Water Treatment, Cyber Security & Public Safety: When the Water Plant Gets Hacked, Your Filter Becomes the Last Line of Defence
By Sergio Santoianni | Velora Water Systems | velorawater.com/blog

After 20 years of water systems and a growing obsession with cryptography, I honestly never thought those two worlds would collide. Then a Russian-linked group claimed it could control chlorine dosing at a Quebec water plant… and suddenly the kitchen sink and quantum entropy were having the same conversation. I have spent the majority of this time designing, installing, commissioning, and servicing residential and light-commercial water systems across the GTA, York Region, and beyond. Most of that work starts with a simple question from a homeowner: “Is my tap water actually safe?”
The honest answer has always been layered. Municipal plants do important work. They clarify, disinfect, and push water through kilometres of pipe. Chlorination in particular is one of the great public-health wins of the last century. It crushed typhoid and cholera in cities. We should not pretend otherwise.
But “treated at the plant” has never meant “finished at your kitchen sink.” Hardness, chlorine taste, disinfection by-products, silicates, sediment from aging mains, and whatever leaches from household plumbing still show up at the tap. That is why whole-home carbon, softening, and reverse osmosis exist. They are the last controlled barrier between the distribution system and the people drinking the water.
A new layer just got added to that conversation.
The plant is no longer only a chemistry problem
In its 2025–2026 annual report, Canada’s Communications Security Establishment described a Russian-linked group, NoName, that breached a Quebec municipal water treatment plant in October 2025. The group claimed covert access to pumps, chlorine dosing, pressure settings, and monitoring alerts. CSE was notified through an international incident-response network after the attackers advertised the access. Partners contained it. The municipality was not named. No confirmed contamination was disclosed.
That last sentence is the one people want to hear. It is also the one that should not make anyone relax.
Chlorine dose is not a software setting with no physical consequence. Too little, and pathogens survive. Too much, and you get toxic residuals and a spike in disinfection by-products. Pressure swings burst mains or drop service. Pump manipulation floods one zone and starves another. Small and mid-size plants are often the soft target: internet-facing operator screens, vendor remote access, thin segmentation between office networks and process control, and almost no 24-hour security operations centre watching tank levels and residual analyzers.
A later incident at Saint-Noël, a village of a few hundred people in the Bas-Saint-Laurent, made the same point in video form. Operators said the plant dropped into safe mode and drinking water was not contaminated. Good. Relying on “the plant went into standby” is not a public-health strategy.
What this means in an Ontario kitchen
If you live in Vaughan, Toronto, Kingston, London, or Muskoka, your water still comes from a regulated plant that meets Ontario Drinking Water Quality Standards on a normal day. That has not changed.
What has changed is the threat model. Foreign actors are probing North American water systems the same way they probe energy and hospitals: not always to dump a reservoir tomorrow, but to prove they can sit on the controls. CSE’s own language is blunt. State-backed actors are moving past espionage toward disruption. Water is on that list because everyone drinks it.
From a filtration standpoint, that is an argument for defence in depth, the same principle we already use for chemistry.
At the plant: disinfection, clarification, corrosion control.
In the street: residual chlorine and pipe integrity.
At the home: sediment, carbon, softening, and RO as the last barrier you actually control.
A point-of-use or whole-home system will not stop a city-wide outage. It will reduce chlorine, chloramines, THMs, sediment, and a long list of trace contaminants that municipal treatment was never designed to polish to “premium drinking water.” If a plant has a bad day: chemical, mechanical, or cyber, the household barrier is still there.
That is not fear marketing. It is the same reason we put check valves on boilers and GFCI on bathrooms. The upstream system is good. It is not infallible.
What homeowners and building operators should actually do
Know your source. Read the latest municipal water quality report. Note hardness, sodium, THMs, lead at the tap (not just at the plant), and whether the utility uses chlorine or chloramines.
Test at the tap. Plant water and kitchen water are not the same sample. Plumbing age, dead legs, and softener settings change the picture.
Build the right last barrier. Carbon for chlorine and organics. Softening where hardness wrecks fixtures. RO where you want dissolved solids and a wide contaminant cut. UV where wells or storage introduce microbiological risk.
Maintain it. A bypassed or exhausted filter is not a barrier. Carbon and sediment have calendars. Resin has a salt and hardness math problem. Skip either and you are back to raw tap chemistry.
Do not confuse “smart” with “secure.” If a building’s water room has remote valve access, cloud telemetry, or vendor VPNs, treat that like industrial control, not a gadget. Default passwords on a softener head are annoying. Default passwords on a chlorine feed pump are a public-health issue.
Where cryptography fits and where Quantum eMotion comes in
No household filter replaces a locked-down treatment plant. And no encryption chip replaces air gaps, network segmentation, or an operator who notices that the residual analyzer just flatlined.
Encryption still matters on the parts of the plant that are connected: vendor tunnels, historians, firmware channels, and the links between operator screens and the controllers that drive pumps and chemical feed. Those channels are only as strong as the keys and the randomness that created them. Weak entropy makes predictable keys. Keys sitting unprotected in memory are the window a lot of real attacks actually use.
That is the problem Montreal-based Quantum eMotion (QeM / QNC) is built around:
eFlux-Q supplies high-quality quantum-generated entropy so keys are not born from a tired software random-number generator.
SecureKey is designed to protect cryptographic keys while they are in use, when memory-scraping attacks are most effective.
eShield-Q combines quantum entropy, in-use key protection, and runtime integrity so sensitive applications can keep a cryptographic foothold even if the host environment is no longer fully trusted.
Those are plant-side and infrastructure-side tools. They belong in the same conversation as segmentation and monitoring, not as a substitute for them. At Velora we still start with water chemistry, licensed plumbing, and a system that a homeowner can service. The point of mentioning QeM here is simple: if municipalities and utilities are going to keep connecting chlorine controls to networks, the cryptographic foundation under those networks cannot be an afterthought.
The through-line
Chlorination made city water drinkable. Filtration makes household water something you actually want to drink. Cybersecurity is now part of whether the first of those two jobs stays trustworthy.
When a group can reach chlorine setpoints from another continent, “the city treats it” is no longer a complete sentence. Treat the plant like critical infrastructure. Treat the home like the last barrier you own. And treat the keys that lock the plant’s digital doors with the same seriousness we already treat residual chlorine.
If you want a tap-side assessment (hardness, chlorine, silicates) and what a proper Velora Water System would remove in your area, that is still the work we do every week.
Read the CSE disclosure as reported here:https://nationalpost.com/news/politics/russian-group-hacked-quebec-water-treatment-plant-gained-access-to-control-pumps-and-chlorine-dosing-cse





Comments