— WATER-UTILITY CYBERSECURITY • FLORIDA GUIDE
Cyberattacks are disrupting water utilities. What should Florida residents know?
A July 30 FBI and EPA warning says attackers accessed internet-facing industrial controllers at water and wastewater utilities in at least seven states. Some incidents degraded operations—but the agencies did not identify the affected states, name a Florida utility or report contaminated drinking water in Florida.
- A cyberattack can interfere with equipment used to monitor pressure, pumps and treatment processes.
- A system intrusion does not automatically mean drinking water became contaminated. The actual impact depends on the device, its function, physical safeguards and the utility's ability to operate manually.
- Florida residents should act on a named utility or health notice—not a national warning alone.
What happened in the 2026 attacks?
The FBI and EPA said that beginning July 27, water and wastewater utilities in at least seven states reported attacks on internet-facing programmable logic controllers, or PLCs. The warning specifically identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 devices, while advising operators to consider similar risks with other brands.
According to the agencies, attackers changed device IP addresses and passwords. That caused some utilities to lose monitoring or control functions. Reported operational effects included pressure loss and flooding. The consequences varied depending on whether the compromised device merely monitored equipment or controlled it, what equipment it supported and whether operators could switch to manual operation.
The FBI and EPA did not publish the names or locations of the victim utilities. Florida Tap Report found no basis in the warning to label any Florida water system compromised or unsafe.
Could a cyberattack change tap-water safety?
Potentially—but that is not the same as saying every cyber incident contaminates water. EPA says a successful attack on vulnerable operational technology could disrupt treatment, distribution or storage; damage pumps and valves; or alter chemical levels. The July warning adds that pressure loss can create a pathway for untreated groundwater to enter damaged or compromised pipes.
Utilities use operators, alarms, sampling, treatment barriers and emergency procedures to detect and respond to abnormal conditions. An attack that locks an operator out, interrupts billing or forces manual operation may be serious without producing unsafe water. The public-health question depends on what physically happened to the water system, not merely whether a computer was accessed.
Would residents receive a boil-water notice?
A utility may issue a precautionary boil-water notice when pressure drops, a main breaks or another event creates a credible risk that microorganisms could enter the distribution system. If a cyber incident caused that kind of physical condition, the public instruction would come through the affected utility and local or state health authorities.
A boil-water notice should not be assumed from a cyber headline. Boiling addresses microbial risk; it does not correct every chemical or operational problem. Residents should follow the exact wording, affected boundaries and ending notice issued by officials.
What about the widely reported Oldsmar incident?
In February 2021, officials in Oldsmar, Florida, initially reported that an unauthorized remote user changed a sodium-hydroxide setting at the city's water treatment plant. The change was reversed and officials said the public was not harmed.
The later record requires caution. CISA's advisory says the FBI was not able to confirm that the event began as a targeted cyber intrusion. That means Oldsmar should not be repeated as a proven outside cyberattack. It remains a useful example of why remote access, operator oversight and independent treatment safeguards matter, but not proof that an attacker poisoned a Florida water supply.
How serious is the national weakness?
EPA reported in 2024 that more than 70% of the community water systems it had inspected since September 2023 were violating basic federal risk-and-emergency-planning requirements. Inspectors found problems such as unchanged default passwords, shared staff logins and access that had not been removed for former employees.
The U.S. Government Accountability Office also found growing cyber risk across a highly fragmented water sector with older technology, limited cybersecurity investment and workforce gaps. EPA has since completed a sector risk assessment and risk-management plan, but GAO continues to list gaps in federal authority affecting small drinking-water and wastewater systems.
These are national findings. They do not establish that 70% of Florida utilities are vulnerable or out of compliance.
What are utilities being told to do?
Federal guidance starts with basic controls: remove industrial controllers from direct public-internet exposure, place remote access behind secure gateways and firewalls, use strong unique passwords, restrict communications to authorized devices, review logs and replace or isolate unsupported equipment.
EPA, CISA and the FBI also recommend cybersecurity assessments, inventories of information and operational technology, tested incident-response plans, reliable backups, vulnerability reduction and staff training. Under the Safe Drinking Water Act, community water systems serving more than 3,300 people must assess physical and cyber risks, maintain emergency-response plans and recertify them on a five-year cycle.
What should a Florida resident do?
- Confirm the utility that serves your address. A city mailing address does not always identify the water provider.
- Use official notices. Check the utility, county emergency management and Florida Department of Health sources before sharing an unverified warning.
- Follow the stated boundaries. A disruption at one facility or pressure zone should not be expanded to an entire city or county.
- Do not invent a treatment response. A household filter or boiling instruction depends on the confirmed water problem; neither is a universal answer to a cyber incident.
- Wait for rescission. If officials issue a precautionary notice, continue following it until the responsible agency formally lifts it.
The bottom line
Cyberattacks on water utilities are a documented operational threat, and the 2026 FBI-EPA warning shows that exposed control equipment is being actively targeted. But a national cyber warning is not a Florida contamination alert. The responsible response is to separate computer access from physical water consequences and publish a Florida warning only when an authoritative source identifies the affected system and the action residents should take.
Check current verified Florida water alerts →
Find your utility and official water report →
Understand detections, limits and drinking-water safety →
Published September 13, 2026 · No corrections posted.
This page will be updated if federal or Florida authorities identify an affected Florida water system, issue new public instructions or materially revise the July 2026 warning.
Sources
- FBI and EPA: July 30, 2026 warning on attacks targeting water-sector controllers
- U.S. EPA: drinking-water systems must address cybersecurity vulnerabilities
- U.S. EPA: cybersecurity guidance and assistance for the water sector
- U.S. Government Accountability Office: cybersecurity risks to water and wastewater systems
- CISA: Oldsmar investigation and water-treatment-facility advisory