<script type="application/ld+json">
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Was the American Water incident ransomware?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Nobody knows. No group has ever claimed it, the word appears in no American Water SEC filing in the company's history, and the company has never characterized the incident. Accounts calling it ransomware trace back to a security executive's explicitly labeled speculation on October 10, 2024, which lost its hedge as it was repeated."
}
},
{
"@type": "Question",
"name": "How did the attackers get in?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No vector has ever been publicly established by the company, any regulator, or any investigating body. Any specific mechanism attributed to this incident is a downstream inference."
}
},
{
"@type": "Question",
"name": "Were water treatment operations affected?",
"acceptedAnswer": {
"@type": "Answer",
"text": "American Water stated it 'currently believes' and later that it 'continues to have no indication' that its water and wastewater facilities were impacted, and, separately and without qualification, that water quality was not affected. It never issued a confirmation that operations were unaffected, and that distinction is worth preserving."
}
},
{
"@type": "Question",
"name": "Was customer data stolen?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The company stated that customer Personal Information, as defined by the data breach notification laws of the fourteen states where it has regulated operations, 'was not impacted as a result of the incident.' It never offered credit monitoring. No breach notification from American Water has been located in any searchable state Attorney General registry. Putative class actions allege exfiltration, but the allegation is pleaded as the plaintiff's belief, and no court has made a finding on the question."
}
},
{
"@type": "Question",
"name": "Why did billing go down if the plants were fine?",
"acceptedAnswer": {
"@type": "Answer",
"text": "American Water disconnected and deactivated systems as a containment measure, including its MyWater portal and billing platform. Our read, and we flag it as a read rather than a disclosed fact, is that the business estate could not be confidently bounded, so separating it from the operational environment required taking it down."
}
},
{
"@type": "Question",
"name": "How long was the outage?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Unauthorized activity was identified on October 3, 2024 and reactivation was announced on October 10, 2024. About a week. No late charges were issued for the period."
}
},
{
"@type": "Question",
"name": "Who attacked American Water?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Nobody knows. The only congressional document naming the incident describes 'an unidentified cyber threat actor.' No attribution to any nation-state or criminal group has ever been made by anyone with standing to make it."
}
},
{
"@type": "Question",
"name": "Why does this entry say 'Vector undisclosed'?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Because the incident is documented and its mechanism is not. We use this status where a victim, regulator or investigator has confirmed that something happened but nobody has ever stated how. It is distinct from 'Contested,' which we reserve for incidents where named parties have given materially conflicting accounts, as at Oldsmar in 2021."
}
},
{
"@type": "Question",
"name": "What did BlastWave get wrong, specifically?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Earlier versions of this entry listed the attacker as 'Unknown Ransomware,' the vector as 'phishing, unpatched systems, or supply-chain compromise leading to ransomware installation,' and the root cause as 'Weak Credential,' and said the company had 'confirmed' its OT and water quality were unaffected. None of that was established. Two of the three listed vectors have never been asserted as the vector for this incident by anyone, and the root cause traces back to speculation in a single vendor blog. We printed it as determinations."
}
},
{
"@type": "Question",
"name": "Does this mean nothing happened?",
"acceptedAnswer": {
"@type": "Answer",
"text": "No. American Water disclosed to the SEC that it identified unauthorized activity and determined it to be a cybersecurity incident, notified law enforcement, and disconnected systems. Nothing in that account has ever been disputed. What is missing is the mechanism, not the event."
}
}
]
},
{
"@type": "HowTo",
"name": "What To Do About It: Ten Steps for a Water Utility",
"description": "Ten practical steps water utilities can take to reduce cyber risk, strengthen IT/OT separation, improve OT access controls, rehearse containment decisions, and avoid publishing unsupported incident claims.",
"step": [
{
"@type": "HowToStep",
"position": 1,
"name": "Inventory every path from the business network to the operational network",
"text": "Inventory every path from your business network to your operational one, including vendor remote access, historian replication, engineering workstations that sit on both, and anything inherited through an acquisition. The list is always longer than the diagram."
},
{
"@type": "HowToStep",
"position": 2,
"name": "Test every path against full corporate compromise",
"text": "For each path, ask what happens if the corporate side is fully compromised. If the answer depends on a credential that also exists on the corporate side, that path does not survive the scenario you are defending against."
},
{
"@type": "HowToStep",
"position": 3,
"name": "Make the OT environment unreachable by default",
"text": "Make the OT environment unreachable by default, so it returns nothing to an unauthorized source. An intruder cannot shorten reconnaissance against a network that does not answer."
},
{
"@type": "HowToStep",
"position": 4,
"name": "Replace shared and password-based OT access",
"text": "Replace shared and password-based access to OT with certificate-based, per-user, per-device authentication. Remove the secrets that a business-network compromise would hand over."
},
{
"@type": "HowToStep",
"position": 5,
"name": "Authorize by identity and device posture",
"text": "Authorize by identity and device posture, not by network position or IP range. Flat segments and forgotten address space stop mattering the moment position confers nothing."
},
{
"@type": "HowToStep",
"position": 6,
"name": "Define who can order a disconnection",
"text": "Write down who can order a disconnection, and what happens when they are unreachable. Then treat the existence of that document as evidence of a design problem rather than as a mitigation."
},
{
"@type": "HowToStep",
"position": 7,
"name": "Set engineering limits that hold independently",
"text": "Set engineering limits that hold regardless of what a control system is told. Pump sizing, valve gearing, reservoir volume, and setpoint clamps answer the intrusion case and the operator-error case at once."
},
{
"@type": "HowToStep",
"position": 8,
"name": "Choose controls that deploy in front of existing equipment",
"text": "Choose controls that deploy in front of existing equipment, with no changes to PLCs, HMIs or IP schemes, and that one team can manage centrally across every site. Anything requiring local staffing will not reach the 91% of systems serving 10,000 people or fewer."
},
{
"@type": "HowToStep",
"position": 9,
"name": "Rehearse the containment decision",
"text": "Rehearse the containment decision on a holiday weekend, with the primary decision-maker deliberately unavailable. The exercise is not about response time. It is about discovering how much of your safety currently lives inside one person's availability."
},
{
"@type": "HowToStep",
"position": 10,
"name": "Apply the same evidence standard to incident publishing",
"text": "Apply the same standard to what you publish about incidents as to what you deploy. If the record does not say it, do not print it in a field. Somebody downstream will cite your field."
}
]
}
]
}
</script>
On 3 October 2024, the largest regulated water utility in the United States found unauthorized activity on its corporate network and took its own billing systems offline for about a week to protect plants it had no indication the intruder had reached. Nobody has ever said how it happened. That did not stop the sector from knowing, nor did it stop us. This entry corrects our own initial entry.
The JLR anniversary blog taught me a lot about hacks in the OT space. The initial reports were unsourced, and we repeated them. We have been conducting a new accounting of all OT incidents since then. The next Hackopedia anniversary update also needs some edits.
Until now, the Hackopedia entry for American Water listed the attacker as "Unknown Ransomware." It listed the attack vector as "phishing, unpatched systems, or supply-chain compromise leading to ransomware installation." It listed the root cause as "Weak Credential." Its body said the company had confirmed its operational technology and water quality were unaffected.
None of that is established. No group ever claimed this incident. The word "ransomware" appears in no periodic report or current report filed by American Water Works Company, Inc., in the company's entire history. No vector has ever been stated by the company, the EPA, CISA, the FBI, or WaterISAC. The company did not confirm anything about its plants; it said it "currently believed" and then that it had "no indication," two different hedges on two different days, and neither is a confirmation.
Two of the three vectors we listed have never been asserted by anyone as the vector for this incident. Not hedged, not floated by a researcher and later walked back. The root cause traces back to a single sentence of speculation in a vendor blog that cites no sources at all. We printed all of it as determinations, under a "Contested" flag that every field beneath it contradicted. A hedge the fields contradict is not a hedge. It is a decoration.
So the entry is being rebuilt, and the rebuild starts with a question I think is more useful than "what hit American Water." The question is: if nobody ever said what hit American Water, how does everybody know?
I can answer that one to the day. It took forty-eight.
The confirmed record here is short, and its shortness is the point. Everything below comes from American Water or from a federal document.
The company found unauthorized activity on its corporate network on 3 October 2024. Its Form 8-K, filed four days later, reads: "On October 3, 2024, American Water Works Company, Inc. (the 'Company') learned of unauthorized activity within its computer networks and systems, which the Company determined to be the result of a cybersecurity incident." It activated incident response, engaged third-party experts, and notified law enforcement.
It did not file this as a material cybersecurity incident. Item 1.05 is the SEC's disclosure item for those. Both of American Water's 8-Ks went under Item 8.01, Other Events, and Items 7.01 and 9.01. That is a permitted choice where materiality has not been determined, so read it carefully rather than dramatically. But four months later, the annual report closed the loop, stating that the company "has not experienced a cybersecurity incident that has resulted in a material impact."
The response was a self-imposed business outage. American Water disconnected and deactivated systems, took its MyWater customer portal offline, and paused billing. Customers could not pay. The company did not issue any late charges for the duration. Reactivation was announced on 10 October 2024, about a week after detection.
The company's language about its plants was hedged twice, in different ways. The 7 October filing: "The Company currently believes that none of its water or wastewater facilities or operations have been negatively impacted by this incident." The 10 October release: "The Company continues to have no indication that its water and wastewater facilities were impacted by this incident." One is an assessment. The other is a statement about the evidence in hand, which is a weaker thing to say and an honest thing to say a week into an investigation. Most coverage printed a stronger version than either document contains, and so did we.
The one unhedged operational claim is narrower than people remember. In the same 10 October release: "The incident did not affect water quality." That is a flat statement, and the company has never qualified it. It is also a claim about the water, not about the control systems, and the difference matters.
On customer data, the company said something more specific than it is usually quoted as saying. Its IT security FAQ reads: "The Company has determined that customer Personal Information (PI), as that term is defined by the state data breach notification laws in the states in which we have regulated operations (i.e., NJ, PA, MO, IL, IN, IA, WV, VA, CA, HI, KY, TN, GA, MD), was not impacted as a result of the incident." That is a statement about a statutorily defined category of data in fourteen named states. It is not "no customer data was affected," and I am not going to compress it into that, because compressing other people's hedges is what this article is about. No credit monitoring was offered, and no breach notification from American Water has been located in any searchable state Attorney General registry, with the caveat that Maine's public registry is currently offline.
No actor has ever been identified. CyberScoop, on the day of the filing: "No ransomware gang has claimed responsibility for the attack on the company, which has operations in 14 states and serves at least 18 military installations." The Record, the same day: "The attack on American Water Works has not been claimed by any ransomware gang or hacker group as of Monday afternoon." Twenty-three months later, nothing has surfaced.
The only federal characterization says the same thing. The House Committee on Homeland Security's Cyber Threat Snapshot of 12 November 2024 is the only congressional document that names the incident. Its description: "The networks of one of the country's major water utilities were breached by an unidentified cyber threat actor, forcing the company to shut down the online customer portal and billing services for days in an attempt to protect customer data." Unidentified. No vector. No ransomware. Note in passing that Congress's read of the motive, protecting customer data, is not the same as mine, and neither of us is sourced.
The scale is why anyone cared. American Water's own October 2024 figures: more than 14 million people served, regulated operations in 14 states, and 18 military installations. The military number moved this from a trade story to a national one.
That is the record. A detection, a disconnection, a reconnection, two hedges, one flat statement about water quality, one carefully bounded statement about data, and silence.
Here is the part I find genuinely useful, and the reason this entry is worth rewriting rather than quietly amending.
Because this incident is recent, because the coverage is thin, and because almost nobody followed up, the sequence is short enough to lay out completely. Every item below is dated, public, and still online.
One caution before I start. This is a sequence of dated publications, not a documented causal chain. The later pieces mostly cite nothing, so I cannot prove any of them read the earlier ones. What I can show is what was said, when, and how much hedging survived each step.
7 October 2024. The 8-K. Nothing asserted. No vector, no classification, no actor.
7 October 2024. CyberScoop reports the explicit negative. No gang has claimed it. Worth noting that the article's permanent web address is /american-water-works-cyber-ransomware/. The slug carries the keyword the article exists to negate. I do not think that was deliberate, and I do not think it was harmless.
10 October 2024. The earliest dated attribution. IT Pro published a piece by Solomon Klappholz titled "Cyber expert suggests American Water cyber incident was a ransomware attack." The expert was Kevin Kirkwood, Chief Information Security Officer at Exabeam, and this is what he said, in full:
"If I had to speculate, I would say that American Water was potentially the victim of a ransomware event. The firm mentioned they shut down their billing systems, which points back to internal corporate backend systems. Given the large segment of water and wastewater treatment facilities that American Water covers, if control systems had been compromised, we'd likely be hearing about plants shutting down and advisories to boil water across states."
Read that on its own terms. It is a careful, well-reasoned answer to a reporter's question. Kirkwood labels it as speculation, then hedges it again in the same sentence, shows his work, and arrives at the right structural conclusion: the plants were probably fine, and here is how you would know. If you asked me to write a responsible one-paragraph assessment of a thinly disclosed incident four days in, I would be pleased to have written that one.
Nobody did anything wrong at this point. That is what makes it the interesting item in the sequence. The failure downstream is not that somebody said something reckless. It is that a sentence built to carry a hedge got asked to carry a fact.
14 October 2024. Forescout holds the line. Forescout Vedere Labs published a technical assessment titled, pointedly, "American Water's Security Incident: Ransomware or Something Else?" Its position: "The details are still limited, and American Water has not confirmed the cause or perpetrators," and on the ransomware question, "it is too early to draw conclusions." It observed that the IT-only impact pattern "could point to" ransomware and declined to go further. This remains the most careful public treatment of the incident.
15 October 2024. So does WaterISAC. The sector's own information sharing body published an incident awareness update with no vector, no actor, and no classification, and stated that it "has reached out to stakeholders for further information, but at the time of this writing has not received any additional details outside of the public statements on American Water's website." The organization best positioned to know said it did not know.
15 October 2024. The first blend I have found. eSecurityPlanet: "While American Water has not disclosed the exact method of attack, such incidents often involve tactics like ransomware or phishing." This is the earliest instance I can locate of those two words in one sentence about this incident. It is still honest. It is explicitly about the category, not the case. But the sentence now exists, and sentences are portable.
18 October 2024. The list gets built. ZPE Systems published a piece with a section headed "How the Attack Likely Happened," offering four scenarios: phishing or social engineering, ransomware, IT/OT integration vulnerabilities, and internet-facing systems. Every one is hedged. Every one is explicitly reasoned by analogy to a different incident, with MGM, Ragnar Locker, and Volt Typhoon named as the comparisons. The piece is honest about being pattern-matching rather than reporting.
It is also the structural ancestor of the field we published: a list of candidate vectors joined by "or," terminating in ransomware. What it does not contain is instructive. It does not say "unpatched systems." It does not say "supply-chain compromise." Its third item is IT-to-OT integration, which is a different claim about a different thing.
18 October 2024. A headline promising what the body denies. TechTarget: "The American Water cyberattack: Explaining how it happened." The body: "The specific type or method of attack has not been disclosed," and "some early speculation claims that it was a ransomware attack." A headline that answers a question the article says nobody has answered.
27 November 2024. The hedge comes off. Spin.AI published "American Water Ransomware Attack: What Happened and How Critical Industries Can Respond." First sentence: "On October 3, 2024, American Water company was targeted by a ransomware attack that disrupted billing systems for this critical services company."
No hedge. No attribution. No cited source of any kind for that claim or any other. Forty-eight days after Kirkwood said "if I had to speculate," it is a fact in a title.
The same article is also where our root cause came from. On the vector, it stays hedged, and then says: "in many ransomware attacks, phishing attacks often lead to compromised credentials... This may very well be the means attackers used in this case." A "may very well be," downstream of a classification that was never established, about an incident with no disclosed vector.
Then us, and this is where it stops being somebody else's story. Three vectors joined by "or." An attacker field reading "Unknown Ransomware." A root cause reading "Weak Credential." A body sentence saying the company "confirmed" what it had hedged.
"Phishing" I can find hedged in two vendor pieces. "Ransomware" and the credential claim I can find hedged in Spin.AI, which took the hedges off one of them. I cannot find "unpatched systems" or "supply-chain compromise" asserted as this incident's vector by anyone. What I can say is that every hedge that existed upstream was gone by the time it reached our page, and that the last step, from "may very well be" to a field labeled Root Cause, happened here.
That is the shape of the thing. One sentence explicitly labeled as speculation, forty-eight days, and a claim nobody ever made becomes something the sector knows. Not one bad actor in the sequence. A reporter doing his job, a CISO answering carefully, vendors reasoning by analogy and saying so, an SEO headline, and then a piece of content with nothing under it. And at the end, a security company publishing a reference catalog with a warning label on the page and determinations beneath it.
The incident was real. This matters because the correction available at Oldsmar is not available here, and I do not want anyone to read this as a debunking. American Water told the SEC in a signed filing that it had identified unauthorized activity and determined it to be a cybersecurity incident. It notified law enforcement. It disconnected systems. Nobody has ever disputed a word of that, and the company has had two annual reports and six quarterly ones in which to walk it back.
It might well have been ransomware. Kirkwood's reasoning is sound. The impact pattern, corporate systems down and plants up, is a textbook shape for IT-side ransomware. If you made me bet, I would bet with him. The point is not that the guess was bad. The point is that an entry stating the attacker was "Unknown Ransomware" is not offering a hypothesis; it is answering the question, and we do not answer a question on a hunch just because the hunch is probably right. That is not a standard. That is a preference for being interesting.
The claim that customer data was stolen is a pleading, not a finding. At least nine putative class actions were filed in the District of New Jersey in October 2024, with the earliest reported on 11 October and the most widely covered, Menichini v. American Water Works Company, Inc., filed on 14 October. The first complaint does not use the word "ransomware." Its exfiltration claim is pleaded as the plaintiff's belief: "Plaintiff further believes her PII, and that of Class Members, was subsequently sold on the dark web following the Data Breach, as that is the modus operandi of cybercriminals that commit cyberattacks of this type." Bloomberg Law's headline, "American Water Faces Suit Over Breach That Leaked Millions' Data," drops attribution that its own opening sentence carries: "a proposed class action alleges." That is a headline convention problem rather than a reporting one, and it is worth separating the two, because the difference between a body that attributes and a headline that does not is precisely the gap everything in this article falls through.
The company stopped talking about it. The last filing to use the phrase "October 2024 cybersecurity incident" is the quarterly report filed 29 October 2025. The annual report filed 18 February 2026 contains no identifiable reference to it, and its contingencies note does not carry the litigation. I am not going to tell you why, because I do not know. Resolution, immateriality, and ordinary disclosure hygiene all produce the same silence, and picking one would be doing the thing this entire piece is about.
And here is the one inference I am going to make, labeled as one. The company took its own revenue systems offline for a week to protect operational environments that, by its own account, it had no indication the intruder had reached. I read that as telling you something about the architecture. If the plants had been genuinely unreachable from the corporate estate by construction, there would have been less reason to sacrifice billing to protect them. Systems were disconnected because disconnection was the mechanism of separation.
That is my read of the shape of the response. It is not a disclosed finding, and no document says it. I am flagging it here; I have flagged it in the entry, and if you see it repeated somewhere without the flag, that is this article's own contribution to a sequence like the one above.
The water was fine. Why it was fine is not comfortable.
Nobody has established what the intruder was trying to do or what it could have reached. It is entirely possible it never had a path to the operational environment and never wanted one. What follows is an argument about what the response tells us about the design, not a claim about what nearly happened.
With that said: the reason nobody has to argue about whether the water was fine is that people at American Water noticed unauthorized activity, assessed it quickly, decided the corporate estate could not be confidently bounded, and shut things down. Every step in that chain is a human step. Noticing is human. Assessing is human. Deciding to break your own company's billing for a week, on a Thursday, without yet knowing what you are dealing with, is very human, and it is not a small thing to do on incomplete information.
I have real respect for that call. I also do not want to build a national water supply on top of it.
Run the counterfactual, understanding that it is a counterfactual and not a near miss. Same intrusion, same day, but the alerting is noisier than usual, and triage takes six hours longer. Or it lands on a Friday evening during a holiday week, the scenario the Kaseya entry was built around and that attackers deliberately choose. Or the person with authority to order a disconnection is on a plane. None of those are exotic. All of them are Tuesday.
Nobody can tell you how much margin American Water had. That is not a criticism of the company; it is a property of the situation. You cannot measure the distance between an intruder and a system they never reached. The margin is unknowable by construction, which means the control is unfalsifiable, which means you cannot know whether it holds next time.
A safety margin that depends on somebody noticing is not a safety margin. It is a reflex. Reflexes are fast and useful, and they are the reason this incident is a footnote rather than a catastrophe. They are also not architecture; you cannot audit them, and they degrade at three in the morning.
The Bowman Avenue entry made a version of this point about luck. The sluice gate at Bowman had been manually disconnected for maintenance when the intruder arrived, which is the only reason the access did not become an incident. American Water is the more sophisticated cousin of the same problem. Bowman was saved by an accident. American Water was saved by a decision. A decision is enormously better than an accident. Neither one is a control.
This catalog keeps arriving at the same structural question. What was the expensive step, and what happens when it gets cheap?
For an intrusion like this one, the expensive step is orientation. An attacker lands on a corporate network at a large utility and has no idea where they are. Which of these thousands of hosts is a jump box? Which subnet reaches the historian? Which service account has been over-permissioned since a 2016 migration? Which of the fourteen states uses a different SCADA vendor due to an acquisition? Finding the bridge from the business network to the operational network within a large, messy, acquired-and-merged estate has historically taken days to weeks of careful, quiet, manual work, and that interval is precisely the margin a response like American Water's operates within.
That is the interval that is compressing. Not the exploitation and not the initial access, but the orientation: reading an unfamiliar environment, building a model of it, and identifying the shortest path to something that matters. It is a comprehension task, and comprehension is exactly what has gotten cheap over the last two years.
I want to be careful not to overstate, because this is a projection, not an observed incident. I am not aware of a public case in which an adversary demonstrably used automated reasoning to shorten reconnaissance within a utility. The claim I am making is narrower, and I think it is hard to argue with: the defense that worked at American Water was a race, and the defenders won it by an unknown margin against an adversary moving at human speed. If the adversary's orientation phase compresses from days to hours while the defender's detect, assess, decide, and authorize loop stays measured in hours, the margin does not shrink gradually. It inverts.
Detection speed is worth investing in, and I am not arguing against it. I am arguing that a strategy whose success condition is "we notice and decide faster than they orient" has an expiry date, and that somebody else sets it.
The goal for an operator like American Water is not to respond faster. It is to reach a state where an intrusion into the corporate network is entirely a corporate problem, and nobody has to make a decision about the plant at all.
Network cloaking means the OT environment does not respond to the corporate network. No ping, no port, no banner, no service response, no login page. An intruder who has fully compromised the business estate, has domain admin, and has read every wiki page and network diagram, still finds nothing to scan because the systems return nothing to an unauthorized source, regardless of the credentials that source holds. Orientation cannot be accelerated when there is nothing to orient toward. This is the control that turns "how much margin did we have" into "the question did not arise."
Every path from business network to operational network protected by a secret is a path that survives the compromise of the business network, because compromising the business network is how you get the secret. Passwordless, certificate-based authentication bound to an enrolled, posture-checked device means the credentials in the corporate estate are not the ones that reach the plant. There is nothing to harvest, so the intrusion does not compound.
American Water operates across 14 states with an estate assembled over decades of acquisition. In an environment like that, "which network is this host on" is a question nobody can answer confidently for every host, which is one reason a broad disconnection is the confident containment action. Identity-defined microsegmentation removes network position from the trust calculation. Every session to every resource is separately authorized against a verified identity on a verified device. Inherited addressing, forgotten flat segments, and the acquisition nobody fully mapped are no longer a latent blast radius.
This is the control this entry exists to argue for. The response to this intrusion was correct and manual. The objective is an architecture where the correct response is the default state: the operational environment is already separated, cryptographically, at all times, so there is no disconnection to order, no billing to sacrifice, no assessment to complete under time pressure, and nobody who has to be awake and reachable and confident enough to break the company's revenue system on incomplete information. Containment ceases to be an action and becomes a property.
The sector's binding constraint is economic, and it is not going away. There are nearly 50,000 community water systems in the United States, and more than 91% of them serve 10,000 people or fewer. They do not have a security operations center, and they never will. Whatever the control is, it has to deploy in front of existing equipment without re-architecting it, without touching the PLC, the HMI, or the IP scheme, without a truck roll to every lift station, and it has to be managed centrally by people who are not on-site. A utility with two thousand distributed assets needs a control it can apply two thousand times without adding two thousand people. That is not a nice-to-have property. It is the design requirement, and any proposal that fails it is a proposal for the fifty largest utilities and nobody else.
There is no villain in this entry, which is unusual for this catalog, and I cannot find any negligence story either. A large utility was intruded upon, noticed, and acted decisively at real cost to itself. The water was safe throughout. By any reasonable standard, that is a success, but it leads us to two specific issues.
The first is the one we have been arguing for years. Fourteen million people were served safely through a week in which the company's own decision-making was the thing standing between an unbounded corporate network and a set of plants. Not a firewall rule, and not a segmentation design that made the intrusion irrelevant. People noticed and moved. Every other entry in this catalog is about a missing control. This one is about a control that was present, worked, and happened to be made of people. You can get better at making that call, and American Water is proof it can be made well. What you cannot do is guarantee the person who has to make it next time will be at their desk.
The second is newer, and it is about us. This industry filled a two-month silence with a vector, an actor, and a root cause that nobody had, and we were among the people holding the pen. Not out of malice and not even out of carelessness, exactly, but because a blank field in a reference catalog is uncomfortable and a plausible answer is right there. A vendor writes "likely." A content page drops the word. A catalog turns it into a field. Within a year, it is something everyone knows about American Water, and none of it came from anywhere.
I do not think those two failures are unrelated. Both are what happens when the honest answer is an absence and an absence feels unacceptable. American Water could not prove its plants were untouched, so it said "no indication," and the sector heard "confirmed." Nobody could say how the intruder got in, so the sector provided three ways they might have entered. In OT security, we are extremely bad at leaving space empty, and it costs us twice: once when we design controls against the threat we imagined rather than the one we have, and again when the people we ask to spend money stop believing us.
So the entry now says "Not disclosed" in three places, and it will keep saying that until somebody with standing says otherwise.
In OT, the first control is neither detection nor response. It is refusing to answer the question. It turns out that applies to the writing too.
Cam Cullen is the Chief Marketing Officer at BlastWave. BlastWave's BlastShield platform delivers network cloaking, identity-defined microsegmentation, and zero-trust OT secure remote access for critical infrastructure environments. Explore the full Hackopedia at hackopedia.blastwave.com.
Was the American Water incident ransomware? Nobody knows. No group has ever claimed it, the word appears in no American Water SEC filing in the company's history, and the company has never characterized the incident. Accounts calling it ransomware trace back to a security executive's explicitly labeled speculation on 10 October 2024, which lost its hedge as it was repeated.
How did the attackers get in? No vector has ever been publicly established by the company, any regulator, or any investigating body. Any specific mechanism you have read about that is attributed to this incident is a downstream inference.
Were water treatment operations affected? American Water stated it "currently believes" and later that it "continues to have no indication" that its water and wastewater facilities were impacted, and, separately and without qualification, that water quality was not affected. Those are the company's words. It never issued a confirmation that operations were unaffected, and the distinction is worth preserving.
Was customer data stolen? The company stated that customer Personal Information, as defined by the data breach notification laws of the fourteen states where it has regulated operations, "was not impacted as a result of the incident." It never offered credit monitoring. No breach notification from American Water has been located in any searchable state Attorney General registry. Putative class actions allege exfiltration, but the allegation is pleaded as the plaintiff's belief, and no court has made a finding on the question.
Why did billing go down if the plants were fine? American Water disconnected and deactivated systems as a containment measure, including its MyWater portal and billing platform. Our read, and we flag it as a read rather than a disclosed fact, is that the business estate could not be confidently bounded, so separating it from the operational environment required taking it down.
How long was the outage? Unauthorized activity was identified on 3 October 2024 and reactivation was announced on 10 October 2024. About a week. No late charges were issued for the period.
Who attacked American Water? Nobody knows. The only congressional document naming the incident describes "an unidentified cyber threat actor." No attribution to any nation-state or criminal group has ever been made by anyone with standing to make it.
Why does this entry say "Vector undisclosed"? Because the incident is documented and its mechanism is not. We use this status where a victim, regulator or investigator has confirmed that something happened but nobody has ever stated how. It is distinct from "Contested," which we reserve for incidents where named parties have given materially conflicting accounts, as at Oldsmar in 2021.
What did BlastWave get wrong, specifically? Earlier versions of this entry listed the attacker as "Unknown Ransomware," the vector as "phishing, unpatched systems, or supply-chain compromise leading to ransomware installation," and the root cause as "Weak Credential," and said the company had "confirmed" its OT and water quality were unaffected. None of that was established. Two of the three listed vectors have never been asserted as the vector for this incident by anyone, and the root cause traces back to speculation in a single vendor blog. We printed it as determinations.
Does this mean nothing happened? No. American Water disclosed to the SEC that it identified unauthorized activity and determined it to be a cybersecurity incident, notified law enforcement, and disconnected systems. Nothing in that account has ever been disputed. What is missing is the mechanism, not the event.
American Water’s cyber incident shows why water utilities need stronger OT isolation to stop IT breaches from threatening critical infrastructure operations and availability.
Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.
