MANILA, Philippines (Aug 2026) – Cybercriminals are actively exploiting weak security to target critical water systems, exposing a massive failure in how public infrastructure is protected.
Recent attacks hit water and wastewater utilities across at least seven U.S. states. In Minnesota alone, hackers compromised more than 30 water systems. According to the Operational Technology Cybersecurity Coalition, these incidents show the dangerous consequences of neglecting cybersecurity for operational technology.
The threat to critical infrastructure
Experts warn that utility networks have become easy targets. Shane Barney, chief information security officer at Keeper Security, noted that these facilities face tight budgets and aging setups, leaving them highly vulnerable.
“Water and wastewater systems have always been attractive targets for adversaries because the potential for disruption is high and the barrier to entry has historically been low,” Barney said. He added that the compromise of multiple systems is a clear sign that defense measures are lagging behind standard corporate IT security.
Simple gaps, major risks
The entry points used by hackers are surprisingly basic. Most successful breaches stem from compromised credentials, unmanaged accounts, or poorly secured remote access pathways rather than highly sophisticated techniques.
Fixing these vulnerabilities does not require massive enterprise budgets. Security specialists recommend implementing zero-trust principles, disciplined credential management, and privileged access management to secure access points.
While funding programs like the U.S. Cybersecurity and Infrastructure Security Agency grant program and a $9 million (approx. PHP 522 million) commitment from New York help, experts stress that money alone cannot solve the issue. Utilities require mandatory baseline security requirements to ensure all operators are fully protected.
