Exhale insight · August 2026

Why national cyber authorities are telling water and energy operators to get off the internet

Through the summer of 2026 the FBI, EPA, CISA and the NCSC have converged on one message for operators of critical national infrastructure: take operational technology off the public internet, and broker every connection through a secure gateway.

In late July 2026, a coordinated attack hit US water utilities through their internet-facing programmable logic controllers (PLCs), in many cases wired straight to the public internet with no gateway or firewall in between. Over a single weekend, more than 30 community water systems in Minnesota were struck, and within days the FBI and EPA reported incidents in at least seven states. Attackers changed the controllers' passwords and IP addresses to lock operators out of their own equipment, and utilities fell back to manual operation. CISA reported that some of the larger attacks led to boil-water notices and sustained manual running. On 30 July the FBI and EPA issued a joint public warning (PSA I-073026), and CISA urged the sector to take exposed controllers off the internet.

None of it was sophisticated. There was no new exploit and no custom malware, just controllers reachable from the open internet, weak or default passwords, and flat networks. The same combination was behind the 2023 attack on the Municipal Water Authority of Aliquippa, Pennsylvania, and CISA now lists targeted devices across Rockwell Automation and Allen-Bradley, Schneider Electric and Siemens ranges.

Some of the threat is strategic, not opportunistic. In February 2024, CISA, the NSA and FBI warned that the China-linked group Volt Typhoon had been pre-positioning inside US critical infrastructure, including energy and water, for years. One small Massachusetts electric-and-water utility was found to have had intruders in its OT network for close to a year.

The UK picture is quieter but moving the same way. Southern Water disclosed a ransomware intrusion in 2024 that stole customer data and cost around £4.5m to handle. The Drinking Water Inspectorate logged a record five reported incidents between January 2024 and October 2025, and the NCSC's 2025 Annual Review recorded over 200 nationally significant incidents, 18 of them highly significant. It named critical national infrastructure as a priority: the systems that keep the lights on and the water running. The forthcoming Cyber Security and Resilience Bill will widen mandatory incident reporting for operators. The confirmed UK water incidents to date are IT, ransomware and data theft, not tampering with treatment or supply.

What the authorities recommend, and what Exhale does

The mitigation is an architecture, not a patch. The Secure Connectivity Principles for Operational Technology, published by the NCSC with CISA, the FBI and five partner agencies, say to take OT off the public internet and broker all access through a secure gateway, with traffic to controllers validated against a known-good model. Exhale is built to that pattern: controllers are never internet-exposed, remote access is brokered and authenticated per device, and Modbus traffic is checked at the boundary against a known-good allowlist. It closes the gap these advisories describe.

Exhale protects the OT connectivity layer: internet-exposed controllers, remote access and field links. It does not replace IT security controls such as email and endpoint defence, which address a different class of incident, including the ransomware and data breaches also seen across the sector.

Sources

Figures are as reported by the sources above at the time of writing; advisories are revised as campaigns develop.

Talk to us How Exhale works →