“Safe drinking water now depends upon two invisible barriers: one that removes contaminants from the water, and another that keeps attackers out of the control system.” – MJ Martin
Introduction
Canada’s water utilities have always planned for floods, ice storms, equipment failures, and power outages. Today, however, they face a different kind of threat. The newest vulnerability arrives not through a pipe or transmission line, but through an internet connection. Cyberattacks have become a weapon capable of disrupting essential public services without a single shot being fired.
The City of Hamilton’s devastating cyberattack in February 2024, followed by the coordinated attacks against more than 30 Minnesota water systems in July 2026, demonstrates that North America’s critical infrastructure has entered a new era. These incidents should not be viewed as isolated events. Together they form a warning that every Canadian municipality, utility, and critical infrastructure operator should heed.
Hamilton Became Canada’s Wake Up Call

On February 25, 2024, the City of Hamilton experienced one of the most significant municipal cyberattacks in Canadian history. A sophisticated ransomware group infiltrated the City’s computer systems, disabling approximately 80 percent of municipal information technology services. The attackers demanded approximately $18.5 million in ransom in exchange for restoring encrypted data. Hamilton refused to pay, following the advice of cybersecurity experts and law enforcement. (City of Hamilton)

Although drinking water remained safe because operational systems were protected and operators implemented contingency measures, the attack severely disrupted municipal operations. Business licensing, permitting, financial systems, property tax processing, transit services, internal communications, and numerous public services were affected for weeks and, in some cases, months. Twenty one municipal services experienced significant impacts, while some digital records were permanently lost despite extensive recovery efforts. (Canadian Research Knowledge Network)

The financial consequences continue to grow. Hamilton has now spent more than $18.3 million recovering from the attack, nearly double the City’s initial recovery estimate. Approximately $14 million has been devoted to cybersecurity specialists, system recovery, infrastructure redesign, and strengthening future cyber resilience. Adding further insult to the incident, the City’s cyber insurance claim was denied because required multi-factor authentication had not been fully implemented at the time of the breach. Hamilton taxpayers ultimately became responsible for the recovery costs. (Global News)
The Cyber Threat Actors
The Hamilton attack was a classic ransomware attack, which we have seen at perhaps 10 other Canadian municipal utilities over the past year. So Hamilton is not alone in this misery. These ransomware attacks are a means to hold utilities hostage until they pay the ransom. So, the motivation is money harvesting which when the ransom is paid the decryption keys are released to permit the utility to recover its data and restore its services. The processes of restoration and then applying new security measures to protect against future cyber attacks often cost far more than the ransom itself. The wear and tear on municipal staff is an unseen toll that carries major consequences too. Staff often resign from the stresses or retire which adds to the pain.
As reported in the New York Times newspaper, investigators believe a cyberattack this week on dozens of municipal water systems in Minnesota was probably the work of Iranian hackers, according to U.S. and state officials and others familiar with the matter, a potential act of aggression that comes at a precarious moment in the U.S. war against Iran.
Officials cautioned that they had not definitively determined who was responsible for the attack and that the preliminary assessment could change as the authorities collected more technical data.
They also warned that the hackers could be attempting to pose as Iran-based in an effort to ratchet up tensions between the two countries, though former intelligence officials said such a scenario was unlikely.
Local officials reported that the well and treatment plant in at least one city was temporarily offline on Monday, while other cities in the state had to use manual workarounds to cope with attempted attacks on automated operations.
Minnesota Demonstrated the Next Phase
If Hamilton illustrated the economic consequences of a cyberattack, Minnesota demonstrated the potential impact on operational technology.

During 26 and 27 July 2026, more than 30 community water systems across Minnesota experienced coordinated malicious cyber activity involving operational technology. Attackers targeted the industrial control systems responsible for operating wells, pumps, reservoirs, and treatment facilities. In some communities, operators temporarily lost automated control of their facilities and were forced to manage water production manually while cybersecurity experts restored system access. Some municipalities issued boil water advisories or requested residents reduce water consumption while systems were stabilized. Fortunately, no evidence suggested that drinking water quality had been compromised.

According to the United States Cybersecurity and Infrastructure Security Agency, the attackers focused on Programmable Logic Controllers, commonly known as PLCs. Rather than stealing information, they attempted to change administrative passwords and lock legitimate operators out of their own equipment. Their objective was disruption rather than data theft. Investigators examined possible links to Iranian affiliated threat actors, although attribution remained under investigation.
FBI and the Investigation
The FBI is warning that hackers are trying to disrupt America’s water systems.
Cyberattackers have targeted municipal water systems in at least seven states in a widening attack on America’s critical infrastructure.
Officials say some attacks degraded water operations and caused facilities to lose monitoring and control capabilities. Other incidents involving water infrastructure have reportedly forced utilities to issue boil-water notices and operate equipment manually.
There is currently no evidence that Minnesota’s drinking water was contaminated.
Investigators have not publicly identified who carried out the attacks. However, a law enforcement official said the Minnesota breaches showed signs of possible Iranian involvement. The attacks came days after federal agencies warned that Iran-backed hackers were targeting American infrastructure during the escalating conflict between Washington and Tehran.
Officials stressed that attribution requires further investigation.
The hackers reportedly gained remote access to internet-connected industrial control devices used to manage municipal water systems. They then changed IP addresses and passwords, locking some operators out of their own equipment.
These systems help workers monitor water pressure, pumps and other essential operations. Losing control of them can disrupt service even if the water itself remains uncontaminated.
The FBI and EPA are urging utilities to remove control systems from direct internet exposure, place them behind secure gateways and firewalls, strengthen passwords and restrict communication between authorized devices.
Water systems can be especially vulnerable because many smaller utilities rely on aging equipment, limited cybersecurity staff and industrial devices that were never designed to face modern online threats.
Operational Technology Is the New Front Line
Most municipal executives understand cybersecurity in terms of protecting email, payroll, or financial systems. Water utilities operate under a completely different risk model.
A PLC is the digital equivalent of the conductor leading an orchestra. Pumps, valves, chemical feed systems, filters, reservoirs, and pressure regulators all perform individual functions, but without the conductor the performance rapidly descends into disorder. When attackers seize control of a PLC or prevent operators from accessing it, the utility may have no choice but to revert to manual operation.
This distinction is critical. Information technology (IT) protects data. Operational technology (OT) protects public health. I often use the adage, “IT protects the business, whereas OT is the business”.

Canada’s Opportunity to Lead
Canada has an advantage that Hamilton did not possess before 2024 and Minnesota did not possess before 2026. We have the benefit of learning from both incidents.
Every Canadian utility should assume that cyber intrusions will occur. Success will no longer be measured solely by preventing attacks, but by maintaining safe operations throughout them. That requires physically separating operational technology from corporate networks, implementing multi-factor authentication everywhere, maintaining immutable offline backups, continuously monitoring industrial control systems, testing disaster recovery plans, and routinely training operators to transition safely to manual control.
Cybersecurity should become as routine as calibrating a chlorine analyzer or inspecting a high lift pump. It is no longer an information technology project. It is an engineering discipline.

Summary
Hamilton demonstrated how a cyberattack can cripple an entire municipality and cost taxpayers tens of millions of dollars. Minnesota demonstrated that attackers are increasingly targeting the operational technology that delivers safe drinking water.
Together, these incidents redefine how Canadian utilities must think about critical infrastructure. Water treatment plants are no longer protected simply by fences, locks, and alarm systems. They require digital fortifications that are every bit as robust as their physical infrastructure.
The next attack may not begin in Hamilton or Minnesota. It could begin in any Canadian municipality connected to the internet. The question is not whether attackers will continue probing our infrastructure. The question is whether Canadian utilities will act on these lessons before they become the next case study.
Questions for Discussion
Should provincial regulators require annual cybersecurity certification for every municipal water utility in Canada?
Should operational technology be regulated with the same rigor as drinking water quality standards?
Finally, should cybersecurity funding become a mandatory component of every water and wastewater capital program rather than an optional information technology expense?
About the Author:
Michael Martin is the Vice President of Technology with Metercor Inc., a Smart Meter, IoT, and Smart City systems integrator based in Canada. He has more than 40 years of experience in systems design for applications that use broadband networks, optical fibre, wireless, and digital communications technologies. He is a business and technology consultant. He was a senior executive consultant for 15 years with IBM, where he worked in the GBS Global Center of Competency for Energy and Utilities and the GTS Global Center of Excellence for Energy and Utilities. He is a founding partner and President of MICAN Communications and before that was President of Comlink Systems Limited and Ensat Broadcast Services, Inc., both divisions of Cygnal Technologies Corporation (CYN: TSX).
Martin served on the Board of Directors for TeraGo Inc (TGO: TSX) and on the Board of Directors for Avante Logixx Inc. (XX: TSX.V). He has served as a Member, SCC ISO-IEC JTC 1/SC-41 – Internet of Things and related technologies, ISO – International Organization for Standardization, and as a member of the NIST SP 500-325 Fog Computing Conceptual Model, National Institute of Standards and Technology. He served on the Board of Governors of the University of Ontario Institute of Technology (UOIT) [now Ontario Tech University] and on the Board of Advisers of five different Colleges in Ontario – Centennial College, Humber College, George Brown College, Durham College, Ryerson Polytechnic University [now Toronto Metropolitan University]. For 16 years he served on the Board of the Society of Motion Picture and Television Engineers (SMPTE), Toronto Section.
He holds three master’s degrees – in business (MBA), communication (MA), and education (MEd). As well, he has three undergraduate diplomas and seven major certifications in business, computer programming, internetworking, project management, media, photography, and communication technology. He has completed over 80 next generation MOOC (Massive Open Online Courses) [aka Micro Learning] continuous education programs in a wide variety of topics, including: Economics, Python Programming, Internet of Things, Cloud, Artificial Intelligence and Cognitive systems, Blockchain, Agile, Power BI, Big Data, Design Thinking, Security, Indigenous Canada awareness, and more.
Martin in a volunteer, a photographer, a learner, a technologist, a philosophizer, and a romantic optimist.