CSIDB logo
Incident

Baltimore City Department of Public Works

Incident posture

Attack window
Jul 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 20:03

Linked entities

Victim
Baltimore City Department of Public Works
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending

Summary

The Baltimore City Department of Public Works reported that attackers, possibly based in Iran, changed the IP addresses and passwords of programmable logic controllers used in its water system, preventing operators from monitoring or controlling the infrastructure. The incident followed a warning from U.S. cybersecurity officials about Iranian-affiliated activity targeting operational technology devices. While experts noted the effects did not appear to last long, they explained that resetting passwords could take a few hours and altering IP addresses often required physical site visits, potentially leaving the system offline for up to a day. The department supplies drinking water to Baltimore City and surrounding counties and said it regularly evaluates threats and strengthens its cybersecurity posture.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

On or before August 5 2026, Baltimore City DPW reported being on guard after cyber attacks. Attackers changed IP addresses and passwords on programmable logic controllers, preventing operators from monitoring or controlling water systems. This could lead to flooding, pressure loss, and possible entry of untreated groundwater into pipes. The department supplies drinking water to Baltimore City and parts of Baltimore County, Carroll, Howard and Harford counties. The attacks followed a July 22 update to an April warning from CISA about Iranian-affiliated cyber activity targeting operational technology devices, specifically disrupting programmable logic controllers. The attackers focused on one brand of PLCs; many of these devices lacked passwords or had weak ones, allowing unauthorized access.

As a result, operators likely had to visit physical sites to reinstall software after password and IP address changes, which could take a couple of hours for password reset and up to a day for full recovery due to needing to reprogram devices. DPW stated it continuously safeguards critical water and wastewater infrastructure through industry best practices, ongoing monitoring, and collaboration with local, state and federal partners, and that it regularly evaluates evolving threats and strengthens its cybersecurity posture. The department does not discuss specific cybersecurity measures or operational procedures. Anne Arundel County’s DPW declined to comment on its protections but said it is taking proactive measures against cyber attacks. While the attack was broader than previous Iranian cyber incidents, observed effects did not appear to persist long, and the situation did not constitute a large‑scale emergency, though it caused more than mere inconvenience.

Sources

Sources available to members: 1 source.

CSIDB