Cyber Incident Victim: Baltimore City Department of Public Works
Timeline
Summary
The Baltimore City Department of Public Works reported that attackers, possibly based in Iran, changed the IP addresses and passwords of programmable logic controllers used in its water system, preventing operators from monitoring or controlling the infrastructure. The incident followed a warning from U.S. cybersecurity officials about Iranian-affiliated activity targeting operational technology devices. While experts noted the effects did not appear to last long, they explained that resetting passwords could take a few hours and altering IP addresses often required physical site visits, potentially leaving the system offline for up to a day. The department supplies drinking water to Baltimore City and surrounding counties and said it regularly evaluates threats and strengthens its cybersecurity posture.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or before August 5 2026, Baltimore City DPW reported being on guard after cyber attacks. Attackers changed IP addresses and passwords on programmable logic controllers, preventing operators from monitoring or controlling water systems. This could lead to flooding, pressure loss, and possible entry of untreated groundwater into pipes. The department supplies drinking water to Baltimore City and parts of Baltimore County, Carroll, Howard and Harford counties. The attacks followed a July 22 update to an April warning from CISA about Iranian-affiliated cyber activity targeting operational technology devices, specifically disrupting programmable logic controllers. The attackers focused on one brand of PLCs; many of these devices lacked passwords or had weak ones, allowing unauthorized access.

As a result, operators likely had to visit physical sites to reinstall software after password and IP address changes, which could take a couple of hours for password reset and up to a day for full recovery due to needing to reprogram devices. DPW stated it continuously safeguards critical water and wastewater infrastructure through industry best practices, ongoing monitoring, and collaboration with local, state and federal partners, and that it regularly evaluates evolving threats and strengthens its cybersecurity posture. The department does not discuss specific cybersecurity measures or operational procedures. Anne Arundel County’s DPW declined to comment on its protections but said it is taking proactive measures against cyber attacks. While the attack was broader than previous Iranian cyber incidents, observed effects did not appear to persist long, and the situation did not constitute a large‑scale emergency, though it caused more than mere inconvenience.
