State officials have confirmed that at least one water district in Oregon experienced unauthorized access to its core operating technology. This incident is part of a broader wave of cyber attacks targeting municipal water and wastewater systems across multiple states. While state leadership is currently evaluating the impact, they have not identified the specific district involved in the breach.
The Federal Bureau of Investigation has been monitoring these events, noting that malicious actors are targeting programmable logic controllers. These small computers manage industrial equipment, and unauthorized access allows hackers to change passwords or IP addresses. Such actions have led to operational issues in other regions, including pressure loss and potential contamination risks when untreated water enters the distribution system.
Governor Tina Kotek’s office stated that the administration is working with federal investigators to address these security concerns. Local water providers across Oregon are now under increased scrutiny as officials emphasize the importance of limiting remote access and maintaining manual backup plans for system operations. While major providers like the Portland Water Bureau acknowledge ongoing cybersecurity threats, they remain limited in what they can disclose regarding specific recent attempts.
Water infrastructure remains a critical target for bad actors, and the national scope of these attacks highlights the vulnerability of local utilities. Operators are being encouraged to tighten security protocols and harden their systems against internet-facing threats to ensure the safety of public water supplies.

