What happened
Cyberattacks on US water and wastewater utilities have now been reported in at least 12 states, with South Dakota and Georgia among the latest to disclose incidents. The FBI and the Environmental Protection Agency first warned on July 30 that malicious actors had targeted systems in at least seven states since July 27; days later the count had climbed, with Michigan, New Jersey and Minnesota also among those reporting attacks. According to the FBI, the attackers went after programmable logic controllers, the small industrial computers that monitor pumps and valves, that were reachable directly from the internet. In several cases they changed device IP addresses and passwords, locking utilities out of monitoring and control, and some incidents degraded operations, including loss of water pressure and flooding. No contamination of drinking water has been reported, and news reporting ties the campaign to suspected Iran-linked actors who have targeted this class of equipment before.
Why it matters for your business
Most of the affected utilities are small operations, which is the uncomfortable lesson here: attackers did not pick prestige targets, they scanned the internet for exposed control equipment and took whatever answered. Small businesses in the DC, Maryland and Virginia area run the same risk in miniature. Internet-connected HVAC controllers, security cameras, door systems, network storage and point-of-sale gear are routinely left reachable from the open internet with default or weak passwords, and automated scanning finds them fast.
What to do about it
Take an hour this week to inventory what your business exposes to the internet. Anything that does not need outside access should sit behind your firewall or a VPN, every device password should be changed from the default, and remote-access features you do not use should be turned off. If a water plant can be knocked offline through an exposed controller, so can your building systems.
