100+ Water System Hacks Show AI Cooling Risk Sits Outside the Data Center

Water treatment plant control panel and cooling towers illustrating the Oregon water system hack and data center cooling risk

TL;DR · 30-second read

The Short Version

In July, hackers broke into the control systems of a drinking-water provider in Oregon. Officials have not said which one. It was part of a wave that reached at least 100 American water systems in seven states.

The attackers reached small computers that run pumps and valves over the internet and locked operators out. Some towns saw water pressure drop, flooding, or a precautionary boil-water notice.

This matters beyond your tap. Many of the huge computer buildings behind artificial intelligence use local tap water to stay cool, so a hacked water utility is their problem too.

Oregon Public Broadcasting reported on August 7, 2026, that Oregon Gov. Tina Kotek’s office confirmed hackers gained access to an Oregon water district’s core operating technology in July. Oregon Enterprise Information Services, which provides cybersecurity support to state agencies, confirmed a July incident involving unauthorized access to operational technology used by an Oregon drinking-water provider. State officials would not name the district, would not say whether the incident is linked to a wider campaign, and said the impact is still being assessed.

The Oregon disclosure follows a July 30 New York Times report that at least 100 US water systems had detected malicious attacks, which the paper said were initiated by hackers in Iran. An FBI release the same day acknowledged attacks in seven states and said some of the activity degraded water operations. At least 30 systems were targeted in Minnesota, where one treatment plant temporarily went offline; in Georgia, one system lost water pressure and briefly issued a boil-water precaution.

Executive Summary

An unnamed Oregon drinking-water provider is the latest confirmed victim of a July campaign against municipal water and sewage systems. According to the FBI, attackers connected over the internet to programmable logic controllers, the small industrial computers that run pumps and valves, then changed their IP addresses and passwords, cutting operators off from monitoring and control. Reported effects included loss of pressure and flooding.

For the data center industry, the episode matters because water is an operating input, not only a sustainability metric. Facilities that reject heat through evaporative cooling draw continuously on local utilities. The campaign shows that at least 100 of those utilities could be reached directly from the internet within days. A data center’s resilience therefore depends partly on the security of infrastructure it neither owns nor audits.

The same class of controller also runs chilled-water plants, pumps and valves inside data centers. The FBI’s guidance to water utilities, to limit remote access and keep manual fallback procedures, reads as a checklist for cooling plant operators as well.

What the FBI Says Happened

The FBI’s description of the attack is short and specific. Between July 27 and July 30, attackers connected to programmable logic controllers (PLCs), rugged single-purpose computers that open valves, start pumps and read sensors, directly over the internet. They then changed the devices’ IP addresses and passwords, which the agency said resulted in a loss of monitoring and control. Operators could no longer see or steer parts of their own systems.

The consequences were physical. The FBI said operational effects included loss of pressure and flooding, and warned that pressure loss could potentially allow untreated groundwater to seep into pipes. In Minnesota, where at least 30 systems were targeted, one treatment plant temporarily went offline. In Georgia, a pressure drop prompted a precautionary boil-water notice.

Attribution remains partly open. The New York Times reported the campaign was initiated by hackers in Iran. Oregon officials declined to say whether their incident belongs to that campaign and referred questions to federal investigators. That caution is reasonable while the investigation continues, and the operational lessons do not depend on who was behind the attacks.

Why AI Cooling Risk Sits Outside the Fence

Many data centers remove heat with evaporative cooling towers, which lose water continuously to evaporation and replace it, as so-called makeup water, from the local municipal supply. AI clusters pack far more heat into each rack than conventional servers. Even when the chips are cooled directly by liquid, that heat still has to leave the building, and in many designs it leaves through those same towers. For a significant share of facilities, water pressure at the meter is as much a dependency as power at the substation.

The failure modes the FBI listed match that dependency closely. A pressure loss or an offline treatment plant is exactly the event a cooling plant’s onsite water storage exists to ride through. What the July campaign changes is the likelihood and breadth of that event. At least 100 systems in at least seven states were affected in a matter of days. The technique did not require first breaching a corporate network, because the controllers were reachable from the internet. A risk that site selection teams once modelled as drought or main breaks now has a cyber path, and it can hit many utilities simultaneously.

The people exposed are the ones who build, lease and finance capacity: operators sizing onsite storage, tenants whose service agreements assume cooling continuity, and lenders underwriting sites in water-dependent markets. Oregon hosts major data center clusters around Hillsboro, The Dalles and Prineville. Nothing disclosed so far indicates the affected district serves any of them. The point is structural, not local.

The Same Controllers Run the Chiller Plant

PLCs are not unique to water utilities. The same kind of device, often from the same vendors, sequences chillers, modulates pumps and controls valves in data center mechanical plants. Remote access is common there for the same reason Tualatin Valley Water District spokesperson Justin Dyke gave for utilities: it lets operators respond quickly when demand shifts. The convenience cuts both ways when a controller’s management interface is reachable from the open internet.

The FBI’s recommendations to water systems translate almost directly. Limit remote access to controllers. Enforce authentication and other security protocols. Maintain manual procedures for when automation is lost. Dyke described that last practice at his district: if online systems go down, operators make changes by hand. Data center operators can apply the same test to their cooling plants and ask whether staff can run the chilled-water system safely with the controls network unavailable.

A Defense Spread Across 2,500 Districts

Oregon has more than 2,500 water districts, and all of its drinking-water systems are locally managed. Oregon Enterprise Information Services consults with districts on cybersecurity and threat assessments but does not run them. That structure is typical of US water and puts security decisions in the hands of many small operators with limited budgets and staff.

It also limits disclosure. The Portland Water Bureau said it routinely examines vulnerabilities with the city’s security team, the Cybersecurity and Infrastructure Security Agency and the FBI, but declined to say whether it was targeted in July. Tualatin Valley reported an increase in attempts, none successful. Klamath Falls and Corvallis reported no increase, and Redmond and Bend reported no breach. For a large water customer, that patchwork means a utility’s security posture is mostly invisible unless the customer asks directly.

Background

Water utilities have spent years connecting their treatment plants, pumping stations and reservoirs to remote monitoring. This lets small operating teams adjust flow and reservoir levels quickly as demand changes. The same connectivity, when controllers are reachable from the internet, exposes physical equipment to remote tampering. Federal agencies, including the FBI and the Cybersecurity and Infrastructure Security Agency, work with utilities on these risks, but in states like Oregon, day-to-day operation and security remain local responsibilities.

Oregon is also one of the country’s established data center markets, with large campuses around Hillsboro, The Dalles and Prineville. Water supply has featured in local debate about their growth. As AI workloads raise heat density per rack, cooling design, and for many facilities the municipal water behind it, has become a primary constraint on where and how capacity gets built.

Sources

Source: Oregon drinking water system accessed in recent cyber attacks (Oregon Public Broadcasting): Oregon officials confirm a July intrusion into a water provider’s operating technology amid a national campaign against water utilities.