A cyberattack has penetrated the operating technology of an Oregon drinking-water provider, bringing a growing national threat against critical infrastructure directly into the state and raising serious questions about how well the computerized systems controlling public water supplies are protected from outside intrusion.
Gov. Tina Kotek’s office has confirmed that hackers gained access to operational technology belonging to an Oregon water district. The state has not identified the utility, disclosed where it is located or said how many customers it serves, leaving communities across Oregon without a clear picture of where the breach occurred.
There is no evidence that Oregon drinking water was contaminated, and officials have issued no boil-water notice or public health advisory connected to the attack. No information released so far indicates that customers received unsafe water.
The breach is nevertheless significant because the attackers reached technology associated with the physical operation of a water system rather than simply an administrative computer network.
Modern drinking-water systems rely on computerized controls to operate and monitor pumps, valves, storage facilities, treatment equipment and other machinery responsible for moving and treating water. Some systems use programmable logic controllers and other industrial devices that allow operators to control equipment electronically.
Unauthorized access to that technology creates a fundamentally different risk from the theft of emails, passwords or customer information. Depending on the system and the level of access obtained, a successful intrusion into operational technology can potentially interfere with the machinery responsible for keeping water infrastructure functioning.
The Oregon breach surfaced as federal authorities were already confronting cyberattacks against water and wastewater utilities elsewhere in the United States.
The FBI has reported incidents affecting utilities in at least seven states, with some attacks degrading water operations. Federal cybersecurity officials have also warned that attackers are targeting internet-connected industrial equipment used by water systems and other critical infrastructure.
Those warnings intensified this year. In April, the Environmental Protection Agency, FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency issued a joint warning concerning cyber threats against American infrastructure, specifically including drinking-water and wastewater systems.
Federal authorities followed with additional warnings involving internet-connected operational technology and programmable logic controllers, the industrial computers commonly used to automate equipment.
The Oregon case now provides a direct example of the vulnerability those warnings have described. Exactly what happened inside the unidentified water district remains unclear. Officials have not disclosed how the attackers entered the system, how long they maintained access or precisely which equipment they reached. It is also unknown whether they attempted to change operating settings, whether any machinery responded to unauthorized commands or whether employees moved portions of the system to manual operation.
Authorities have not publicly attributed the Oregon attack to a foreign government or identified a particular hacking organization as responsible. For residents of Southern Oregon, the undisclosed location is particularly important. Nothing released by state or federal authorities establishes that the affected provider serves Grants Pass, Medford, Ashland, Roseburg, Klamath Falls, Brookings or another Southern Oregon community. Residents should not interpret the statewide confirmation as evidence that their local drinking water has been compromised.
But Southern Oregon is not removed from the larger issue exposed by the attack. Oregon’s drinking-water network extends far beyond its major cities. Smaller municipalities and water districts throughout the state operate treatment plants, reservoirs, pumps and distribution systems that increasingly depend upon computerized equipment. Many smaller utilities must protect those systems while operating with fewer employees and more limited technology budgets than large metropolitan providers.
That imbalance has become a national concern. A federal assessment of more than 1,000 drinking-water systems serving approximately 193 million people found dozens with critical or high-risk cybersecurity vulnerabilities. The EPA later reported finding cybersecurity vulnerabilities at 277 water systems during 2025 and working with utilities to strengthen authentication, access controls and other protections.
Oregon has its own cybersecurity structure for government and critical infrastructure, while the Oregon Health Authority maintains oversight responsibilities involving public drinking-water systems. At the federal level, the EPA, FBI and CISA have been working with utilities to identify vulnerabilities and respond to attacks.
There has been no public indication that the Oregon Secretary of State or Oregon Department of Justice is leading the investigation into this particular breach. The FBI, an agency of the U.S. Department of Justice, is involved in the broader federal response to cyberattacks targeting critical infrastructure.
For now, Oregon residents are left with an unusual situation: the state has confirmed that attackers reached technology belonging to a public drinking-water provider but has not identified the community involved.
That leaves an important line between what is known and what remains unknown. There is no confirmed drinking-water contamination, no statewide public health emergency and no evidence released publicly that Oregon residents need to change how they use their tap water. What has been confirmed is a cybersecurity intrusion into the operational environment of infrastructure responsible for delivering drinking water.
The pipes beneath Oregon communities may be physical infrastructure, but the machinery controlling what moves through them increasingly operates in a digital environment.
The breach of an Oregon water provider shows that protecting the state’s drinking-water supply now requires defending both.

