Water infrastructure is becoming one of the most important fronts in modern conflict. The July 2026 CISA advisory confirmed attacks on more than one hundred U.S. water systems, and past incidents like Oldsmar and Israel’s attempted 2020 chlorine manipulation show how easily dosing and pressure can be tampered with. Three hypothetical scenarios extend the threat further, from a collapse of public trust in a major city to a tourism sabotage campaign to a cascading data center failure. Deception technology is built for exactly these scenarios, turning every intrusion attempt into intelligence before it ever touches a real system.
Prologue: The Fragility We Never Saw
“Insanity is doing the same thing over and over and expecting different results.”
Water has always been a major critical‑infrastructure risk. Security teams spent decades refining firewalls, EDR, XDR, SIEM alerts, patch cycles, and signatures, while water systems remained exposed to natural failure, digital interference, and public panic. Some nations manufacture their drinking water; others treat what nature provides. Both systems can be attacked, but they fail in very different ways.
Desalination nations cannot store their water, it must be produced continuously, kept moving, kept pressurized, kept alive. Natural‑water nations cannot manufacture supply, they can only clean what nature provides, and contamination spreads faster than truth. This imbalance shapes what follows.
The Global Water Divide: Makers vs Takers
Across the world, nations fall into two categories: Water Makers and Water Takers. Water Makers rely on desalination, manufacturing water from seawater through membranes, pumps, and continuous production. Their resilience depends entirely on machinery, and when disrupted, they fail instantly. Water Takers rely on rainfall, rivers, reservoirs, and aquifers. Their resilience comes from nature, storage, and distribution, and when disrupted, they fail slowly but painfully. This divide determines how a nation may collapse under pressure and how an adversary might exploit that collapse.
Real‑World Water Infrastructure Security Incidents
These are verified events, not hypotheticals, that demonstrate how fragile water systems and water infrastructure security already are. They are real, documented, and publicly reported.
Real‑World Incident 1 | CISA July 2026 Water System Attacks
On July 30, 2026, CISA issued an alert warning of a significant increase in threat actors targeting internet‑exposed programmable logic controllers in the water and wastewater sector. Attackers modified PLC passwords to lock operators out and changed device IP addresses to disconnect the controllers, resulting in boil water notices and sustained manual operations at affected utilities. Three weeks later, in Internet Exposure Reduction guidance published August 21, CISA put a number on it: malicious activity targeting over 100 internet‑exposed systems in the sector during July alone, most commonly through PLCs connected directly to a cellular modem. It was the first time a federal agency had publicly quantified the scope of this wave. CISA has not attributed the activity to any government or group, though reporting has linked it to suspected Iranian actors, with targeting confirmed in at least a dozen states, including Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama, mostly at small, rural utilities. Nothing about the technique was new. Internet‑exposed controllers, default credentials and weak segmentation are problems the OT security community has documented for years; what changed was the scale. The attacks reached organizations of every size, and CISA warned that even utilities with mature cybersecurity processes should validate their external connections, because the targeting included cellular modems installed by operators, vendors or integrators that were never documented or included in routine attack surface scans.
Reference: CISA Alert, July 30, 2026: CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs and SecurityWeek, August 2026: CISA: Over 100 Internet‑Exposed Water Systems Targeted in July Cyberattacks
Real‑World Incident 2 | Oldsmar, Florida
In February 2021, the Pinellas County Sheriff announced that an intruder had remotely accessed the Oldsmar water treatment plant and changed the amount of sodium hydroxide in the water from about 100 parts per million to 11,100 parts per million. The operator immediately reduced the chemical to the proper level and alerted a supervisor. The incident prompted a joint federal advisory and a four‑month FBI investigation. Two years later, the story changed. The FBI said it was not able to confirm the incident was initiated by a targeted cyber intrusion, and former City Manager Al Braithwaite said publicly that there was no attack, describing it as a “nonevent” likely caused by employee error. Whatever happened in the control room that day, the setup that made the story believable was real: a treatment console reachable through remote‑access software, with a single operator as the last line of defense. That is the lesson that survives the correction, and it is why the sector has spent five years using Oldsmar as its warning.
Reference: CISA Advisory AA21‑042A (Oldsmar Water Treatment Facility) and Tampa Bay Times, April 11, 2023: Cyberattack on Oldsmar’s water supply never happened, official says
Real‑World Incident 3 | Israel, April 2020
On April 24 and 25, 2020, an attempted cyberattack aimed at disrupting water supplies in at least two locations in Israel was detected and thwarted before it could cause damage. Six Water Authority facilities were targeted, and the attackers attempted to increase the amount of chlorine in the water supply to dangerously high levels. The intrusion was noticed after water pumps began malfunctioning and focused on the operational systems and mechanisms for adding chlorine to wells. Israeli and Western officials said the hackers penetrated software controlling water pumps after routing their activity through American and European servers to conceal its origin. Had it succeeded, the manipulation could have triggered safety systems to shut down the pumps, leaving thousands without running water during a heatwave, or sickened hundreds of people. Yigal Unna, head of Israel’s National Cyber Directorate, said the attack could have had disastrous consequences by injecting the wrong proportions of chemicals into the water. Israel never formally attributed it, and Iran denied involvement. The pressure did not stop there: in July 2020, a further attempt targeted two small facilities in the Upper Galilee, this time hitting agricultural pumps. What began as an attempt on drinking water became a pattern of repeated probing of the same national system.
Reference: NATO CCDCOE Cyber Law Toolkit: Israel’s water facilities attack (2020) and The Washington Post, May 8, 2020: Foreign intelligence officials say attempted cyberattack on Israeli water utilities linked to Iran
Convergence: Water as Battlespace
Across real incidents and hypothetical futures, one truth emerges: modern conflict may not begin with bombs or bullets, it could begin with water.
With parts of the UK still under hosepipe bans and reservoirs sitting at reduced levels, water scarcity has moved from a Middle East and California story into a developed-economy problem. As drought becomes more frequent and desalination dependency grows, water is shifting from background utility to strategic commodity, and strategic commodities attract adversaries.
As we have seen, water is a resource, but it’s also a measure, a foundation of economic stability, a dependency for digital continuity, and a pillar of national security. When water fails, everything built upon it begins to fracture, and the world is not ready for how quickly that fracture can spread.
Data centers are the physical layer under banking, encryption, government services, aviation and logistics, and many of them run on water. According to Lawrence Berkeley National Laboratory’s 2024 United States Data Center Energy Usage Report, US data centers directly consumed 66 billion liters of water in 2023, up from 21.2 billion liters in 2014, with hyperscale and colocation facilities accounting for 84% of the total. LBNL projects that hyperscale data centers alone will consume between 60 and 124 billion liters annually by 2028.
At the top end, single sites are heavy users: Google’s largest data center, in Council Bluffs, Iowa, withdrew an average of 3.9 million gallons of water and consumed 2.8 million gallons per day. The dependency is uneven. Legacy facilities often consume large quantities of water through open evaporative cooling towers, while newer data centers can use little to no water by deploying waterless and hybrid heat rejection systems. For the sites that do depend on water, the risk is simple: cooling towers need continuous supply, and an interruption in supply or pressure becomes a thermal problem for the servers inside. Water is both a physical resource and a digital one.
Deception: A Defense Made for Agentic Attacks
AI changed the game. Attackers no longer need brilliance; automation is enough. Traditional defenses fail because defenders keep doing the same thing. Deception, however, is not the same thing…it’s a very different approach to defense. A water‑plant attacker enters a dosing console, but it is a digital twin. They manipulate chlorine levels, but the readings are fake. They pivot to pump pressure, but the system is simulated. They escalate, but every step is observed, logged, captured, and analyzed. Every move becomes intelligence, and the real plant stays untouched. Deception detects attacks and gains real-time threat intel from the attacker, stopping the collapse of trust that follows. In a world where water is a potential battlespace, deception is the last sane line of defense.
The July 2026 CISA advisory revealed that more than one hundred U.S. water systems were attacked through internet‑exposed PLCs connected directly to cellular modems, simple access paths that deception can neutralize instantly. When attackers connect to a controller that is actually a digital twin, their reconnaissance becomes intelligence, their intrusion becomes telemetry, and their attack chain becomes a map of intent. Deception turns exposure into advantage, transforming vulnerable infrastructure into an early‑warning system.
CounterCraft builds AI directly into the platform to meet this. Environments can be AI-generated to be believable, complete with the departments, reporting lines, and digital footprint an attacker would expect to find, so a probing AI agent has no way to tell decoy from reality. That believability is the point: AI attackers are hungry, pushing further into whatever looks real rather than hesitating at a signature or waiting on human judgment, and every one of those pushes becomes a captured, analyzed interaction. The same automation that makes AI attackers fast and relentless is what makes them easy to study once they’re inside an environment built to be entered.
Water is life. Water is a digital civilization. Water is national security. And nations that protect their water with deception will be the last nations to fall.
