. A vulnerability catalog number that got attached to the wrong incident is exactly the kind of error that propagates unchallenged through a hundred articles, and I would rather be the person who catches it in his own copy than the person quoting it in 2029.
“You are using a charged man to make a rhetorical point.” Fair, and I have said plainly that Kuroda is charged and not convicted. I rely on the complaint’s account of the method, not on its account of his guilt, and the methodological point holds whatever the verdict. Whoever put chloroform in that bottle had to be standing in that room. If he is acquitted, the case still tells you what an attempt to poison someone’s drinking water physically requires.
“The industry groups who sued EPA had a point.” They did, and I should say so. Sanitary surveys carry public notification requirements, so putting cybersecurity findings into them arguably creates a disclosure risk; and state drinking water programs genuinely do not have the expertise to audit control systems. Those are real objections. They are also arguments for building the right instrument, which is what the WRRO bill attempts, rather than for the outcome we got, which is nothing at all for three years.
Next in Soft Targets
Part III, “Pre-Positioned.” Iran is loud. It defaces a controller, posts a banner, and wants you to know. That is not the adversary that should keep you awake. Next week: two intrusion models side by side, the quiet one that has been living inside American power and telecommunications infrastructure without touching anything, and why the interdependency map makes electricity the master dependency for every system in this series, including the water plant that just proved it could run by hand.
References
[1] FBI and EPA Public Service Announcement, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions,” 30 July 2026. https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions
[2] CISA Alert, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” 30 July 2026. https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
[3] Joint Advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” FBI, CISA, NSA, EPA, DOE, CNMF, 7 April 2026, updated 22 July 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[4] Censys, “CISA Alert: Water Tower PLC Targeting,” exposure snapshot dated 30 July 2026. https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
[5] NVD, CVE-2021-22681. https://nvd.nist.gov/vuln/detail/CVE-2021-22681
[6] CISA ICS Advisory ICSA-21-056-03, Rockwell Automation Logix Controllers, 25 February 2021. https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03
[7] Rockwell Automation Security Advisory SD1790, MicroLogix 1400. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html
[8] EPA, “Cybersecurity in Sanitary Surveys,” and the October 2023 withdrawal memorandum. https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys
[9] EPA Enforcement Alert, “Drinking Water Systems to Address Cybersecurity Vulnerabilities,” May 2024. https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities
[10] GAO-26-109159, “Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector,” testimony, 21 May 2026. https://www.gao.gov/assets/gao-26-109159.pdf
[11] GAO-24-106744, “EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems,” 1 August 2024. https://www.gao.gov/products/gao-24-106744
[12] EPA Office of Inspector General, Report 25-N-0004, “Management Implication Report: Cybersecurity Concerns Related to Drinking Water Systems,” 13 November 2024.
[13] EPA, “America’s Water Infrastructure Act Section 2013.” https://www.epa.gov/waterresilience/awia-section-2013
[14] H.R. 2594, Water Risk and Resilience Organization Establishment Act, 119th Congress, introduced 2 April 2025. https://www.congress.gov/bill/119th-congress/house-bill/2594/text/ih
[15] Testimony of Michael Dewhirst, Association of Metropolitan Water Agencies, Senate Environment and Public Works Committee, 4 February 2026. https://www.epw.senate.gov/public/_cache/files/c/1/c1102867-601e-4bfd-a0bc-d1d5fe2e16ea/A2FAEFC36A3BA0855F37563B9B0FBE5ACB04D4C9EDA5662D877A762A8B2EBA61.02-04-2026-dewhirst-testimony.pdf
[16] Water Sector Coordinating Council, “Cybersecurity State of the Sector,” 2021. https://www.waterisac.org/2021survey
[17] Congressional Research Service IF12959, “The Cybersecurity Information Sharing Act of 2015: Expiring Provisions.” https://www.congress.gov/crs-product/IF12959
[18] EPA, National Primary Drinking Water Regulations, maximum residual disinfectant levels. https://www.epa.gov/ground-water-and-drinking-water/national-primary-drinking-water-regulations
[19] Gessner BD et al., “Acute Fluoride Poisoning from a Public Water System,” New England Journal of Medicine, 13 January 1994. https://www.nejm.org/doi/full/10.1056/NEJM199401133300203
[20] Penman AD et al., “Fluoride overfeed at a well site near an elementary school in Michigan.” https://pubmed.ncbi.nlm.nih.gov/12369244/
[21] Mac Kenzie WR et al., “A Massive Outbreak in Milwaukee of Cryptosporidium Infection Transmitted through the Public Water Supply,” New England Journal of Medicine, 21 July 1994. https://www.nejm.org/doi/full/10.1056/NEJM199407213310304
[22] Corso PS et al., “Costs of Illness in the 1993 Waterborne Cryptosporidium Outbreak, Milwaukee, Wisconsin,” Emerging Infectious Diseases, April 2003. https://wwwnc.cdc.gov/eid/article/9/4/02-0417_article
[23] CyberScoop, “Did someone really hack into the Oldsmar, Florida, water treatment plant? New details suggest maybe not,” 10 April 2023. https://cyberscoop.com/water-oldsmar-incident-cyberattack/
[24] Idaho National Laboratory, CyOTE case study, “Remote Access Attack on Oldsmar Water Treatment Facility.” https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-Study_Oldsmar.pdf
[25] CBS News, “U.S. investigating whether Iran was behind cyberattack on Minnesota water systems,” 30 July 2026. https://www.cbsnews.com/news/us-investigating-iran-cyberattack-minnesota-water-systems/
[26] Joe Schulz, “UW-Madison employee faces felony charges for allegedly trying to poison coworker,” Wisconsin Public Radio, 20 April 2026, updated 21 April 2026. The most detailed public account of the criminal complaint. https://www.wpr.org/education/higher-education/uw-madison-employee-kuroda-felony-charges-poison-coworker
[27] Criminal complaint, State of Wisconsin v. Makoto Kuroda, Dane County Circuit Court, filed 14 April 2026. https://www.wpr.org/wp-content/uploads/2026/04/makoto-kuroda-complaint-1.pdf
[28] The New York Times, “University of Wisconsin coworkers, poison case,” 20 April 2026. https://www.nytimes.com/2026/04/20/us/university-wisconsin-coworkers-poison.html
[29] CDC ToxFAQs, Chloroform. https://wwwn.cdc.gov/tsp/ToxFAQs/ToxFAQsDetails.aspx?faqid=52&toxid=16
[30] Congressional Research Service R47315, “Small Water Systems: Selected Safe Drinking Water Act Provisions.” https://www.congress.gov/crs-product/R47315










In a town that I lived in, the wrong kind of ash was delivered to the water municipality and inserted into the water supply. The alert went out, people mobbed the usual water bottle outlets in a neighboring town (Costco carts loaded with water about 8 high was not unusual, until their supply was "sucked dry".)
I was finally able to find the last 5 gallon jug at a Home Depot.
People know how important water is, and yet there is no personal resilience, because they just assume the water will be there. And safe.
I have a few 55 gallon food safe drums now, but I haven't swapped out the water in a few years, nor have I added a little bleach to it for the same time. I guess I should attend to that.
One thing I never considered, and that you brought up (thank you!) is the pressure differential and it's role in keeping untreated ground water out. I just assumed someone broke open a pipe and some dirt fell in, but it makes perfect sense.