In late July 2026, cyberattacks targeted municipal water and wastewater systems across at least seven U.S. states. More than 30 facilities in Minnesota alone were breached, with additional incidents confirmed or reported in Michigan, South Dakota, and other locations. Attackers gained remote access to internet-facing programmable logic controllers (PLCs), changed IP addresses and passwords, and disrupted operators’ ability to monitor and control critical functions. While authorities have stated there was no evidence of contaminated water supplies, some systems experienced degraded operations, pressure fluctuations, and, in certain cases, boil-water notices that forced utilities into sustained manual workarounds.
These incidents are a stark reminder that critical infrastructure remains an attractive and often soft target. Many water utilities continue to operate aging operational technology (OT) environments where privileged accounts are shared, rarely rotated, or left exposed to the internet. When those credentials are compromised, attackers can manipulate chemical dosing, water pressure, or other essential processes. The fact that these attacks appear opportunistic—hitting whatever systems were reachable—makes the problem even more urgent. Any facility running internet-connected industrial control systems without strong privileged access controls is potentially at risk.
Federal agencies have issued repeated warnings. The FBI, EPA, and CISA have highlighted the targeting of water and wastewater sector devices, urging operators to remove PLCs from direct internet exposure and harden remote access. At the same time, geopolitical tensions have increased the likelihood of state-sponsored probing and disruption campaigns against U.S. critical infrastructure. The recent multi-state activity demonstrates that the threat is no longer theoretical.
Traditional network security measures—firewalls, segmentation, and endpoint protection—remain essential, but they are insufficient on their own. Once an attacker reaches a privileged interface, the ability to change configurations, disable monitoring, or issue destructive commands depends almost entirely on whether privileged credentials and sessions are properly governed.
This is precisely the gap Privileged Access Management (PAM) is designed to close. Kron PAM provides a comprehensive set of controls that directly address the weaknesses exploited in the recent water system attacks.
Standing privileged accounts that remain permanently available create a persistent attack surface. Kron PAM enables just-in-time access so that elevated privileges are granted only for a defined window and only after proper authorization. When the session ends, the elevated rights are automatically revoked. This sharply reduces the window of opportunity for an attacker who manages to obtain or guess credentials.
Many industrial systems still rely on hard-coded, shared, or static passwords stored in scripts, configuration files, or local accounts. Kron PAM vaults these credentials, rotates them on a defined schedule or after each use, and injects them only into authorized sessions. Operators and third-party vendors never need to know or handle the actual passwords, eliminating a common source of compromise.
Water utilities frequently rely on remote operators, system integrators, and maintenance contractors. Kron PAM enforces strong authentication, session isolation, and full session recording for every privileged connection. Security teams gain real-time visibility into what commands are being executed and can terminate suspicious activity immediately. Detailed session recordings also support rapid investigation and compliance requirements.
One of the primary vectors in the recent incidents was internet-facing management interfaces. Kron PAM acts as a secure intermediary, allowing legitimate users to reach OT systems without leaving those systems directly reachable from the public internet. Combined with least-privilege policies and network access controls, this architecture significantly raises the bar for opportunistic attackers.
Beyond preventing unauthorized access, Kron PAM provides continuous insight into privileged activity. Unusual login times, unexpected command sequences, or access attempts from unfamiliar locations can be flagged for immediate review. In an environment where minutes can matter, this visibility supports faster detection and response.
The recent attacks on U.S. water systems succeeded because privileged access was weakly controlled. They also revealed a broader pattern: many critical infrastructure operators still treat privileged accounts as an operational convenience rather than a high-value security asset. As threat actors—whether opportunistic or state-sponsored—continue to scan for exposed industrial systems, the cost of that approach continues to rise.
Kron PAM helps organizations close this gap by placing strong, enforceable controls around the credentials and sessions that ultimately determine whether an attacker can disrupt operations. For water utilities, energy providers, manufacturing plants, and other operators of critical infrastructure, implementing modern privileged access management is no longer optional. It is a foundational step toward resilience.
The multi-state incidents of July 2026 offer a clear warning. The next step is decisive action: inventory privileged accounts, eliminate standing access, remove unnecessary internet exposure, and bring every high-risk connection under continuous control. Kron PAM is built to help critical infrastructure operators take exactly those steps—before the next wave of attacks finds another open door.
Kron PAM, recognized as an Overall Leader in KuppingerCole Analysts’ Leadership Compass: Secure Remote Access for OT/ICS, helps organizations protect critical infrastructure with agentless, time-bound and role-based access controls, secure credential injection, real-time session monitoring, recording, policy-based approvals, and support for OT protocols including Modbus and DNP3. By strengthening privileged access and improving visibility across critical environments, Kron PAM helps organizations reduce identity-based risks and build more resilient OT security strategies. Discover how Kron PAM can help secure your critical infrastructure.