>samit_hota
Back to security news

Security News · SN-2026-369

HIGHOPEN

Iranian Threat Actors Target Internet-Exposed PLCs Across US Water Systems

Affected: Water and Wastewater Systems (WWS) Sector · Exposed Industrial Control Systems

Samit Hota·
#news#data-breach#iranian

Water facilities across a dozen U.S. states are facing an escalating wave of cyberattacks targeting exposed Programmable Logic Controllers (PLCs). Suspected Iranian state-linked threat actors are behind the campaign, leveraging simple network scanning tools to discover operational technology (OT) devices left directly accessible over the public internet without adequate access controls.

Why Exposed PLCs Are Vulnerable

PLCs serve as the fundamental control units of industrial automation, managing critical physical operations such as pump regulation, water filtration, and chemical dosing. Historically, operational technology was designed under the assumption that systems would remain air-gapped from corporate networks and the public internet. Consequently, many legacy controllers and Human-Machine Interfaces (HMIs) lack basic security controls, such as encrypted communications or robust user authentication.

When utilities connect these controllers to cellular modems or broad internet links for remote management without secondary access controls, malicious actors can easily locate them using search engines like Shodan or Censys. Threat groups frequently exploit default factory credentials, unauthenticated management protocols, or known remote access vulnerabilities to gain control over the devices, alter logic settings, or push disruptive configurations.

Impact and Operational Risks

The immediate blast radius for targeted water and wastewater utilities centers on physical disruption and safety compliance. Unauthorized modifications to PLC control logic can cause pumps to fail, alter chemical treatment levels, or create pressure anomalies that risk damaging distribution infrastructure.

While many affected facilities maintain mechanical fail-safes and water quality testing protocols to prevent unsafe water from reaching consumers, remediating a compromised controller typically requires operators to fall back on manual operations. Re-establishing secure control requires taking affected PLCs offline, inspecting firmware integrity, resetting logic configurations, and isolating management interfaces.

Securing Exposed Control Systems

Mitigating attacks on water system attacks and exposed PLCs requires removing control infrastructure from the public internet immediately:

  • Audit Perimeters: Disconnect all PLCs, HMIs, and Remote Terminal Units (RTUs) from direct internet exposure.
  • Enforce Secure Remote Access: Require an encrypted Virtual Private Network (VPN) with multi-factor authentication (MFA) for any necessary remote administrative access to OT networks.
  • Harden Controller Credentials: Change all factory-default administrative passwords on OT endpoints and field devices.
  • Restrict Outbound Traffic: Implement firewall rules blocking arbitrary outbound connections from the OT network to prevent unauthorized remote management or command-and-control traffic.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call