Chicago/ Crime & Emergencies

Chicago's Jardine Water Plant Fights Off Hackers Targeting Millions' Taps

AI Assisted Icon
Published on August 28, 2026
Chicago's Jardine Water Plant Fights Off Hackers Targeting Millions' TapsSource: Unsplash/Iain

The world's largest conventional drinking water treatment plant sits quietly along Lake Michigan just north of Navy Pier, pushing out enough water each day to supply millions of people across Chicago and 120 suburbs. But behind that scale lies a persistent and growing danger: the James W. Jardine Water Purification Plant has become, in the words of its own officials, a prime target for cyberattackers who have already gotten inside its front-office systems once.

According to NBC Chicago, hackers locked the Chicago Department of Water Management's front-office computers for two months in a ransomware attack that targeted administrative and office computer systems supplied by an outside vendor. The hackers obtained paperwork for work performed, but the outlet reports that Chicago cyber experts eventually figured out the ransomware puzzle and rebuilt the computer system rather than pay the attackers. Department Commissioner Randy Conner said the water department did not pay a ransom, and officials maintain the hackers did not obtain sacred information or anything damaging to anyone.

Crucially, the outlet's report notes that cyberattackers have not interfered with the chemical treatment of water systems, nor have they stopped the flow of water altogether. Conner said Chicago tries to stay one step ahead of cyberattackers, and that whether intruders can break through often depends on the sophistication of the bad actors involved.

A Plant Built to Dwarf the Capitol

The Jardine plant is named for James Jardine, a longtime commissioner who served in the role during the 1950s and 1960s, the same report notes. Physically, the facility is larger than the U.S. Capitol and can accommodate the footprint of five Capitol buildings, a scale that underscores just how much is riding on its cyber defenses. The plant contains pump routing devices that federal law enforcement officials have suggested were the specific target Iranian hackers accessed during a separate wave of attacks on American water systems.

Those attacks on American water systems began about a month before the NBC Chicago report was published and eventually targeted more than 100 facilities nationally, per the same account. Some publicly available factory passwords reportedly had not been changed before those cyberattacks hit. Chicago's water department, by contrast, says it sets its own passwords from inside the organization rather than relying on manufacturer defaults, and that officials update and monitor those passwords constantly.

Federal Warnings Echo a National Pattern

Chicago's posture reflects a broader federal alarm over water-sector cybersecurity. On July 30, 2026, the FBI and EPA issued a joint public advisory warning that cyber actors were actively exploiting internet-facing Rockwell Automation and Allen-Bradley programmable logic controllers at water and wastewater utilities across at least seven states, causing direct operational disruptions, according to the FBI. That warning follows a pattern federal regulators have flagged for years: in May 2024, the U.S. Environmental Protection Agency found that more than 70% of inspected community water systems had failed to comply with basic Safe Drinking Water Act cybersecurity requirements, including neglecting to change default passwords.

A November 2024 EPA Office of Inspector General assessment scanning more than 1,000 public drinking water systems serving 193 million Americans identified critical or high-priority cybersecurity vulnerabilities at 97 utilities, with 211 more carrying medium or low-level risks, per StateScoop. In March 2024, the EPA and the National Security Council warned state governors that state-sponsored actors, including China's Volt Typhoon and Iran's IRGC, were pre-positioning inside U.S. water facility networks to prepare for potential disruptive attacks during geopolitical conflicts.

Real-world precedent for what can go wrong exists just outside Illinois. In November 2023, the Iranian-backed threat group CyberAv3ngers compromised a pressure-boosting station at the Municipal Water Authority of Aliquippa, Pennsylvania, by exploiting Israeli-manufactured Unitronics PLCs, forcing operators to disable automated controls and switch to manual operations, CBS News reported. And in October 2024, American Water, the nation's largest publicly traded water and wastewater utility serving 14 million people, was forced to temporarily disconnect its customer portals and billing networks after a major cyber incident, though its physical treatment operations remained isolated and unaffected, according to TechTarget.

Isolating the Physical System From the Digital One

That IT-versus-operational-technology split is exactly the strategy Chicago water officials describe leaning on. Law enforcement agencies and water purveyors nationally are working to prevent attacks from interfering with chemical treatment or halting water flow even when administrative networks are compromised, the NBC Chicago investigation notes. Chief filtration deputy Harold Keaton and Commissioner Conner have described the Jardine facility as being on a higher state of alert, with locked doors and restricted interior areas limiting physical access on top of the digital safeguards.

The stakes for Chicago are unusually large. The water system serves 42% of Illinois's population, and the Department of Water Management distributes roughly 750 million gallons of drinking water daily across 4,300 miles of water mains to more than 5.1 million residents across the city and 120 surrounding suburbs, according to the City of Chicago. Any disruption to that grid would ripple far beyond the city's own borders, a fact regulators and city officials alike have called a public safety concern.

Money Pressures Layer Onto the Cyber Fight

The cybersecurity push is unfolding as Chicago pours substantial capital into modernizing the aging plant. City budget documents show the Department of Water Management's proposed FY2026 budget allocated $290.2 million specifically for construction and overhaul of buildings and structures, per BGA Policy. That investment comes even as the department faces a financial threat from an unexpected direction: suburban leaders in DuPage and Cook counties announced a $6 billion regional initiative this month to build an independent Lake Michigan water supply and purification system, a move that could pull away roughly 15% of Chicago's water operating revenue, as Hoodline detailed in its report on the suburban breakaway bid.

Similar cyber pressures have already touched other Chicago-area systems. Hoodline previously reported on a cyberattack that sent fraudulent payments through Aurora's municipal systems, and on hackers who forced a Georgia utility to lock out water controls and switch to manual operations in a case that mirrors the tactics federal officials are now warning about nationwide. For now, Chicago officials say the Jardine plant's defenses have held, but the broader threat landscape shows no sign of easing.