Oldsmar Water Treatment Plant, Oldsmar, Florida
Unknown. No actor was ever identified and none has ever been attributed. The FBI was not able to confirm that the incident was initiated by a targeted cyber intrusion, and in 2023 a former city official said investigators found no evidence of outside access. The Pinellas County Sheriff's Office says the case remains open.
Water
No operational or financial impact. The change was reversed within minutes.
Unconfirmed. Remote access to the operator console is the presumed path. The joint federal advisory states only that "it is possible that a desktop sharing software, such as TeamViewer, may have been used ... although this cannot be confirmed at present date." No forensic finding has ever been published.
Unsecured remote access, and the absence of an engineering limit on the setpoint. Whether the command came from outside the plant or from a keyboard inside it, the control system accepted a dose 111 times the normal concentration with no independent constraint between the command and the chemical feed.
Whether an external party was involved, how access was obtained, and who was responsible. Five years on, no forensic finding has been published by any party.
Passwordless Secure Access
%20Cards.png)
On Friday 5 February 2021, a sodium hydroxide setpoint at the Oldsmar water treatment plant was changed from 100 parts per million to 11,100 parts per million and reversed within minutes by an operator who watched the cursor move across his screen. Treated water was never affected. What put the hand on that mouse has never been established.
The Pinellas County Sheriff announced an intrusion three days later, describing a brief remote session that morning that plant staff took for a supervisor, and a second session that afternoon lasting three to five minutes in which an unidentified party navigated to the chemical controls. The joint FBI, CISA, EPA and MS-ISAC advisory issued on 11 February 2021 described the same events without naming the plant, and hedged the vector: "Early information indicates it is possible that a desktop sharing software, such as TeamViewer, may have been used to gain unauthorized access to the system, although this cannot be confirmed at present date." That advisory, as it stands today, also records that "the FBI was not able to confirm that this incident was initiated by a targeted cyber intrusion."
In March 2023, Oldsmar's former city manager said publicly that the incident was a non-event, that investigators found no evidence of access from outside, and that the change was most likely made by a plant employee. The FBI's own statement is narrower than that account and does not support it in full. No forensic report has been published by any party in five years, and the sheriff's case is still open.
The security posture described at the time is a separate matter, and it is not in dispute. No party, including the former city manager, has ever contested it. It is worth being precise about where it came from. The details everyone repeats, remote desktop sharing software reachable from the internet, a single password shared across the plant's computers, 32-bit Windows 7 throughout, and no firewall, appear in a cybersecurity advisory published by the Massachusetts Department of Environmental Protection. They do not appear in the federal advisory, which names no plant, cites no dosage figures, and makes no finding about passwords or firewalls. The Massachusetts department is not an investigating body and has never explained its sourcing.
What can be said without qualification is this. In either account of that afternoon, a control system accepted a chemical setpoint 111 times the normal concentration, and the only thing between that command and the feed pump was a person who happened to be looking at the right screen. The federal advisory makes the same point in its own mitigations, recommending independent cyber physical safety controls, pump sizing, reservoir sizing and valve gearing, so that an attacker who reaches a sodium hydroxide pump is "unable to raise the pH to dangerous levels."
The primary vulnerability was the exposure of a commercial desktop-sharing application that, when compromised, provided complete administrative control.BlastWave eliminates this exposure.
Instead of relying on remote desktop protocols or commercial sharing software exposed to the internet, remote support access is achieved through a secure, identity-validated tunnel that runs the BlastAccess remote desktop application. This tunnel is dynamically created only for the specific, authorized identity, for a defined duration, and strictly to the specific HMI application needed.
This approach ensures the access is temporary, audited, and strictly limited, preventing an attacker from gaining full control over the underlying network or OS.
This holds regardless of how the Oldsmar setpoint was changed. Identity validated, time bound, application scoped access removes the outside path. It does not, on its own, stop a legitimate operator from entering a value the system should never have accepted, which is why an engineering limit on the chemical feed belongs alongside it. Oldsmar is cited across the water sector as an argument for one of those controls. It is a better argument for both.
Editor's note, 10 September 2026
An earlier version of this entry stated as fact that an unidentified cyber actor accessed the Oldsmar water treatment plant's SCADA system through an inactive TeamViewer account, exploiting Windows 7 and weak passwords. That is how the incident was reported in February 2021 and it is how most of the industry, this catalog included, has described it ever since. It is more than the record supports.
The joint FBI, CISA, EPA and MS-ISAC advisory AA21-042A, published on 11 February 2021, never named Oldsmar, cited no dosage figures, and made no finding about shared passwords or firewalls. On the vector it said only that "it is possible that a desktop sharing software, such as TeamViewer, may have been used to gain unauthorized access to the system, although this cannot be confirmed at present date." The technical details that everyone repeats, ourselves included, come from a separate advisory published by the Massachusetts Department of Environmental Protection, which is not an investigating body and has never explained where it got them.
On 20 March 2023, at a public administration conference, Oldsmar's former city manager described the incident as a non-event and said the FBI "concluded there was nothing, no evidence of any access from the outside, and that it was likely the same employee that was purported to be a hero for catching it, was actually banging on his keyboard." In April 2023 the FBI told CyberScoop that "through the course of the investigation the FBI was not able to confirm that this incident was initiated by a targeted cyber intrusion of Oldsmar."
We want to be careful about what that does and does not mean, because the correction is being overstated in the other direction now. "Not able to confirm" is the standard language of an inconclusive investigation. It is not a finding that nothing happened. The Pinellas County Sheriff's Office, which announced the intrusion in 2021, said in 2023 only that the case is still open, and it has never retracted or defended its original account. The former city manager's account is uncorroborated, given from memory two years afterward, and sits awkwardly against what he said at the time, which was that the city had "obviously disabled the program that enabled it to happen." No document supports either version. That is the honest state of it.
One thing did change quietly. Archived captures of the federal advisory show that the sentence "Through the course of the investigation, the FBI was not able to confirm that this incident was initiated by a targeted cyber intrusion" was not present on 22 March 2023 and was present by 6 May 2023. The advisory's revision history still reads, in full, "February 11, 2021: Initial Version" and "February 12, 2021: Update to PDF File." No revision was logged, no correction was issued, and the title still reads "Compromise of U.S. Water Treatment Facility."
Almost nobody appears to have noticed. A Congressional Research Service report published on 3 June 2025 opens by telling Congress that "in 2021, a cyberattack in which a hacker attempted to pump dangerous amounts of lye into a water system in Oldsmar, Florida, garnered national attention," sourced to day one newspaper reporting and carrying no caveat. Before the House Homeland Security Committee on 22 July 2025, one witness told members that "a water treatment facility in Oldsmar, Florida was hacked through its TeamViewer remote-management software over the internet," which is the single detail the advisory expressly declines to confirm. A Department of Energy national laboratory case study describing an adversary gaining unauthorized remote access to the plant is still online and uncorrected. The most cited water sector incident in the United States had its federal advisory amended three years ago and the citation chain never caught up.
What is not in dispute is the security posture. Nobody, including the former city manager, has ever contested that the plant ran remote desktop sharing software reachable from the internet on end of life operating systems. And in either account of that Friday afternoon, the control system accepted a sodium hydroxide setpoint 111 times the normal dose with nothing between the command and the chemical feed except an operator who happened to be looking.
We have marked this entry Contested. The lesson we drew from Oldsmar has not changed. Our confidence in the story we told to reach it has, and saying so is worth more than the original claim was.
Reading about past failures is only useful if it changes future outcomes. If attackers can see your OT network, they can target it. If they can target it, compliance, safety, and uptime are already at risk.
BlastWave eliminates reconnaissance, initial access, and lateral movement — without agents, without downtime, and without changing IPs, protocols, or PLCs.