On 23 July 2026, an unauthorized person breaks in and takes control of a drinking water station serving 350 people. Yet this attack was not targeted.
The pro-Russia group Z-Alliance gets into the drinking water station's system, disables the water level alarms and changes the chlorine dosing, then posts a ten-minute video on Telegram. The employee on duty detects the intrusion shortly after 8 a.m. The water stayed safe to drink, but it was not a defence that protected the village: according to Radio-Canada, by setting the level probes to zero the attackers unintentionally triggered the automatic shutdown of the pumps.
Radio-Canada, 30 July 2026 · Le Soleil and Noovo, 31 July 2026. Investigation by the Surete du Quebec, the provincial police force.
The NoName group claims access to the Georgetown water treatment station and posts screenshots of its supervisory display. On 27 July it writes: "While officials talk about reliability, we are quietly inside their system." It was a cybersecurity expert, and then the press, who warned the municipality.
Radio-Canada · claim published by the group.
Pressure losses, boil water advisories, reversions to manual operation. On 30 July the FBI counts at least seven states affected; the count will reach twelve in early August, and attribution is still unsettled. The same day, the US cybersecurity agency describes a significant escalation in attacks against control equipment reachable from the internet.
Tenable · ABC News, 4 August 2026 · FBI alert and CISA sector alert of 30 July 2026.
Twenty-two months before 23 July, the Government of Canada had written down what was going to happen.
"We assess that PRNS actors will likely attempt to disrupt vulnerable Internet-connected OT systems within Canadian critical infrastructure when the opportunity arises."
"This activity opportunistically targets internet-accessible devices and exploits basic vulnerabilities, such as insecure remote access software or the use of default passwords."
The important word is not "Russia". It is "opportunistically" and "internet-accessible".
Nobody in an office overseas picked Saint-Noel. Nobody assessed its budget or its strategic importance. An automated sweep of the internet found an exposed sensitive service, and simply interacted with it. A village of 387 people, a town of 63,000, neither mattered: size never entered the equation. Besides, they were not the first.
Nine months earlier, the same Centre reported three Canadian incidents in the space of a few weeks: a water facility, an oil and gas company, a farming operation. Alert AL25-016, 29 October 2025.
The sentence that sums up the whole problem does not come from the attackers. It comes from a cybersecurity expert quoted by Radio-Canada, who alerted the police in the Ontario case: "I am the one who called to wake them up, because nobody knew.". A municipality can be inside a system that is being claimed publicly on Telegram, and learn about it from a third party.
This is not a hypothesis. It is a public auditor's finding, made in Quebec, then checked again three and a half years later.
In 2022, all three held data about that equipment, but none had ranked it by criticality. The first recommendation was to inventory and classify the assets: everything starts there. At the May 2026 follow-up, two towns reported 100% of recommendations applied or showing progress judged satisfactory. The third was at 43%, and the Commission is continuing its work with it.
This is not unwillingness, it is a question of hands. A municipality of 1,200 people has no information security officer: it has a general manager who does everything, and an IT supplier paid to keep things running, not to watch what is visible from outside. Among Canadian businesses, the share with staff dedicated to cybersecurity fell from 61% to 50% in two years; the survey does not cover public administrations.
Commission municipale du Quebec, the province's municipal oversight body: performance audit of 1 November 2022 and follow-up report of 21 May 2026. The towns are deliberately not named here: the point is not which one fell behind, it is that three and a half years are not enough. Staffing: Statistics Canada, Canadian Survey of Cyber Security and Cybercrime 2023 (12,462 businesses).
The Government of Canada puts it in one sentence. In its assessment devoted to water systems, the Canadian Centre for Cyber Security judges it almost certain that there are water system operators in Canada with devices exposed on the internet. The question it leaves open is which ones. Canadian Centre for Cyber Security, The cyber threat to Canada's water systems: Assessment and mitigation, information available as of 31 May 2025.
Subdomains, IP addresses, services and suppliers attached to the municipality, starting from a single domain name.
Remote desktop, access portals and perimeter firewalls, equipment management interfaces reachable publicly.
Who can write in the name of the town's domain, and which services actually send on its behalf.
Cloud storage left public, configuration files and logs reachable from outside.
Certificates approaching expiry, addresses still pointing at an abandoned service.
A dated document for the municipal council, the regional county municipality, or your insurer.
The analysis is entirely external: no software on your servers, no access to your systems, no interruption. It starts from a domain name and looks at your municipality the way someone looking for a door would.
What this is not, and it needs saying: we do not secure your water treatment plant. We do not talk to controllers, we do not enter your network, and we do not replace an on-site audit. We tell you what the world sees of your municipality from the internet, and we tell you again when it changes. You cannot protect what you do not know you own: that first step is the one nobody has time to take.
They require no technical knowledge. They are put to your IT lead, to your service provider, or to both in the same meeting.
If the answers worry you, the first step costs nothing and has nothing to do with us: ask for that list in writing, with a date. Many municipalities find out at that moment that nobody keeps one.
Two ways to start, without talking to anyone.
Who can send email in your municipality's name? A free check of what your domain publishes for SPF, DKIM and DMARC. No account, no card, immediate result.