Hackers breached an unidentified Oregon water district's operating technology in July, but the Tualatin Valley Water District, which delivers drinking water to Beaverton and surrounding communities, was not the target.
TVWD spokesperson Justin Dyke confirmed to OPB on Friday, Aug. 7, that the district has seen an increase in hacking attempts. None have succeeded, and the district has not reported any to the FBI.
"If those systems go down, operators have back-up plans and make changes manually," Dyke told OPB, describing how staff can switch to manual control of flow rates and reservoir levels if digital systems are compromised.
TVWD is Oregon's second-largest drinking water provider, serving approximately 222,800 residents across 41 square miles of Washington County, including portions of Beaverton, Hillsboro and Tigard.
Gov. Tina Kotek's office confirmed the breach to OPB on Friday but declined to name the affected district. Hope Hiebert, spokesperson for Oregon Enterprise Information Services, said the state is aware of a July cyber incident involving unauthorized access to operational technology at an Oregon drinking-water provider. The FBI's Portland office also declined to identify the target.
A national wave
The Oregon breach is part of a larger campaign. The FBI and EPA warned on July 30 that hackers had hit water and wastewater systems in at least seven states since July 27, with some attacks degrading operations. At least 100 municipalities nationwide detected malicious activity, according to a New York Times report the same day.
The attackers targeted Rockwell Automation programmable logic controllers, small computers that run pumps and valves. By connecting remotely and changing passwords, hackers caused loss of monitoring, pressure drops and flooding in some systems. In Minnesota, one treatment plant went temporarily offline. In Georgia, a utility briefly issued a boil-water advisory.
U.S. investigators are examining whether the attacks were carried out by Iranian hackers, CBS News reported, though no formal attribution has been made. Investigators are also considering whether another actor may have mimicked Iranian tactics. Iran-linked actors targeted U.S. water utilities in 2023 using similar methods.
TVWD's response
Dyke said TVWD operators are aware of cyber threats and prepare for them. The district's online systems let staff quickly adjust flow rates and reservoir levels when demand shifts, but manual backup procedures are in place if those systems fail.
The district posted a cybersecurity program manager position in late 2025, signaling it was already investing in cyber defense before the current wave of attacks.
The FBI is encouraging water districts nationwide to limit remote access, use strong unique passwords and maintain manual backup plans.
Residents with questions can contact TVWD at (503) 848-3000.







