/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Police say a computer in a water treatment plant in FL, set up for remote access, was breached; the intruder tried raising sodium hydroxide levels in the water

The hacker tried to drastically increase sodium hydroxide levels in the water, Pinellas County, Florida, officials said on Monday.

VICE Jason Koebler

Context & Ripple Effects

The Pinellas County incident shifts the risk from municipal data loss to physical process control: Florida had already seen Lake City's malware-driven municipal outage, while this intrusion targeted the settings governing a treatment chemical. Related coverage also documents vulnerabilities in industrial network equipment used across critical facilities.

The later multi-state water and wastewater attack reports show why a remotely accessible treatment-system computer matters beyond one county: water utilities are a recurring operational target, not simply a source of civic records.

First-order effects

  • Pinellas County must treat remote access to the affected treatment-plant computer as a direct safety-control exposure because the intruder attempted to alter sodium hydroxide levels.
  • The incident puts the plant's separation between remote administration and chemical-dosing controls under immediate scrutiny.

Second-order effects

  • Other water and wastewater operators face a clearer case for reviewing remotely reachable operational systems, especially where a single workstation can change treatment settings.
  • Industrial-network suppliers face greater pressure to show that equipment deployed in critical facilities can limit unauthorized control actions, following earlier reported industrial Ethernet switch vulnerabilities.

Third-order effects

  • The pattern recasts cybersecurity at water utilities as process safety: protecting records is insufficient when compromised access can change the physical service delivered to residents.
  • If incidents continue across utilities, the sector's security priorities are likely to center on constraining remote operational authority rather than merely restoring systems after an intrusion.

The trend: Water-utility cyber risk is moving from municipal IT disruption toward attacks on remotely accessible operational controls with direct public-safety consequences.

Discussion

  • @marcorubio Marco Rubio on x
    I will be asking the @FBI to provide all assistance necessary in investigating an attempt to poison the water supply of a #Florida city. This should be treated as a matter of national security. https://www.vice.com/... via @vice
  • @a_greenberg Andy Greenberg on x
    Florida local officials say hacker tried to dump caustic lye in a 15k-person city's water via access to the water plant's TeamViewer software. A rare public announcement of an industrial control system breach intended to have catastrophic consequences. https://www.wired.com/...
  • @martinsfp Martin Sfp Bryant on x
    😬😬😬😬 (this could have been a serious health hazard) https://twitter.com/...
  • @lachlan Lachlan Markay on x
    Authorities in Pinellas County, FL, say a hacker gained access to water treatment systems and tried to poison an entire town by spiking sodium hydroxide levels https://www.vice.com/...
  • @henrykrinkie @henrykrinkie on x
    it's frankly absurd that these systems are even connected to the internet https://twitter.com/...
  • @tb_times @tb_times on x
    An attacker tried to increase the amount of sodium hydroxide — also known as lye — in Oldsmar's water supply more than 100-fold Friday, Pinellas Sheriff Bob Gualtieri said. The attack was stopped before water was affected. https://www.tampabay.com/...
  • @zorasuleman Zora Suleman on x
    WTAF On Friday #Hackers accessed a water treatment facility in #Florida changing Sodium Hydroxide levels from 100 ppm to a potentially fatal 11,000 ppm - luckily it was spotted by a worker before the chemical change kicked in https://www.vice.com/... https://twitter.com/...
  • @milleridriss Dr. Cynthia Miller-Idriss on x
    This seems like the kind of thing that should be making bigger news right now. How dependent are we for basic public goods like water on systems that are badly secured, outdated or now being monitored from at-home employee setups that are more vulnerable? https://twitter.com/...
  • @garygrumbach Gary Grumbach on x
    “According to the sheriff, the hacker spent up to five minutes in the system and adjusted the amount of sodium hydroxide in the water from 100 parts per million to 11,100.” Sodium hydroxide is the main ingredient in liquid drain cleaners. https://www.wtsp.com/...
  • @jesserodriguez Jesse Rodriguez on x
    This is scary. Cyber attacker tried to raise levels of sodium hydroxide in Oldsmar, FL water supply by a factor of more than 100. A supervisor caught it just in time. https://www.tampabay.com/...
  • @_ainikki Ainikki on x
    Hackers change lye output at Florida water treatment plant. Lucky someone just happened to see it: “The guy was sitting there monitoring the computer...The next thing you know someone is dragging the mouse and clicking around and opening programs and manipulating the system.” htt…
  • @peterpham Peter Pham on x
    yikes. stick with @liquiddeath that isn't gonna kill you. https://twitter.com/...
  • @stephenmendez_ Stephen Mendez on x
    @zackwhittaker There are many issues with this...public, remote, visual access, lack of software controls, lack of intrusion detection, etc. Question becomes which remote access software was involved and how did the person access it?
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: A hacker tried to poison a Florida city by increasing the level of sodium hydroxide in the water supply. Worker who was monitoring levels from home caught it right away and avoided what would have been a disaster. https://www.vice.com/...
  • @wthrcom @wthrcom on x
    The sheriff said the hacker increased the amount of sodium hydroxide in the water from 100 parts per million to 11,100. Sodium hydroxide is also known as lye, which is the main ingredient in liquid drain cleaners. https://www.wthr.com/...
  • @briankrebs @briankrebs on x
    This will be one to watch: https://www.tampabay.com/...
  • @spauldingsez Suzanne Spaulding on x
    @Bing_Chris Example of the importance of tripwires. We need to work on preventing access to ICS but also ensure prompt detection and sufficient resilience/redundancy to prevent significant consequence from a successful intrusion. https://www.wtsp.com/...
  • @chrislhayes Chris Hayes on x
    Seriously W.T.F. https://www.vice.com/...
  • @taliaringer Talia Ringer on x
    I have so many questions, but among them: Why at the software level is it even POSSIBLE to up the lye in the water supply to dangerous levels? If we have well-known safe ranges it should be impossible for even an inside malicious actor to go outside of those ranges https://twitte…
  • @scontorno Steve Contorno on x
    Local government employees are rarely recognized & their contributions to communities are often overlooked. Today, a worker at a local water treatment plant discovered someone was poisoning the water supply via hack and quickly acted to save citizens. https://www.tampabay.com/...
  • @kimzetter Kim Zetter on x
    Note that Florida authorities said there were “redundancies” in place that would have prevented the lye from getting to drinking water. Safety systems do detect things like this, but safety systems, depending on how they're configured, can *potentially* also be subverted.
  • @zackwhittaker Zack Whittaker on x
    I don't think I can reach out for comment and not ask if they're that stupid?
  • @zackwhittaker Zack Whittaker on x
    I can't immediately verify the veracity of the claims made by the sheriff but, the fact that the authorities *set up* a public-facing and/or remotely accessible system that allowed someone to change the water chemical levels is by far the bigger issue here.
  • @zackwhittaker Zack Whittaker on x
    This is wild. Police in Florida say a hacker broke in to a computer system that was *deliberately set up for remote access*, and tried to change the sodium hydroxide level from 100 parts per million to over 11,100 ppm. https://www.youtube.com/...