Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The October 13, 2021, headline “Homeland Security Warns of Cyberattacks Intended to Kill People” referred to then-Secretary Alejandro Mayorkas’s warning that attacks on systems controlling physical processes could cause injury or death. It did not announce a confirmed cyberattack that had killed someone, nor did federal investigators establish that the Oldsmar, Florida, water-plant intrusion was intended to kill.
In Oldsmar, unidentified actors changed a chemical-treatment setting, but plant personnel caught and reversed the change before the treatment process was affected. The incident showed why cyber access to industrial controls can pose a safety risk; it did not prove the most dramatic interpretation of the headline.
What was Homeland Security warning about?
In an October 13, 2021, report, Futurism described Mayorkas’s warning that cyberattacks could move beyond stealing data, disrupting services, or demanding ransom and produce physical harm by manipulating critical infrastructure. Futurism reported his remarks and characterization of the Oldsmar incident; the article is not a verbatim transcript of the underlying interview.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe distinction is between an attack on information technology (IT), which handles data and business applications, and an attack that reaches operational technology (OT), which monitors or controls equipment and physical processes. An OT intrusion might change a pump, valve, chemical dose, temperature, or pressure. It can also create danger indirectly: disabling a service or depriving staff of reliable information may make safe operation harder.
#1 Best Overall
“Killware” is a media and industry shorthand for cyber activity associated with physical injury or death, not a universally standardized technical category. A ransomware incident can become a safety emergency if essential care or infrastructure is disrupted, but that does not automatically make it a proven attack intended to kill. A 2021 Gartner forecast about attackers weaponizing OT by 2025 was cited by Futurism; it should be treated as a forecast reported at the time, not as proof that a defined new class of attack emerged.
What happened at the Oldsmar water plant?
On February 5, 2021, unidentified actors gained unauthorized access to a municipal drinking-water facility’s supervisory control and data acquisition (SCADA) system. SCADA systems let operators monitor and control industrial processes. The actors changed the setting for sodium hydroxide, also known as lye, used in water treatment. Plant personnel noticed the change and corrected it before the treatment process was affected, according to the joint FBI, CISA, and EPA advisory.
The episode illustrates both the danger of unauthorized control and the value of human safeguards. Operators detected and reversed the change; the advisory does not say treated water was affected. The EPA material on the incident described weaknesses including shared remote-access credentials, internet-connected remote-access software, poor password security, and an outdated operating system.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What the Oldsmar evidence establishes—and what it does not
| Question | What the cited federal advisory establishes |
|---|---|
| Was there unauthorized access? | Yes. Actors accessed the facility’s SCADA system. |
| Was a chemical-treatment setting changed? | Yes. The sodium-hydroxide setting was increased. |
| Was treatment affected? | No. Personnel detected and corrected the change before the treatment process was affected. |
| Were deaths or injuries reported? | No deaths or injuries are reported in the cited advisory. |
| Who carried out the intrusion? | The advisory identifies the actors as unknown. |
| Was an intent to kill established? | The cited advisory does not establish the actors’ motive. Calling the incident a proven attempt to kill goes beyond that evidence. |
Mayorkas characterized the incident as an example of malicious activity with grave public-health and safety implications, as reported by Futurism. That warning about possible consequences should be kept separate from what investigators established about the actors’ intent. The setting change could have created a serious hazard if it had gone unnoticed, but potential consequence, actual outcome, and motive are different questions.
Rank #3
Why an OT compromise can affect physical safety
Industrial facilities use several kinds of control technology. A programmable logic controller (PLC) directly controls equipment or a process. A human-machine interface (HMI) is the screen or software operators use to view status and change settings. SCADA systems gather information from equipment and allow operators to supervise processes across a facility or network. If an attacker can reach these controls, the concern is not only stolen data: unauthorized commands or loss of trustworthy monitoring can affect the physical operation.
CISA and EPA warn that internet-exposed HMIs can let threat actors view process information and make unauthorized changes that disrupt water or wastewater treatment. Internet exposure is one route, not the only one. Risk can also enter through remote-maintenance tools, vendors, compromised business networks, removable media, or stolen credentials.
Rank #4
- Water and wastewater: Unauthorized changes could affect dosing, pumps, valves, or operators’ ability to monitor treatment and distribution.
- Hospitals: An outage can delay procedures, divert ambulances, or make records and connected equipment less available. A death occurring during an outage does not by itself prove the outage caused it.
- Energy, fuel, and manufacturing: Disrupted operations can affect equipment, production, or service availability. The consequences depend on the system and safeguards involved.
- Transportation and buildings: Digital controls can support essential monitoring and operation; losing reliable control may create safety concerns even when an attacker does not directly command dangerous equipment.
Loss of availability can itself become a safety problem where essential services lack safe manual alternatives. Conversely, alarms, independent process checks, trained staff, and the ability to operate manually can limit the consequences of a compromised control system.
How current is the risk?
The current concern is best described as cyber risk to vulnerable OT, not a newly established attack category called “killware.” EPA says attacks against community water systems are increasing in frequency and severity in its drinking-water cybersecurity enforcement alert.
Best Value
An EPA inspector-general report examined 1,062 drinking-water systems serving more than 193 million people. In the scan cited in the report, dated October 8, 2024, 97 systems serving approximately 26.6 million users had critical or high-risk cybersecurity vulnerabilities. These are findings from that assessment and scan, not a count of systems known to have been attacked. See the EPA inspector-general report.
On April 7, 2026, EPA, the FBI, CISA, and NSA warned of Iranian-affiliated cyber activity involving OT at U.S. water and wastewater systems. The agencies’ joint advisory concerned activity affecting systems that include programmable controllers and HMIs. It is evidence of a current OT threat, not retroactive proof about who was behind Oldsmar or what those actors intended.
Federal agencies have also issued sector-specific guidance. In 2024, CISA, EPA, and the FBI published top cybersecurity actions for water systems. The central lesson is practical: reduce unnecessary exposure, secure access, separate networks, and prepare to detect and recover from unsafe changes.
Recommended Free Tools
How utilities and critical-infrastructure operators can reduce the risk
Controls should be selected with operational constraints in mind: older equipment may be difficult to patch or replace without vendor support, downtime, or coordination. No single safeguard—MFA included—substitutes for a layered plan. CISA’s OT mitigations fact sheet and EPA’s water-sector guidance support a defensive approach that includes:
- Limit exposure: Remove unnecessary public-internet access to OT assets and HMIs. Inventory IT and OT equipment so operators know what needs protection.
- Secure accounts and remote access: Replace default and shared passwords, use strong authentication and MFA where technically feasible, restrict remote access to approved users, and monitor it.
- Separate networks: Segment business IT from control networks and limit the paths and privileges available between them.
- Maintain systems safely: Patch vulnerable software where supported, plan replacement for unsupported operating systems, and coordinate changes with vendors and operations staff.
- Prepare to recover: Back up trusted IT and OT configurations, preserve logs, and test incident-response and recovery plans.
- Practice safe fallback: Train staff to recognize suspicious changes and verify process conditions; ensure essential operations can be conducted safely if digital controls fail.
A resilient operator should be able to spot abnormal changes, determine whether commands are legitimate, stop or reverse unsafe changes, maintain essential service manually when needed, and restore trusted configurations. Prevention matters, but detection and recovery are what limit harm when prevention fails.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

