
Last week’s cyberattacks against water and wastew…
Loading summary
A
Hello and welcome to statescoop's Priorities podcast. I'm Colin Wood, statescoop's Editor in Chief. This week we're taking a closer look at the recent cyber attacks against the nation's water utilities, a coordinated attack, the full extent of which is still being uncovered. But first, here are the other biggest state and local government IT news stories of the week. The Department of Justice has announced it's expanding its strategy for combating fraud in Medicaid, SNAP and other taxpayer funded programs by deepening partnerships with state governments aimed at improving data sharing, investigations and fraud detection. Work with Alabama, Florida, Georgia, Louisiana, Mississippi, North Carolina and South Carolina is designed to improve information sharing, identify fraud earlier, and coordinate prosecutions across jurisdictions. A recent report from the National Conference of State Legislatures outlined bipartisan policy recommendations for strengthening state childcare systems, including addressing disparities in tech systems between state agencies and local providers and the need for better data sharing across agencies. In an interview, Jenna Bannon, associate director of the conference's Children and Families Program, explains why it's critical to use technologies that simplify state systems. The National Governors association has announced a new partnership with Raise Us, a nonprofit workforce initiative launched in June by two former governors. Aimed at helping states develop effective AI workforce initiatives. The new $1 million project will, according to organizers, quote, identify and amplify new policy models. Late last month, headlines began to crop up from in local news outlets in Minnesota about a cyber attack that had disrupted water utilities in some communities. Soon the state government announced that at least 30 communities had been affected. Then the federal government announced that actually at least eight states had been targeted. And as of August 4, which is today, the day that I'm recording this, ABC News reported that the number of states involved is at least 12. There are still a lot of unanswered questions surrounding the attack. And to gain some clarity on the issue, I interviewed two very well informed and insightful experts in operational technology. One is Mauricio Papa, a computer science professor at the University of Tulsa, who you'll hear from later. But first, here's Patrick Gillespie, who directs the OT practice at the firm guidepoint Security.
B
Why this happens is we have threat actors wanting to target critical infrastructure in the U.S. essentially, the ease of why it's happening or why it's happening so prevalently right now is that these are inherently insecure devices that are directly connected to the Internet. So they have no firewall, no cyber protections on the devices themselves, or a firewall in front of them. So it's not sophisticated attacks. It's essentially you know, kind of low hanging fruit, just devices that are legacy, sometimes years or decades old, without encryption, without authentication, or sometimes default credentials and then also, you know, running cleartext protocols and then of course, no, you know, with no security gateway in front of them.
A
Yeah. And one question that I get asked sometimes is whether these sorts of attacks, and this attack in particular, which the information we have as of this recording is that it's affected Minnesota and then seven other states. I don't know if you or others. Well, somebody probably knows who those other states are. I, I don't know that I do or that it's been reported widely. I looked before we started this interview and I don't think, I don't think those states have been announced. But one question I get asked a lot is why did they go after Minnesota? And I always assumed that it's because they, you know, they're, they're twice twisting the doorknobs on every door and they were able to get into Minnesota. So it was more, it tends to be more opportunistic. But I'm curious to hear from an expert whether that's a correct read on the situation.
B
Now. That's a great analogy, Colin. So not having any protection. So essentially, like you said, all the devices that are directly connected to the Internet that are affected by these attacks and these advisories from CISA are essentially unlocked doors. So like you said, a bunch of doorknobs have been tested. The reason that it's heating water, wastewater is these, a lot of these small utilities have no support for cybersecurity. They don't have dedicated cybersecurity personnel to understand, you know, what needs to happen. And a lot of these IP addresses are, the owner of the IP addresses are cellular providers. So it's essentially a cell connection connected to these PLCs and that have been connected to these PLCs for sometimes years. So yeah, it's very, very opportunistic. It just so happened that, you know, that these were tied to Water Wastewater Systems and CISA put out this advisory initially, I think back in April, early April. So, you know, these attacks have been happening for a while. They've had more time to do enumeration, you know, those kind of things and then figure out, you know, I guess, I guess then they decide which ones to attack, know, so on and so forth. But yeah, right now I don't. Let's see, trying to see what other states there's. Yeah, possibly Michigan and Georgia as well. But yeah, it's, it's very, very opportunistic. I don't think they specifically targeted Minnesota as a state versus Michigan or any other state. Right. I think it's very, very opportunistic to where it's, you know, like I said, low sophistication attack.
A
Right. Now one kind of conundrum that occurs to me whenever these attacks occur is that it seems that the sort of advice that gets circulated, like, you know, you need to change the default passwords, et cetera, and the other things that you mentioned, that's good advice, but often advice that is already being heeded by those who weren't attacked. And maybe those who are being attacked are the ones who are least likely to be paying attention to such advice. Do you think there's any sort of way around that? Catch 22, a lot of it is
B
going to rely on, on other support. Right. Because the people running these water wastewater systems are keeping water running to our, you know, communities, our citizens. That's their focus. Right. Their focus is not cyber. Their focus is not necessarily even it. So they know how to run water and wastewater systems. So they're not thinking cyber with, you know, through as part of their job. So that's where you know, the entities that have put firewalls in place that have changed those default credentials. Like you have personnel that understand what to do and they have the time and the resources to do those things. So the ones that haven't done it are the ones being attacked. And yeah, very much agree with what you said. You know, a lot of times they don't have the staff, the time, the resources. So that's where some states, I think it was New York, I think the governor of York just provided $9 million to secure water wastewater in New York. I can't remember if that was a state or just a city.
A
Yeah, it's New York.
B
New York. Okay. So, yeah, the state of New York. So it's going to things like that. It's going to need coordination from federal entities. Like I know Minnesota was working with the FBI last week, so to help, you know, resolve some of this. So it's going to take coordination and planning from cyber experts to be able to help identify those devices. Because again, the end users, the OT operators, the asset owners at these facilities most likely don't know that there's even cell connections connected to their PLCs until there's an attack.
A
Right. They're concerning themselves with calcium levels or chlorine amounts.
B
Yeah. Fluoride. Yeah. All the water, water related stuff. Yeah. It's just like me. I, you know, Being a cyber expert, I wouldn't have a clue what to do in a water wastewater system, you know, but I would never be expected to go in and fix one if my local rural utility, just because I'm a cyber expert, you know, I would ask the water wastewater person to fix that part and then, but you know, it takes everybody working together.
A
Yeah. And I think the whole of state approach to cybersecurity is meant to, as you alluded to, kind of remediate some of that, the kind of the lack of expertise, especially at the local levels and in the more rural areas. It's kind of surprising to me that more people haven't followed in the footsteps of New York because those efforts have been ongoing for I think something like 18 months at a minimum. So at least in terms of the planning of it. But you know, the, the whole of state cybersecurity is definitely, you know, that's a trend that's been growing for years. So hopefully that will bring some, some more, some more change with critical infrastructure, because obviously it's critical. So outside of that, are there any other sort of policy changes that you think are important or would be helpful?
B
Just these devices themselves are just inherently insecure. So, you know, for, you know, federal government put out the zero trust mandate for ot, I think last November. So these, a lot of these devices could, you know, even if there were a firewall in front of them, you know, would not be able to support that. So if there was an attack that, you know, went in to the IT side, you know, like Colonial Pipeline, for example, that attack came in through the IT side of the network. So with these devices not being, not having cyber hygiene, you know, there should be a baseline of foundational requirements for any of these assets that are tied to critical infrastructure. You know, instead of just recommending or putting out advisories on changing default passwords or using encryption, you know, there should be foundational requirements for that way when New York does fund $9 million for cyber, that when they, if they buy new devices, that those new devices do not have default creds, they're using encryption, they're not exposed to the Internet, they're using secure remote access, there should be, you know, foundational requirements for that. You know, just like, like medical devices. The FDA has policy from 2022 that requires third party testing for new medical devices. So, you know, it really should be, you know, at least considered that we do the same thing for critical infrastructure devices. If it's, you know, if it's running water, wastewater, power, you know, nuclear you know, keeping, you know, keeping people safe, keeping our citizens safe, should also consider some of the same foundational requirements as well.
A
Right. The fact that this has been such big news, the, you know, outlets like the New York Times and all the, all the big outlets are, have been covering this maybe means that people who wouldn't have been paying attention to this are perhaps what are some easy steps. Give us the hit list. Five things that small utilities should be doing if they're not already.
B
Yeah, of course, yeah. For the OT asset owners, the operators that are running the water wastewater facility is, you know, having an asset inventory, knowing what devices are in your system, you know, by brand or model, those kind of things. You don't have to be a cyber expert to be able to build a list of your inventories. That way when you do get support from state, county or federal, you can provide the asset inventory list. That will reduce the amount of time it takes to find out what devices are vulnerable. But then also making sure there are no Internet modems essentially or Internet connections through fiber, cable, cellular, which most of these are cellular on these attacks. So just asset inventory is foundational to making sure there's no Internet connections on those. And then, you know, working with support, whether that's your IT person or if you have a cyber person or working with, you know, outside teams from, you know, organization agencies or organizations, is, you know, asking for help for, for making sure you don't have default creds, you know, enabled, you know, those kind of things. So, but then, but for resiliency purposes, so in the event that your PLC program has changed or you do it does lose connection or gets reset, is having a backup. So whoever is responsible for the asset itself, whether that's a third party vendor or your maintenance, maybe maintenance team, maintenance manager is having an offline backup. Offline backup file is crucial to recovery where you can get your site back up quickly. And then also running it in manual mode without Internet connection will be able to keep you running. And that's what they did in Minnesota last week, was switched everything to manual mode without Internet connection and was able to restore the water wastewater.
A
Right. I spoke to someone who was talking about a annual events, I forget the name of it. But anyway, it's an annual event that some people participate in with the EPA or some office, independent office associated with the EPA to see if they could do a day without their SCADA systems. And apparently there are few who can.
B
So in the early 80s, the Internet became inevitable, just like AI is inevitable now. So water wastewater has Been running for decades, right? For, for many years. A lot of these systems are decades old running technology from the 70s and 80s. So the, the operators were able to run things manually. Once the Internet came, it reduced the amount of time and cost it takes to restore by providing, you know, remote access for third party vendors. So the Internet enabled a lot of things to save costs and keep costs down for constituents. So to where the water bills does continually keep going up. So in that time, in those 40 plus years that these systems have started to connect to the Internet, over time they've relied on those systems. So now you have generations of people that have ran these systems with Internet connection or some connection to IT systems, automated systems for billing, payment processing, you know, all of these things. So yeah, I think the epa, the exercise is the national Cybersecurity drill, but I think it was, I think it was last month. But there's also CISA and the five eyes worked on what's called CI Fortify. So it's essentially prepping to get in the event that, you know, the president or the governor, you know, states, you know, there is a cyber attack on our water, wastewater, for example, that they know where the Internet connections are, they're able to disconnect them and run the systems like pre Internet days, pretty much run the manual, put it, let's put it in manual mode. Let's keep our water, wastewater going to our hospitals, to our, you know, citizens, you know, those kind of things. And then once the threat is over, then we can, you know, reconnect the Internet. But without an asset inventory, without knowing what's on your network and where the Internet connections are, you're not able to do that. So I think that's where a lot of them are struggling, is finding where these Internet connections are and also building that, that total asset inventory of not just hardware, but software as well.
A
That was Patrick Gillespie with GuidePoint Security. Next we'll hear from Mauricio Papa Brock, professor of Computer science at the University of Tulsa.
C
So I started doing research on OT security specifically back in 2006. So what, 20 years now, I cannot even believe it. I started working mostly with anything that had to do with critical infrastructure. I don't know if you know, but according to DHS, there's, you know, we have 16 different sectors and I live in the state of Oklahoma, so the energy sector is one of those 16. We have some, you know, oil and gas companies and electric power. And so I focus mostly on those two. But I've worked in other domains and so yeah, I've been researching in this area for about 20 years, and actually my PhD was also in computer security. I started with IT security, and then I moved to OT.
A
Yeah, so 20 years would have been 2006. I think that was pre iPhone. The world of technology looked very different. Do you recall what attracted you to OT specifically?
C
Well, my background. I also have a background in electrical engineering, and I used to work with control systems. And so having a degree in computer science and having the ability to research on control systems for me was ideal because I could go kind of back to my roots but also continue to work in my area, which at the time was also network security.
A
So when you see news like we saw last week, if I have my timeline. Right. Well, anyway, the recent. So originally Minnesota and now at least seven other states, Michigan and Georgia, I'm told, are among them. When you see news like that, does that surprise you? No.
C
I mean, critical infrastructure is a very attractive target for cyber attacks, not only by hacker groups, maybe that may have some financial motivation, sometimes like ransomware types of attacks, but also you have the issue now with nation states having resources dedicated to find ways to attack critical infrastructure if they succeed. Something that would have an impact on our ability to work in society, will have an impact on national security. So unfortunately, they're attractive targets regardless of the motivation.
A
Yeah. So if people like you have been aware of this for at least two decades, why is this still a problem that we're dealing with?
C
Well, cybersecurity and technology, you know, they're always evolving. Just to give you a little bit of history, maybe the first time that a US President recognized that we had to do something about critical infrastructure and cyber attacks was back in 1998 with President Clinton. So we've been working on that area for a number of years, and we've been learning with time. So just to give you an example of the things we've Learned, back in 98, President Clinton gave agencies five years to come up with a strategy to protect the critical infrastructure. And so what happened before the five years went up? Back in 2001, we had September 11 attacks. And so then we learned that not all critical infrastructure is the same. We had to have priorities and categories, and there were things that we needed to bring up first. And that's why they came up with the 16 sectors and created DHS and all that. But like I said, technology is always evolving. The Internet, as you probably know, this maybe not so much of an issue back in 2006, but we want to connect everything to the Internet. It's so convenient. It's right there. You don't even have to move to get access to data. And so as a result of that, now systems that used to be isolated, like control systems, used to be more isolated than are nowadays. They're being increasingly connected to the Internet. And with that, you leave them more open to attacks. And so we need to remain vigilant.
A
Yeah. So I'm not so naive to think that, you know, any system could be totally secured, but I, I wonder if maybe there, there are steps to go in the right direction.
C
Yes.
A
Talking about industry or government rules about, you know, even the. Even if you can't totally secure it, maybe creating some sort of technology where it doesn't work until you've changed the password or something really basic like that.
C
Yeah, we have to. And we have some guidelines, basic guidelines for securing this type of systems. I mean, the first one, and probably the most obvious one, and a cyber attack occurs because someone had access to the resource that's connected to the network. So one of the first things that we sort of need to do, and this, by the way, is one of the recommendations given to the water utilities that were under attack, is just to make sure that the digital controllers that we call PLCs, programmable logic controllers, to make sure they're not accessible through the Internet. And so that would probably be one of the first things. Remove direct access through the Internet. You know, you can also sometimes have indirect access. You know, networks is just a sequence of nodes that are connected. But at the very minimum, that would be probably the first thing that we need to do. And then the other things that we need to recognize is once someone has access, the reason a cyber attack occurs is because there's a device that has some sort of a vulnerability that can be exploited. And so the second thing we need to do is be aware of what kind of vulnerabilities may be applied to some of the devices we have, and then make sure we have protections against those vulnerabilities. So those are basic two things we have. You know, there's guidelines on how to configure the network, the topology or the shape of the network, and make sure. In the case of ot, in particular, one of the first recommendations are usually made, apart from making sure they're not accessible from the Internet, is what we call make sure we segregate networks, which means make sure that OT systems are on their own networks and they're isolated. And so there are good practices out there, some from the federal government. NIST has guidelines and Then there are some sectors that are maybe more regulated than others that have specific regulations that have to do with network security or critical infrastructure protection.
A
But even if we had really well designed rules that were instated tomorrow, we're talking about tens of thousands of water utilities. How do you, you know, you could do it tomorrow and then 10 years from now there would be still be ones out there that hadn't shored up their defenses yet.
C
I was reading that, yeah, they're estimated Here in the US more than 150,000 water treatment facilities or water systems. So I think it's important also to sort of create a community so that people are aware these things are happening. Maybe a little bit of training and education on some of the basic things that I was just telling you that we can do would be good. I think also resources. The particular case of, I believe, water and water treatment systems, they're typically under the control of local government or municipalities. And unfortunately, sometimes they don't have all the resources that they need. They're sometimes very small operations. They may not have the budget or trained people that can actually protect those systems.
A
Yeah. When you look at industry and the sorts of products that are available, do you see any opportunities there for improvements where cybersecurity is concerned?
C
There's a lot of work that's being done specifically for ot because, you know, we've been aware that cyber attacks are a possibility for a very long time. Like IT security. We've been working probably much, much longer than in OT security. So there are technologies that we can use. But the thing we need to recognize is that OT systems have different requirements than IT systems. So maybe tools that work very well in IT may not work very well in ot, mostly because they have different needs. So AI right now it's being used a lot in the OT domain to detect most, to help detect anomalies on the network and be able to alert the IT security professionals. So there's tools and there's also a lot of research that's being done. Like I said before, technology is an ever evolving thing. And so we have to remain vigilant and train ourselves and be proactive. The way I say it, we need to be a step ahead of the bad guys.
A
Yeah. Outside of the things that you've mentioned already, do you have any. You know, there are other. Obviously there are other resources for this. There's CISA and.
C
Yeah, yeah, there's CISA and nist. NIST has a very nice publication also with technical guidelines on what to do and how to protect Otis Systems how to design the network where once they're deployed so the resources are out there. I'm very optimistic in that. Here in the US in general, we've done a pretty good job. I think when you compare against some of the other attacks on critical infrastructure in other parts of the world, I think we're doing well. But this is sort of a wake up call. We cannot give up. We gotta keep trying. And in this particular case, I think probably we can, I hope, make a case that those local municipalities are in charge of these critical systems. Maybe get more resources than they actually do right now.
A
If you were one of the bad guys, would you be going after water?
C
Well, water for the reasons that I just mentioned, like in the case of this particular attack, you know, CISA knew in April that they had identified the groups, they knew which kind of PLCs were being targeted. So we've known for a while and people were alerted. But sometimes we don't have all the resources to respond. And so in this particular case, the first reports that I read, they said they attacked 30 facilities to do that, something like that. At the same time. That means they had quite a bit of intelligence apart from just the technical know how you know what sort of things to do, what kind of PLC have the weakness. So water treatment and water system in particular have that problem. Electric power sector, there's more regulation there and more resources, I believe. Same thing. You know, oil and gas, you have big companies. So if you have to go or look for targets that are maybe more, more attractive in the sense that it looks like it's may, might be easier. Water systems. Yeah. Are one of them.
A
Right. Do you think that's because when you think of an electrical grid or something like oil, those are, those sound like flammable things that you can kind of blow up. But water is like, ah, it's just water, it can't blow up water, right.
C
Yeah, except that, that, that is true. Except that you know, we drink it. There's probably safety issues. The other difference between let's say water and electric power is the dynamics in the time domain of both types of systems. When you have an electric power grid, you do something bad, you'll notice it almost immediately. So you have to be able to respond very, very quickly. On a system like water systems, where they're more like sometimes even gravity driven things occur much slowly and sometimes you have more time to respond.
A
Yeah, that could be really insidious too if there's a gradual change in chemical levels or something.
C
Yeah. In the case of Water, I think they separate. You have the water treatment plan that make sure we have drinkable water. If there are control systems, like you were saying, are taking a look at the chemicals and the properties of the water. If you have a cyber attack on one of those systems, that obviously wouldn't be good, especially if they're handling chemicals, you know, and then when you look at water, the plants that are treating wastewater, you know, that has an impact on environment and maybe also public health. Both sides, I think, are, in the case of water, equally important. And my understanding is in this particular attacks, that there were systems where they had to recommend or tell people to boil their water, which probably means they're not. I mean, they're not sure that it's drinkable, you know.
A
Right, right. Well, I remember how difficult it was to track down the. The bug with the lettuce, you know.
C
Yeah, yeah, yeah. Now there's that, too. I mean, we. Like you said, you never know. And the impact in the case of critical infrastructure or when you have things with the food and supply chain, those are real risks. And, you know, an IT security, I tell people, I'm sure if you're using Windows or Mac OS or probably any other operating system, we're used to, you know, rebooting and installing updates almost every week. When you're talking about critical infrastructure, we cannot do that. Like I said before, you know, the security needs of an OT system are much different. You're sometimes using equipment that's very old, that's legacy equipment. You cannot just be rebooting control systems. You know, if you're controlling a refinery or a pipeline, you cannot be rebooting systems every week just because there's an update. So that makes it more challenging.
A
That was Mauricio Papa from the University of Tulsa. A big thank you to both of our guests for taking time to share their expertise with us. That's it for this episode. The Priorities podcast is a production of Scoop News Group in Washington, D.C. carlin Fisher is our producer. I'm Colin Wood. Thanks for listening.
Podcast: Priorities Podcast (StateScoop)
Episode: Water utility cyberattacks product of expedient decisions, IT staff shortages, experts say
Date: August 5, 2026
Host: Colin Wood, StateScoop Editor in Chief
Guests:
This episode investigates the recent wave of cyberattacks on US water utilities, with a specific focus on why these systems remain vulnerable and what can be done to mitigate future attacks. Drawing from the expertise of operational technology (OT) specialists, the discussion covers the root causes—ranging from legacy systems and lack of cybersecurity personnel to policy inadequacies and industry inertia. Real-world examples, policy suggestions, and practical guidance for water utilities are offered.
| Timestamp | Segment / Topic | |------------|-------------------------------------------------------------| | 02:41–05:51| Patrick Gillespie – How/why attacks are happening | | 06:24–08:25| Staffing shortages, rural/local challenges | | 09:15–11:15| Need for foundational requirements; comparison to FDA rules | | 11:15–13:08| Practical steps for utilities (hit list) | | 13:33–15:38| Evolution from manual to internet-connected systems | | 15:48–18:39| Mauricio Papa background; why attacks aren’t surprising | | 18:39–23:08| Historical policy context & specific recommendations | | 24:37–25:49| OT vs. IT security & AI for anomaly detection | | 25:57–26:55| Global comparison & optimistic outlook | | 26:59–28:23| Why attackers target water; regulation differences | | 28:23–29:15| The insidious nature of water system vulnerabilities | | 30:19–31:20| Challenges of updating OT versus IT systems |
For more technical guidance: