Case file · OLDSMAR 2021

The Oldsmar water 'hack': a poisoning scare that may not have been an attack

Published 2026-09-29 · 4 min read · Missing control: Unique credentials for remote access

In February 2021 a small Florida city became the face of a national fear: a hacker who reached into a water plant and tried to poison the supply with lye. Two years later, the city's former top administrator said there had been no hacker at all.[1] This case file covers what was reported, what changed, why the plant looked so easy to break into either way, and the control that was weak.

What happened

On February 5, 2021, an operator at the water treatment plant in Oldsmar, a city near Tampa, noticed someone connected remotely to the plant's control screen around 8 a.m. That by itself was not alarming, since supervisors sometimes logged in from outside.[1][2]

Around 1:30 p.m. it happened again, and this time the operator watched the setting for sodium hydroxide, better known as lye, climb from 100 parts per million to about 11,000. Lye is used in small amounts to control the water's acidity; at that level it would have been dangerous. The operator put the setting back to normal right away, before the change could take effect.[1][2]

On February 8 the Pinellas County sheriff told reporters that someone had broken into the plant's system, and called whoever did it a bad actor. The FBI was called in.[1][2][5] The story ran worldwide as a warning about how exposed small utilities were.

How it worked, or seemed to

Whatever caused the change, the investigation exposed how the plant's computers were set up. Reporting at the time said the control system ran on computers using Windows 7, which Microsoft had stopped supporting, and that the computers shared a single password for the remote access software staff used to log in from outside. There was no firewall between those machines and the internet.[3]

In plain terms, anyone who learned one password could have reached the controls for the city's water, and nobody could tell afterward which person had used it. Days before the incident, a batch of leaked email addresses and passwords tied to Oldsmar had also surfaced online, though no link to the plant was confirmed.[1]

How the story changed

In April 2023 the former Oldsmar city manager told a virtual conference of public administrators that the FBI had found no evidence of outside access, and that the likely cause was the same employee who had been praised for catching it, pressing keys by mistake.[1] The FBI said that through its investigation it was not able to confirm that the incident began with a targeted cyber intrusion.[1]

No one was ever charged. The honest summary is that nobody has proved a hacker did it, and nobody has proved one did not.

What it cost

No one was hurt, because the setting was reversed before it could take effect.[1] The real cost was trust and attention. For 2 years the incident was treated as a textbook attack on a water system, even though its basic facts were never settled.[1] The FBI and other agencies used it to urge utilities to move off unsupported software and to stop sharing remote access passwords.[4]

The missing control

The missing control: unique, individual credentials for remote access, with a record of who used them. The plant's computers shared one password for remote login.[3]

That weakness mattered both ways. If an outsider did get in, one shared password meant a single leak exposed everything. And if no one did, the plant still could not quickly prove it, because a shared login leaves no clear trail of which person made which change. Individual accounts with their own passwords and a second login check would have made an outside break-in harder and turned a 2-year mystery into a question answerable in an afternoon.

What to do in your business

Watch the case
The Florida water 'hack' that may not have been a hackDrops 2026-12-27
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. CyberScoop: Oldsmar water incident was not a cyberattack, former city manager says
  2. NPR: FBI called in after hacker tries to poison Tampa-area city's water with lye
  3. GovInfoSecurity: Florida city's water hack: poor security laid bare
  4. Fortra: FBI urges caution on legacy systems following water hack
  5. KVIA (CNN): Someone tried to poison a Florida city by hacking into the water treatment system, sheriff says