An operator at the Oldsmar, Florida water treatment facility stopped an attempt to raise sodium hydroxide levels in drinking water from about 100 parts per million to 11,100 parts per million after seeing the change occur on screen during a remote intrusion. Officials said the attacker accessed plant systems through dormant remote-access software and briefly manipulated treatment settings, but the change was quickly reversed and no unsafe water reached residents. Authorities publicly disclosed the incident and did not identify a responsible threat actor.
The case became a high-profile warning for critical infrastructure security, prompting guidance to tighten remote access, strengthen authentication, and improve monitoring in operational technology environments. Later reporting said the Oldsmar event may have been caused by human error rather than a confirmed remote-access cyber breach, underscoring continuing uncertainty over what exactly happened even as the incident remained a touchstone for water-sector cyber risk.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
On 2023-04-04, later reporting said the Oldsmar incident may have been caused by human error rather than a remote-access cybersecurity breach. This represented a significant reassessment of the original understanding of the event.
By 2021-02-10, officials reported that the Oldsmar intrusion involved dormant remote access software on the facility's systems. This added technical detail about the likely access path used in the attempted tampering.
On 2021-02-08, city officials and Pinellas County Sheriff Bob Gualtieri publicly disclosed the Oldsmar water treatment facility incident in a press conference. Authorities said the manipulation was caught before it affected the water supply and did not attribute the intrusion to a specific threat actor.
On 2021-02-05, an unauthorized user remotely accessed the Oldsmar, Florida water treatment facility and, during a second intrusion around 1:30 p.m., changed sodium hydroxide levels from about 100 ppm to 11,100 ppm. A plant operator noticed the cursor movement, reversed the change, and no unsafe water reached residents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
industrialcyber.co
Open sourcecnn.com
Open sourcedragos.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.