AKMSecure Insights

Why Water Utilities Are Still Exposed Five Years After Oldsmar

Written by AKMSecure | Oct 8, 2026, 1:46:59 PM

 In late July 2026, attackers reached internet-facing programmable logic controllers at more than 30 Minnesota water and wastewater utilities, changed their passwords and IP addresses, and locked operators out of monitoring and control (Tenable). The FBI and EPA reported that water systems in seven states were hit (Western Water). The weakness behind these attacks is the same one exposed in February 2021, when the BBC reported that someone had remotely changed the chemical settings at a water treatment plant in Oldsmar, Florida.

Oldsmar is still the most cited case study for water sector cyber risk, and it is still disputed. Its lessons apply directly to the 2026 attacks: control systems reachable from the internet, protected by credentials that can be shared, guessed or changed, with no reliable way to verify who is issuing commands.

What is happening to U.S. water systems in 2026?

  • CISA advisory AA26-097A, first issued in April 2026 and updated in July, describes Iranian-affiliated actors linked to the IRGC exploiting internet-exposed PLCs in the water and wastewater, energy and government services sectors. Targeted devices include Rockwell Automation/Allen-Bradley, Schneider Electric and Siemens controllers (Tenable).
  • In Minnesota, some utilities switched to manual operations. The FBI reported a “loss of monitoring and control functionality” after attackers compromised devices connected directly to the internet (Western Water).
  • Investigators described the link between the Minnesota attacks and Iran as preliminary. No degradation of drinking water quality was reported (Tenable).
  • In November 2025, Utah recorded nearly 500 attempted intrusions against state water infrastructure within 46 minutes, traced to an internet signature linked to Iran (Deseret News).

The federal recommendations issued after the July attacks are the same basic controls that would have applied at Oldsmar: disconnect control devices from the public internet, use secure gateways for remote access, use strong unique passwords and maintain the ability to operate manually.

What happened at the Oldsmar water plant?

On February 5, 2021, a plant operator in Oldsmar watched his cursor move across the screen as someone raised the sodium hydroxide setting from about 100 parts per million to 11,100 parts per million. He reversed the change. Pinellas County Sheriff Bob Gualtieri later told reporters that “someone hacked into the system, not just once but twice” (NPR). A Massachusetts advisory for public water suppliers documented the conditions at the plant (Industrial Cyber):

  • SCADA computers ran TeamViewer for remote status checks and alarm response.
  • All the computers shared the same password for remote access.
  • The computers appeared to be connected directly to the internet without firewall protection.
  • The systems ran an end-of-life version of Windows.

Was Oldsmar actually a hack?

In April 2023, former Oldsmar city manager Al Braithwaite called the incident a “non-event” and said it was likely caused by a plant employee. The FBI told CyberScoop that it “was not able to confirm that this incident was initiated by a targeted cyber intrusion of Oldsmar.” The Pinellas County Sheriff’s Office said the case remained open.

The unresolved outcome points to the real weakness. When every workstation uses the same remote access password and sits directly on the internet, there is no reliable way to separate an outside session from an inside one. Investigators could not give a definitive answer to the most basic question: who changed the setting?

How do the 2021 and 2026 incidents compare?

Oldsmar, 2021

U.S. water utilities, 2026

Entry point

TeamViewer on SCADA computers connected directly to the internet

PLCs connected directly to the internet

Credential weakness

One remote access password shared across all computers

Device passwords that attackers could change to lock operators out

Effect

Sodium hydroxide setpoint changed; reversed by an operator

Loss of monitoring and control; some utilities moved to manual operations

Attribution

FBI could not confirm an outside intrusion

Linked to Iranian-affiliated actors; Minnesota link described as preliminary

EPA data collected between the two events shows the same conditions were widespread:

  • More than 70% of water systems inspected by EPA since September 2023 did not fully meet Safe Drinking Water Act Section 1433 requirements, according to EPA’s May 2024 enforcement alert. Default passwords that were never changed were among the issues cited (Nextgov).
  • 97 drinking water systems serving 26.6 million people had critical or high-risk cybersecurity vulnerabilities in an October 2024 EPA Inspector General assessment of 1,062 systems (The Record).

Why do water plants rely on shared passwords?

PKI was never a workable option for most OT environments. Certificate authorities need network connectivity. Certificates need renewal on schedules that small utility staffs cannot sustain. A PKI handshake takes 300 to 700 milliseconds, and many PLCs and RTUs cannot run a certificate stack at all.

Without a practical way to give each device and session its own cryptographic identity, utilities used what was available: shared logins, vendor remote desktop tools and flat networks. Those choices were made for operational reasons. They also leave the operator unable to prove whether a command came from an authorized session.

How does Autonomous Key Management change this?

AKMSecure’s Autonomous Key Management™ delivers encryption and authentication where PKI was never viable. Each condition documented at Oldsmar and in the 2026 attacks maps to a specific AKM capability:

Condition documented in 2021 and 2026

How AKM addresses it

Shared, default or changeable passwords protecting control access

Every session is independently verified with keys that refresh per session. There is no standing credential to share, reuse or steal.

Workstations and PLCs connected directly to the internet

AKM is air-gapped capable. Authentication does not depend on a certificate authority or an outside service.

No reliable way to separate an outside session from an inside one

Every packet is independently verified. Traffic from an unverified source is rejected at the protocol layer.

Legacy, resource-constrained control equipment

A sub-1MB embedded executable and a handshake under 1ms fit controllers that cannot run a certificate stack.

Equipment lifecycles measured in decades

The symmetric-key architecture is quantum-resilient, so protection does not expire with the next cryptographic transition.

AKM does not stop an authorized operator from entering a wrong value. Setpoint limits and process alarms cover that risk, and Oldsmar had pH alarms in place. What AKM provides is Zero Trust at the protocol layer: no implicit trust in any connection and no persistent credentials. In the 2026 attacks, reaching a PLC over the internet and changing its password was enough to lock operators out. Under AKM, commands must arrive through an independently verified session, so network access and a password are not enough to issue them. AKM also supports the zone-and-conduit segmentation that IEC 62443 describes.

What should water utilities do now?

  • Disconnect PLCs and SCADA workstations from the public internet, and route any remote access through secure gateways.
  • Eliminate shared and default credentials on OT systems.
  • Inventory OT assets, as EPA’s 2024 enforcement alert directs.
  • Monitor cellular modems and other remote connections into control networks.
  • Maintain the ability to run the plant manually, as Minnesota utilities did in July 2026.
  • Keep engineering safeguards, such as setpoint limits and process alarms, independent of the control network.
  • Encrypt and authenticate controller traffic at the device level, including on legacy and constrained equipment.

About AKMSecure

AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.