Someone Tried to Poison a Florida City's Water Supply Remotely
In 2021, an attacker briefly took control of a water treatment plant's chemical controls. An operator watching the screen caught it in seconds. Here's why that near-miss still matters.
In February 2021, an operator at a water treatment plant in Oldsmar, Florida watched their mouse cursor move on its own, opening software the plant uses to control water chemistry — and then watched the target level for sodium hydroxide, the chemical that controls water pH, jump from 100 parts per million to 11,100.
What sodium hydroxide overdose would have meant
Sodium hydroxide (lye) is used in small, carefully controlled amounts to keep drinking water from being too acidic. At the concentration the attacker briefly set, it’s the same chemical used in drain cleaner — capable of causing serious harm if it had reached the water supply at that level.
Why it didn’t become a disaster
The operator noticed the cursor moving in real time, immediately reversed the change, and the plant had additional safeguards downstream that would have caught the chemical imbalance before treated water reached anyone’s tap even if the change had gone unnoticed. The system worked because a human was watching — not because the intrusion itself was stopped.
How the attacker got in
Investigators found the plant used TeamViewer, remote-access software, to allow staff to monitor systems from outside the facility — a common and unremarkable setup at small utilities with limited IT staff. That same remote access, likely reached with weak or reused credentials, is what let an outside party in.
Why this incident is still cited years later
Most cybersecurity coverage focuses on data theft. This incident is different: it’s one of the clearest public examples of a cyberattack with a direct path to physical, public harm, and it happened at a small municipal utility, not a well-funded target — a reminder that critical infrastructure risk isn’t limited to major cities or headline-grabbing pipelines.
What this means beyond Oldsmar
Small utilities, water districts, and municipal systems across the country run on the same kind of lean IT setup Oldsmar did. The fix isn’t something individual residents can act on directly, but it’s exactly the kind of story worth watching for in your own area — local utilities are increasingly required to disclose these incidents, and they rarely make national news.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
Colonial Pipeline, Years Later: The Lesson That Actually Stuck
The 2021 ransomware attack that shut down fuel supply on the East Coast started with a single reused password. That detail still matters more than the headline did.
When Ransomware Shut Down an Entire Country's Government
In 2022, ransomware hit so many Costa Rican government agencies at once that the president declared a national emergency — a response usually reserved for natural disasters.