When Hackers Turn On the Tap, Every Business Should Pay Attention
Imagine getting a call at 6 a.m. telling you that the town’s water treatment plant has been taken over by hackers. Residents are panicking, the plant is offline, and people are being told to conserve water. That’s not a scene from a thriller—it happened across the US in late July and early August, and it’s still unfolding. On the surface, a cyberattack on American water utilities might feel like a distant problem. But as a Malaysian SME owner, it should feel like a warning shot aimed directly at you.
Why? Because the organizations that got hacked were not giant corporations or government agencies with huge security budgets. They were small local utilities, often run by small teams with limited IT staff—exactly the profile of most Malaysian SMEs. The hackers didn’t choose their targets because they were famous. They chose them because they were easy. And “easy” is a description many of us would rather not apply to our own systems, but we should be honest about it.
TL;DR: The alleged Iranian hacks on US water utilities are part of a wider trend of attackers going after small, under-protected organizations. If you run an SME, you are probably in their crosshairs. In this post, you’ll learn why these attacks happen, how they connect to your daily operations, and three practical moves you can make this week to lower your risk—no IT degree required.
What This Means in Plain Language
In the last two weeks of July, water treatment plants in more than 30 Minnesota communities were hit by coordinated attacks. The FBI soon confirmed that water utilities in at least seven states reported incidents, and some cases “degraded water operations.” There were also reported hacks in Arkansas, Georgia, New Jersey, and Michigan. While the official attribution isn’t public, US intelligence agencies are reportedly confident that Iran’s Islamic Revolutionary Guard Corps (IRGC) is behind it.
Here’s the part that matters for you: the US has more than 150,000 water systems, many run by local companies that lack cybersecurity expertise. Security researchers found more than 2,800 controllers in US water systems exposed online—sitting on the internet with no real protection. The hackers didn’t need to break through sophisticated firewalls. They just found open doors.
“The worst effect, however, may be psychological. These attacks have been widely covered in national and local press, causing people to worry about the safety of a fundamental and basic need like water. That may very well be part of the hackers’ goals: to spread panic and fear.”
That quote comes straight from the TechCrunch analysis—and it’s a perfect reminder that cyberattacks aren’t just about stolen data or corrupted files. They’re about disruption and fear. When a small utility in Minnesota had to take its water plant offline for a few hours, the physical impact was temporary. The emotional impact on residents was much longer lasting. The same logic applies to your business: if you’re down for a day, your customers may not forgive you quickly.
How This Applies to Malaysian SMEs
You may be thinking: “I run a small factory, a retail shop, or a logistics company in Malaysia. I don’t operate water infrastructure.” Fair enough. But that’s exactly the mindset attackers count on. They don’t only target critical infrastructure directly—they target every organisation that touches it, supplies it, or shares data with it. If you do business with a Malaysian utility, a government-linked company, or a multinational firm, you’re part of their supply chain. And as the US attacks showed, smaller players are often the least defended link in that chain.
Consider what happened in the US: the hackers targeted internet-connected devices in water systems. Those devices—sensors, controllers, monitors—are everywhere in Malaysian industrial settings, too. Maybe you have a CCTV system that you can check from your phone. Or a fingerprint scanner for attendance. Or an inventory sensor linked to an app. Any of these could be connected to the internet with default passwords or outdated firmware. That’s all an attacker needs to get a foothold. Once they’re inside, they can move to your main network, your customer database, or your accounting system.
Now think about the broader context. Cybersecurity experts have long noted that Iranian hackers target “low-hanging fruit” in opportunistic attacks. The US water utility campaign was described as a “significant escalation” because it was coordinated and widespread. That escalation matters to you because Malaysia is not disconnected from global cyber threats. Malware campaigns, ransomware groups, and state-backed hackers don’t stop at borders. When a new attack tool is discovered in the US, it often shows up in Southeast Asia within weeks.
There’s also a wild card: your employees. Most SME owners in Malaysia don’t have a full-time cybersecurity person. That means the person who answers an email, clicks a link, or plugs in a USB drive is the first line of defense. The US water attacks were able to spread because back-end systems were exposed and staff didn’t spot the intrusions early. The same will be true in Malaysia unless you make a conscious effort to build basic cyber hygiene. This isn’t about buying expensive software; it’s about changing habits. And that starts with you, the owner.
| What happened in the US water hack | What it means for your SME |
|---|---|
| Water utilities in 30+ Minnesota communities hit in late July | If a utility can be attacked, so can any business smaller than it |
| FBI reported incidents in at least 7 states | Attackers often hit multiple targets at once—geography is no barrier |
| More than 2,800 controllers exposed online | Your internet-connected devices may be exposed too, without you knowing |
| Attacks caused loss of pressure, flooding, and boil-water alerts | Operational disruption can have physical consequences beyond data loss |
| Hackers allegedly chosen these targets because they lacked resources | Small and medium businesses are exactly the kind of “low-hanging fruit” attackers prefer |
Practical Takeaways: What You Can Do This Week
You don’t need to hire a cyber expert or buy an expensive system to reduce your risk. Here’s a simple, no-nonsense checklist you can run through in a few hours—many of these are free or cost very little in time:
- Change every default password. Walk around your office and update the admin passwords on your WiFi router, CCTV system, printers, and any IoT device. Use long, unique passphrases. Write them down somewhere offline if you must.
- Check what’s exposed to the internet. Ask someone with basic IT knowledge (or your service provider) to look at your public-facing IP range. If you don’t need remote access to a device from outside, turn it off.
- Turn on two-factor authentication (2FA). This applies to your email, cloud storage, banking portals, and any business app you use. It adds a second step that costs 10 seconds but blocks the most common attacks.
- Do a quick employee briefing. This doesn’t have to be formal. Gather your team for 15 minutes and show them what a phishing email looks like. Tell them to stop and ask before clicking any unexpected link or attachment.
- Back up your essential data. Make sure your critical files are backed up automatically to a secure cloud service or an external drive that isn’t always connected. Test that you can actually restore from the backup.
- Know who to call. If you have a managed IT provider, ask them how to report a suspected incident. If you don’t have one, keep the contact information for CyberSecurity Malaysia or local law enforcement handy.
These steps won’t make you unhackable—nothing will. But they will push you out of the “low-hanging fruit” category. And that’s exactly what you want.
The Bigger Picture: Why Your Business Is Part of National Defense
The US water hack is a reminder that cybersecurity isn’t just a corporate problem. It’s a national security issue that starts with thousands of small operators and suppliers. The US has 150,000 water systems because no single entity can run them all—just like Malaysia has hundreds of thousands of SMEs that form the backbone of its economy. If a major disruption hits one sector, the ripple effect goes far beyond the original target.
Long-term, expect more governments—including Malaysia—to put pressure on suppliers and critical infrastructure supporting industries to meet basic cybersecurity standards. That could mean stricter regulations, mandatory reporting of incidents, or more audits from clients who want to know your security posture before they sign a contract. The smart approach is not to wait for that pressure. Build a baseline level of hygiene now, and you’ll be ahead of both threats and requirements.
Ultimately, the lesson from the water plants is simple: attackers don’t care how big you are or what industry you’re in. They care about how easy it is to get in and how much damage they can cause. As a Malaysian SME owner, you have more control over the “easy” part than you probably think. You don’t need to become a cybersecurity expert. You just need to stop being the easiest target on the street.
After all, in the digital world, being small doesn’t make you invisible. It makes you a target.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
