RealCyberNews
Back to latest
criticalFebruary 8, 2021 · 4 min read

Someone Tried to Poison a Florida City's Water Supply Remotely

In 2021, an attacker briefly took control of a water treatment plant's chemical controls. An operator watching the screen caught it in seconds. Here's why that near-miss still matters.

By RealCyberNews Editorial Team

Share

In February 2021, an operator at a water treatment plant in Oldsmar, Florida watched their mouse cursor move on its own, opening software the plant uses to control water chemistry — and then watched the target level for sodium hydroxide, the chemical that controls water pH, jump from 100 parts per million to 11,100.

What sodium hydroxide overdose would have meant

Sodium hydroxide (lye) is used in small, carefully controlled amounts to keep drinking water from being too acidic. At the concentration the attacker briefly set, it’s the same chemical used in drain cleaner — capable of causing serious harm if it had reached the water supply at that level.

Why it didn’t become a disaster

The operator noticed the cursor moving in real time, immediately reversed the change, and the plant had additional safeguards downstream that would have caught the chemical imbalance before treated water reached anyone’s tap even if the change had gone unnoticed. The system worked because a human was watching — not because the intrusion itself was stopped.

How the attacker got in

Investigators found the plant used TeamViewer, remote-access software, to allow staff to monitor systems from outside the facility — a common and unremarkable setup at small utilities with limited IT staff. That same remote access, likely reached with weak or reused credentials, is what let an outside party in.

Why this incident is still cited years later

Most cybersecurity coverage focuses on data theft. This incident is different: it’s one of the clearest public examples of a cyberattack with a direct path to physical, public harm, and it happened at a small municipal utility, not a well-funded target — a reminder that critical infrastructure risk isn’t limited to major cities or headline-grabbing pipelines.

What this means beyond Oldsmar

Small utilities, water districts, and municipal systems across the country run on the same kind of lean IT setup Oldsmar did. The fix isn’t something individual residents can act on directly, but it’s exactly the kind of story worth watching for in your own area — local utilities are increasingly required to disclose these incidents, and they rarely make national news.

Worried this affects you?

Check whether your email address has shown up in this breach — or any other — in seconds.

Run a free breach check →