The Oldsmar water 'hack': a poisoning scare that may not have been an attack
In February 2021 a small Florida city became the face of a national fear: a hacker who reached into a water plant and tried to poison the supply with lye. Two years later, the city's former top administrator said there had been no hacker at all.[1] This case file covers what was reported, what changed, why the plant looked so easy to break into either way, and the control that was weak.
What happened
On February 5, 2021, an operator at the water treatment plant in Oldsmar, a city near Tampa, noticed someone connected remotely to the plant's control screen around 8 a.m. That by itself was not alarming, since supervisors sometimes logged in from outside.[1][2]
Around 1:30 p.m. it happened again, and this time the operator watched the setting for sodium hydroxide, better known as lye, climb from 100 parts per million to about 11,000. Lye is used in small amounts to control the water's acidity; at that level it would have been dangerous. The operator put the setting back to normal right away, before the change could take effect.[1][2]
On February 8 the Pinellas County sheriff told reporters that someone had broken into the plant's system, and called whoever did it a bad actor. The FBI was called in.[1][2][5] The story ran worldwide as a warning about how exposed small utilities were.
How it worked, or seemed to
Whatever caused the change, the investigation exposed how the plant's computers were set up. Reporting at the time said the control system ran on computers using Windows 7, which Microsoft had stopped supporting, and that the computers shared a single password for the remote access software staff used to log in from outside. There was no firewall between those machines and the internet.[3]
In plain terms, anyone who learned one password could have reached the controls for the city's water, and nobody could tell afterward which person had used it. Days before the incident, a batch of leaked email addresses and passwords tied to Oldsmar had also surfaced online, though no link to the plant was confirmed.[1]
How the story changed
In April 2023 the former Oldsmar city manager told a virtual conference of public administrators that the FBI had found no evidence of outside access, and that the likely cause was the same employee who had been praised for catching it, pressing keys by mistake.[1] The FBI said that through its investigation it was not able to confirm that the incident began with a targeted cyber intrusion.[1]
No one was ever charged. The honest summary is that nobody has proved a hacker did it, and nobody has proved one did not.
What it cost
No one was hurt, because the setting was reversed before it could take effect.[1] The real cost was trust and attention. For 2 years the incident was treated as a textbook attack on a water system, even though its basic facts were never settled.[1] The FBI and other agencies used it to urge utilities to move off unsupported software and to stop sharing remote access passwords.[4]
The missing control
The missing control: unique, individual credentials for remote access, with a record of who used them. The plant's computers shared one password for remote login.[3]
That weakness mattered both ways. If an outsider did get in, one shared password meant a single leak exposed everything. And if no one did, the plant still could not quickly prove it, because a shared login leaves no clear trail of which person made which change. Individual accounts with their own passwords and a second login check would have made an outside break-in harder and turned a 2-year mystery into a question answerable in an afternoon.
What to do in your business
- Give everyone their own login. Stop using shared accounts for remote access, payroll, banking or point-of-sale systems, so every action ties back to one person.
- Add a second check to remote access. Require a code or app approval on any tool that lets people log in from outside the building.
- Keep logs you can read. Make sure remote access tools record who connected, when and from where, and know how to pull that record before you need it.
- Retire unsupported computers. Replace or isolate any machine running an operating system that no longer gets security updates, especially one that controls equipment or money.
- Put a firewall in front. Do not connect control systems, cameras or registers straight to the internet; ask your IT provider to put them behind a firewall and allow only the connections you need.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- CyberScoop: Oldsmar water incident was not a cyberattack, former city manager says
- NPR: FBI called in after hacker tries to poison Tampa-area city's water with lye
- GovInfoSecurity: Florida city's water hack: poor security laid bare
- Fortra: FBI urges caution on legacy systems following water hack
- KVIA (CNN): Someone tried to poison a Florida city by hacking into the water treatment system, sheriff says