Yes, attackers accessed a U.S. drinking-water treatment plant’s control system in 2021 and changed its sodium-hydroxide dosing setting. Operators caught and corrected the change before the SCADA alarm reacted, and the treatment process remained unaffected. The incident is a warning about exposed remote access and unsupported computers—not evidence that Windows 7 alone caused the intrusion or that water was poisoned.
What happened at the water-treatment plant?
On February 5, 2021, unidentified cyber actors gained unauthorized access to a U.S. drinking-water treatment plant’s supervisory control and data acquisition (SCADA) system and increased the sodium-hydroxide dose. Sodium hydroxide, also known as lye, is used in water treatment. Plant operators noticed the setting change and corrected it before the SCADA alarm reacted. The process was not affected.
The joint advisory from CISA, the FBI, EPA and MS-ISAC identified poor password security and an outdated operating system as likely weaknesses. It also said TeamViewer or similar desktop-sharing software may have provided a route in. Those are identified possibilities, not proof that one product or Windows 7 by itself caused the incident. The advisory’s account establishes an attempted unauthorized change, not that contaminated water reached customers.
Why did officials warn about Windows 7?
Microsoft ended Windows 7 support on January 14, 2020. A computer running an unsupported operating system no longer receives normal security updates for newly found vulnerabilities, leaving flaws unpatched and increasing exposure to malware. CISA warned that Windows 7 would become more susceptible as new vulnerabilities were discovered and recommended migration to an actively supported operating system.
#1 Best Overall
- Processor Model: i5-4590
- Standard Memory: 8GB
- Total Hard Drive Capacity: 500GB
- Operating System: Windows 7
“Continuing to use any operating system within an enterprise beyond the end of life status may provide cyber criminals access into computer systems.”
That warning, from the joint CISA, FBI, EPA and MS-ISAC advisory, applies to unsupported operating systems generally. It does not mean that every computer running Windows 7 is compromised. Nor does replacing Windows 7 by itself secure a control network: passwords, remote access, network separation and physical safeguards matter too.
Rank #2
- Microsoft Authorized Refurbisher
- Windows 7 Professional 64bit
- PACKAGE DOES NOT include monitor or keyboard/mouse
Microsoft’s support guidance likewise cautions that a PC past end of support becomes vulnerable without ongoing security fixes. Its older recommendation to use Windows 10 should not be treated as a current operating-system recommendation: check Microsoft’s current lifecycle guidance and the control-system vendor’s compatibility requirements before choosing a migration target.
What should a water utility do about a Windows 7 control computer?
Plan to move the host to a currently supported operating system, but coordinate with the SCADA vendor and operations staff. A control computer may depend on specific software, drivers or equipment; an unplanned upgrade can disrupt treatment operations. If a supported replacement cannot be deployed immediately, reduce the host’s exposure while arranging a controlled migration.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
- Inventory the legacy host and its dependencies. Identify its role, connected controllers, required software, vendor support and remote-access paths. Agree on a migration and recovery plan with the system vendor and plant operations staff.
- Restrict the computer while it remains in service. Isolate it from ordinary business networks and allow only necessary, explicitly authorized communications. Limit who can access it and from where. Isolation reduces exposure; it does not make unsupported software supported or remove its unpatched vulnerabilities.
- Secure any necessary remote access. Require multifactor authentication and unique, strong passwords for remote desktop protocol (RDP) and remote-support accounts. Close unused RDP ports and review remote-connection logs for activity that does not match expected users or schedules.
- Test and schedule migration. Confirm that the supported operating system and SCADA application work with the plant’s equipment. Schedule the change to limit operational disruption, and keep a tested recovery plan in case the new host or control software fails.
- Verify the result. Confirm that the new host receives security updates, remote access is limited to approved accounts and paths, and the intended network segmentation remains in place.
A Windows installation USB is only migration media. It does not establish that the chosen release is currently supported, that the license is valid, that the control software is compatible, or that the network is secure.
How should a utility decide between migration and interim controls?
These measures address different parts of the risk. Migration removes dependence on an unsupported operating system; containment and access controls reduce opportunities for misuse while migration is pending. No single measure substitutes for all the others.
Rank #4
- This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high performance bar may offer Certified Refurbished products on Amazon.com
- Intel Core i7-3770 3.40GHz Processor
- 8GB DDR3 Memory
- 256GB Solid State Drive
- Windows 7 Professional x64
| Measure | What it addresses | Operational consideration | What it does not replace |
|---|---|---|---|
| Move to a currently supported operating system | Restores access to normal security updates, subject to the selected system’s lifecycle. | Confirm compatibility with SCADA software and connected equipment; plan and test the change. | Segmentation, secure credentials, remote-access controls or physical safeguards. |
| Isolate and restrict a legacy SCADA host | Reduces the host’s network exposure when an immediate replacement is not feasible. | Permit only the communications required for operation and tightly limit access. | Security updates or a lasting replacement for unsupported software. |
| Harden RDP and other remote access | Reduces exposure from weak credentials and unnecessary remote connections. | Use MFA and unique, strong passwords; close unused RDP ports and audit connection logs. | OS support, network segmentation or safeguards that limit physical process changes. |
| Add independent process-safety limits | Can constrain unsafe commands through controls such as pump, reservoir, valve and pressure limits. | Design and validate limits for the actual treatment process. | Cybersecurity controls that prevent or detect unauthorized access. |
Should a water plant keep using TeamViewer or RDP?
Remote support is not automatically unsafe, but leaving a remote-control route broadly accessible creates avoidable exposure. RDP and third-party desktop-sharing tools should be enabled only when needed and protected with strong identity checks, narrow permissions and monitoring.
For RDP
- Close unused RDP ports and disable remote access that has no operational need.
- Require MFA and unique, strong passwords for every account permitted to connect.
- Restrict connections to approved users and sources, and review connection logs for unexpected access.
For TeamViewer or similar tools
- Disable unattended access; use manual start where remote support is required.
- Rotate complex passwords and require host confirmation before a remote user takes control.
- Maintain allow and block lists so only approved users or devices can connect.
Segment the SCADA network from ordinary business systems as a separate layer of defense. Train staff to recognize social engineering, and suspend anomalous accounts while investigating unusual activity.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Why are physical safeguards still necessary?
Cybersecurity controls aim to make unauthorized access harder and more detectable. Independent cyber-physical limits address a different failure mode: a valid-looking or compromised SCADA command that would push the process outside safe operating bounds. Pump, reservoir, valve and pressure controls can help constrain those outcomes when they are designed for the plant’s actual equipment and treatment process.
The 2021 incident shows why operators should not rely on a SCADA alarm as the only check on a dangerous change: staff noticed the altered setting before the alarm reacted. Independent process limits, trained operators and cybersecurity controls serve complementary roles.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

