Hackers Silenced The Water Alarms. Insurers Are Being Asked To Fix It.

Estimated reading time: 11 minutes

Attackers did not just lock operators out. Federal guidance says they learned to disable the alarms that warn something is wrong. A proposal wants underwriters to enforce a standard of care that courts already struck down once.

Attackers spent late July inside the control systems of American water utilities. They changed IP addresses. They set passwords on devices that had none. Operators lost the ability to see or command their own equipment.

That is the part that made the news. It is not the worst part.

The Cybersecurity and Infrastructure Security Agency updated its advisory in late July with a further disclosure. The attackers had worked out how to disable the safety features that raise alarms or force a shutdown. An operator can watch a screen reporting normal conditions while the plant is in trouble.

Four days after that advisory, the campaign intensified.

An industrial control panel showing normal flow, pressure and level readings beside a crossed-out alarm bell labeled alarm disabled, illustrating water utility cyber insurance exposure after attackers switched off safety alerts.
The screens read normal. Federal guidance says attackers learned to switch off the alarms behind them. CINI illustration.

What Happened

The Federal Bureau of Investigation and the Environmental Protection Agency issued a public service announcement on July 30. Utilities in at least seven states had reported incidents since July 27, and some of that activity degraded water operations.

The number has moved since. The New York Times reports that at least a dozen states have now filed reports with the FBI, and that at least 100 municipalities have detected malicious activity touching their water systems. However, some of those may be unrelated. There are roughly 150,000 public water systems in the country. Most are small.

The timing has drawn attention. Joe Slowik, director of threat research at Dataminr, told the Times the shift looked like attackers who realized they had been spotted and moved quickly.

The targets were Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series controllers, sitting directly on the public internet.

The Times also surfaced two specific incidents. Clayton County, Georgia, in metropolitan Atlanta, disclosed a July 27 service disruption it attributes to unauthorized cyberactivity. Water pressure dropped. The county issued a precautionary boil-water advisory and restored service within hours. Rapid City, South Dakota, addressed an incident involving a lift station in its wastewater system.

Most utilities kept running by switching to manual operation.

Rockwell published recovery guidance. Restoring a tampered device means cutting power and pulling the battery, which erases the IP address and the program.

SIDEBAR: What Colonial Pipeline Actually Proves

Colonial is the example everyone reaches for. It does not say what people think it says.

Ransomware landed on the company’s business network in May 2021. Colonial shut the pipeline itself, inside an hour. Chief executive Joseph Blount told the Senate Homeland Security and Governmental Affairs Committee the shutdown was meant to isolate the attack and ensure “the malware did not spread to the Operational Technology network.”

He could not confirm it had not already gotten there. So Colonial stopped 5,500 miles of pipe and found out afterward.

Colonial could not tell whether its plant was compromised, so it stopped. The water attacks are worse. Silence the alarm, and the operator is not uncertain. The operator is confident and wrong.

Source: Written testimony of Joseph Blount, June 8, 2021

Why The False All-Clear Changes The Risk

Loss of view is survivable. An operator who cannot see the plant knows it, distrusts the system, and reverts to manual. That reflex is a century old, and it held last week across a dozen states.

A silenced alarm removes the trigger for that reflex. Nobody reverts to anything, because nothing appears to be wrong.

For an underwriter, the two scenarios sit in different severity bands. Loss of view produces a business interruption claim and some overtime. A defeated alarm on a chemical dosing or pressure system produces a bodily injury claim, a recall-style public notification, and a regulatory investigation. Same intrusion. Different loss.

Nothing in the current wave reached that outcome. Officials say drinking water safety was not compromised anywhere.

See also  Cybersecurity Skills Shortage Poses Significant Risks for Small and Mid-Sized Businesses (SMBs)

The Aggregation Problem In The FBI Alert

Two lines in the federal advisory belong in front of anyone modeling portfolio risk.

The FBI found that across several victims, similar network setups supplied by third parties may have let attackers repeat their success from one customer to the next. One integrator’s default configuration becomes a shared failure mode across dozens of insureds.

CISA adds that even utilities with mature security programs should audit their external connections, because vendors and integrators often install cellular modems that never reach the asset inventory.

An insured cannot defend a connection it does not know exists. An underwriter cannot price one either. CINI has covered that failure before. Silent Push found billions of forgotten and misconfigured subdomains sitting on the internet until somebody claimed them: same disease, different organ.

One more detail deserves attention, given the past month of coverage. There is nothing advanced here. The attackers went after internet-facing devices protected by weak or default credentials. After three weeks of disclosures about AI agents reaching past their remit, the campaign that actually degraded American water service used the oldest technique in the file.

Now The Proposal

Into this arrives an argument that insurers should stop waiting for regulators.

Dr. Georgianna Shea is chief technologist at the Foundation for Defense of Democracies Center on Cyber and Technology Innovation and its Transformative Cyber Innovation Lab. She was previously chief engineer at MITRE and served on the cyber-physical resilience working group of the President’s Council of Advisors on Science and Technology. Writing with Stephen Thursby in an FDD Insight published August 4, she argues the gap is professional rather than technical.

A structural engineer owns the building. An electrical engineer owns electrical safety. A fire protection engineer owns life safety. Nobody owns cyber safety.

Her fix is a cyber safety engineer of record, plus an underwriting requirement that projects produce evidence of reasonable care. She puts the goal in language underwriters already use. “The objective is not risk elimination. It is risk engineering.”

Reduce likelihood. Cap severity. Document what remains. Make the claim defensible.

The proposal came out of the 2026 Cyber Safety Summit in Washington, organized by Lucian Niemeyer of Building Cyber Security. Worth stating plainly: FDD is an advocacy institute, and Building Cyber Security develops the kind of standards the article calls for. That is not a knock. The people who build frameworks usually understand best why one is needed. Readers should know where the argument starts.

What Insurers Would Have To Ask For

Shea’s list is the useful part, and an underwriter could put it in a submission tomorrow.

A consequence assessment showing how compromise could affect life safety, property, operations or public services. A registry of every connected controller, vendor-managed device and remotely accessible asset. Design documentation proving cyber requirements reached procurement and architecture. Evidence that remote access, vendor access and recovery procedures were tested rather than merely specified. Commissioning records. A deficiency log with owner sign-off on residual risk. Handoff documentation. Periodic recertification.

The last one matters most. Cyber safety that ends at project delivery is a snapshot, and snapshots do not survive a decade of vendor changes.

Note what is absent. No product. No scanner. It is paperwork, and paperwork is what claims turn on.

That Argument Already Lost Once

Here is the difficulty, and it is not theoretical.

As the Times documents, the EPA proposed cybersecurity requirements for water systems in 2023. Republican-led states and industry groups sued to block enforcement. They argued the agency lacked the authority, and that smaller, underfunded utilities would struggle to meet the standards. The EPA rescinded the order.

Little more than a month later, a small town in western Pennsylvania disclosed that a group tied to Iran’s Islamic Revolutionary Guard Corps had briefly taken control of equipment used to adjust water pressure.

See also  AI In The SOC: Alert Overload, Human Judgment, And Hidden Risk Shape Security’s Next Chapter

So the affordability objection is not a hypothetical risk to Shea’s proposal. It is the argument that already defeated the regulatory version in court, and the sector has spent three years absorbing the consequences. Asking insurers to impose the same requirement through underwriting does not answer that objection. It relocates it.

Two further problems sit underneath.

Carriers cannot create licensure:

Fire codes work because they carry statutory backing, licensed professionals and inspection regimes. Insurers have premium credits and renewal conditions. Those bite in a hard market and evaporate in a soft one. Multifactor authentication became mandatory during the 2021 crunch because carriers could walk away. Cyber is softening. Try it now, and the broker moves the account.

A standard of care cuts both ways:

It gives carriers a benchmark for testing whether an insured behaved reasonably. It also creates errors and omissions exposure for the engineer who signs, and hands plaintiffs an argument against carriers who never asked for it.

There is also a targeting question. If shared third-party configurations multiplied the attackers’ success, the leverage sits with the integrator, not with an engineer of record on each project.

Cyber Insurance News podcast title card reading "You said you had MFA. We did. The claim still failed," with host Martin Hinton and guests Isabel Castillo and Julien Richard of Lastwall.

Watch Our Podcast

Multi-factor authentication matters more today than ever before. More than a decade of breach reports name stolen credentials as the way in. Through one honest checkbox, the humble insurance application is yielding denied claims that were beyond comprehension when an underwriter first asked the question.

The War Exclusion Is No Longer Hypothetical

United States officials suspect Iran-linked hackers are responsible, according to the Times, though that assessment is preliminary and no formal attribution has been made. The United States has been at war with Iran since late February.

That combination is the precise scenario the state-backed exclusion language was written for. Lloyd’s has required such wording in affiliated syndicate forms since 2023. Municipal utilities carry policies on those forms.

The attribution picture is also contested at the highest level. The Times reports that officials briefed states on suspected Iranian involvement, and that the President publicly rejected that account and attributed the Minnesota incidents to the state’s governor instead.

Carriers invoking a war or hostile act exclusion normally lean on government attribution. When intelligence assessments and the President point in different directions, there is no clean authority to cite, and a policyholder has an obvious argument in response.

A small water system could follow every recommendation Shea makes, produce every document, exercise textbook reasonable care, and still find the loss excluded over who pushed the button. That is not an argument against a standard of care. It is a reminder that a standard of care answers a different question than the wording asks. Munich Re flagged the widening threat landscape in its 2026 outlook. Attribution is the part no amount of engineering documentation resolves.

The Tail Nobody Has Priced

Dragos modeled a one-in-250-year operational technology event at $172.4 billion in business interruption losses. CINI covered that analysis when it published. The same research found that tested, operational-technology-specific incident response plans deliver the greatest measurable risk reduction of any single control.

Which is roughly what happened. Utilities that could go manual did.

Joshua Corman of the Institute for Security and Technology told The New York Times the campaign resembled “pre-attack staging, not the attack itself,” and that the level of access obtained was sufficient for considerably more harm than occurred.

Read that next to the disabled alarms. The access was in place. The severity was a choice somebody else made.

There is also no reliable loss data to work from. Congress passed a law in 2022 requiring critical infrastructure operators to report significant incidents within 72 hours. Implementation has been repeatedly delayed. Small utilities may never report to their state, let alone to Washington. Underwriters are pricing a peril whose frequency nobody can observe.

See also  All Things Cyber Liability Insurance With Travelers’ John Menefee

What Comes Next

The Operational Technology Cybersecurity Coalition has called for congressional action, including funding for state and local governments to strengthen defenses. Its executive director, Tatyana Bolton, a former federal cybersecurity policy official, argues the sector has been lucky rather than protected, and that luck is not a strategy.

Grants matter more than standards here. A standard of care without funding is a bill sent to the towns least able to pay it. That was the argument in 2023, and nobody has answered it since.

Elisity chief technology officer Piotr Kupisiewicz made a related point on the CINI podcast, talking through critical infrastructure and the unglamorous hygiene that actually prevents breaches. Nobody gets promoted for an asset inventory. It is still the thing that would have found the modem.

FAQ – Water Utility Cyber Insurance

What happened to US water utilities in July 2026?

Attackers accessed internet-facing programmable logic controllers at water and wastewater utilities, changing IP addresses and setting passwords so operators lost monitoring and control. The FBI and EPA issued a public service announcement on July 30. At least a dozen states have since reported incidents.

Could the attackers turn off safety alarms?

CISA disclosed in late July that the attackers had found a way to disable safety features that raise alarms or force a shutdown. That means an operator could see normal readings on screen while the system was in trouble.

Which devices were targeted?

Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers connected directly to the public internet, typically protected by weak or default credentials.

Was drinking water made unsafe?

No water system is known to have been altered in a way that made drinking water unsafe. Some incidents caused pressure loss, manual overrides and precautionary boil-water advisories.

Who was responsible?

United States officials suspect Iran-linked hackers, but the assessment is preliminary, and no formal attribution has been made. The President has publicly disputed that account.

Why does attribution matter for insurance?

Most cyber policies carry war and state-backed actor exclusions, and carriers normally rely on government attribution to invoke them. A contested attribution leaves both carrier and policyholder without a clear authority to point to.

What is a cyber safety standard of care?

A proposal that connected systems should be designed, documented, commissioned and maintained by a responsible engineer, producing evidence insurers can use to assess whether reasonable care was exercised.

Has this been tried before?

The EPA proposed cybersecurity requirements for water systems in 2023. Republican-led states and industry groups sued, arguing the agency lacked authority and that small utilities could not afford the standards. The EPA rescinded the order.

Leave a Comment

×