On July 30, 2026, the FBI and the EPA published a short warning to American water utilities.¹ Most of it is pretty routine but one line is not. When attackers seize a programmable logic controller and a water system loses pressure, untreated groundwater could seep into the pipes.
Somebody changes a password on a piece of industrial equipment, and the water coming out of a tap is no longer the water anyone tested.
Since July 27, utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.¹ The advisory does not name the states. It does describe precisely how the attacks work: internet-facing Rockwell Automation MicroLogix controllers, accessed remotely, IP addresses and passwords changed, operators locked out of the ability to see or control their own equipment. Reported effects included loss of pressure and flooding. At least one organization noticed ladder logic discrepancies across several sites and then found its PLC project files had been modified. Across several victims, the FBI notes something worse: similarities in network setups supplied by third parties, which the bureau warns may let attackers multiply their successes across a vendor’s customer base.
On July 31, President Trump addressed it from Camp David — the presidential retreat in Frederick County, Maryland — at the start of a Cabinet meeting. He said he did not believe there had been an Iranian cyberattack. He blamed Minnesota instead, “because they’re grossly incompetent,” and said he thought the governor was behind it.² As of this writing, no federal agency has officially publicly attributed these attacks to anyone. The FBI advisory names no country and no actor. US and state officials are treating Iran as one of the suspects, and investigators are also examining whether someone wanted the work to look Iranian.² ³
That argument will run for weeks and it will settle nothing this month. Attribution is slow, it is technical, and it belongs to the people holding the evidence. There is a different question available right now, and answering it does not require knowing who turned the valve.
In March 2023, the EPA told states that existing regulation already required them to evaluate the cybersecurity of operational technology when auditing public water systems. Missouri, Arkansas, and Iowa petitioned the Eighth Circuit, with the American Water Works Association and the National Rural Water Association intervening.⁴ On July 12, 2023, the court stayed the memo. On October 11, 2023, EPA Assistant Administrator Radhika Fox issued a one-page memorandum withdrawing it.⁵
Check that page out for yourself, because the agency indicts itself inside a single paragraph. EPA writes that cybersecurity attacks on water and wastewater systems occur frequently and pose a significant threat to their operations. The next sentence encourages states to voluntarily review those programs.
Serious threat. Voluntary response. Consecutive sentences.
The water associations were not making a frivolous argument. Sanitary surveys carry public notification requirements, so a documented cybersecurity deficiency becomes a published map to the weakness. State drinking water inspectors are trained to find cracked wellheads, not exposed controllers. Those objections were real. The trouble is what filled the space after EPA withdrew it — nothing.
Do you want to know what Maryland did with that space? Something genuinely good.
Senate Bill 871 passed the Senate 42 to 0 and the House 140 to 0. Governor Moore signed it on May 13, 2025, as Chapter 495, effective October 1, 2025.⁶ It created a new subtitle of the Environment Article, made MDE the coordinating agency alongside DoIT and MDEM, required incident reporting to the State Security Operations Center, and set a hard deadline.
The deadline sits in Environment Article § 9-2705(b)(3). Covered systems had to conduct a maturity assessment of their cybersecurity program for operational technology and information technology, on or before July 1, 2026.⁷
That is a critically important law, passed unanimously, in a state that saw the federal retreat and decided not to wait. That’s worth noting before we continue.
In April 2026, three months out from the deadline, MDE published its implementation guidance.⁸ Section 6.0 tells utilities to submit the completed assessment to MDE and DoIT through a secure website or email, “which is currently under development and will be shared with water systems once available.” The following sentence tells them they do not need to submit the completed assessment tool until that secure submission method is in place.
Maryland wrote the deadline into statute, then told the regulated community to hold the paperwork, because the state had not finished building the place to send it. As of today, MDE’s water sector cybersecurity page still reads “Last Updated: 04/2026.”⁹ It carries a downloadable assessment spreadsheet and an incident reporting link.
It carries no submission portal.
MDE will say — correctly — that it deferred only the submission and never the assessment. Every covered system was still obligated to complete one by July 1. That is true, and it makes this worse rather than better. If those assessments were done on time, the state cannot demonstrate it. There is no date on which anyone can say how many systems complied, because there was no place to record it.
Now watch it close.
The same act rewrote Maryland’s Public Information Act. General Provisions § 4-338(b) already required custodians to deny inspection of records containing information about the security of an information system. Chapter 495 extended that to operational technology and critical infrastructure, then added the words that do the real work: including any records of a community water system or community sewerage system.⁷
That language was not in the bill as introduced. It arrived in an amendment from the Education, Energy, and the Environment Committee, adopted on the Senate floor on March 14, 2025. The same amendment struck the requirement that the assessments be conducted by a third party.¹⁰
Not the vulnerability. Not the assessment findings. Any records.
The incident report DoIT must publish by January 1, 2027 is barred by statute from identifying which systems were affected.⁷ MDE’s own report to the General Assembly on water system compliance came due July 1, 2026, the same day as the assessments.⁷ That report has not surfaced publicly.
I spent fifteen years writing and auditing this exact kind of control documentation across CMS, the FDA, and the VA. There is a failure mode everyone in that work recognizes on sight: a requirement that exists on paper with no evidence pipeline behind it. It survives every review. It protects nothing. And it is a fucking liability, because every person downstream proceeds as though the control is working.
Three things need to happen. Two of them require nothing but a decision.
MDE should publish its § 9-2708 compliance report now. If it has not been written, the department should say so plainly and give a date.
DoIT should state publicly whether the secure submission portal exists today, and if it does, publish the date it went live and how many certifications it has received. Aggregate counts identify no system and expose no vulnerability.
And the General Assembly should reopen § 4-338 in the 2027 session. There is an enormous distance between withholding the specific defect at a specific plant and denying any records of a water system. The second one shields no infrastructure. It only keeps people from looking.
There was not a single no vote in either chamber. That unanimity was not an accident, and it was not wrong. The law is sound. The plumbing behind it was never finished, and the mechanism that would have let the public notice was written shut before anyone could reach for it.
Utilities in at least seven states reported incidents to the FBI this week, some of them locked out of their own equipment. We do not know whether any of them were here. That is the problem and it needs to be fixed.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.