Overview
Cyberattacks targeting municipal water and wastewater facilities have expanded significantly, now affecting critical infrastructure across at least a dozen states. The campaign relies on widespread scanning to identify internet-exposed PLCs (Programmable Logic Controllers) that lack basic network segmentation or authentication controls. Iranian state-sponsored groups are heavily suspected in this campaign, continuing a established pattern of low-sophistication, high-visibility operations against vulnerable operational technology (OT) environments.
Attack Vector and Operational Impact
Programmable Logic Controllers serve as the primary operational backbone in industrial automation, controlling critical mechanics such as pump operations, valve actuation, and chemical dosing in water treatment plants. When these control units are connected directly to the public internet—frequently deployed this way for remote operational convenience—they become trivial targets for automated scanning platforms and opportunistic threat actors.
The primary vulnerability class here is architectural exposure and weak access control rather than a sophisticated software exploit. Many field-deployed PLCs utilize unauthenticated management protocols, web interfaces secured only by factory-default passwords, or cleartext communications.
Once an attacker discovers an exposed PLC, they can interact directly with the control logic. Depending on the device capabilities, threat actors can force system shutdowns, alter operational thresholds, or tamper with Human-Machine Interface (HMI) displays. For the small-to-medium utility providers typically affected, the immediate blast radius involves losing remote telemetry, forcing facilities into manual override modes, and straining local operations, even when secondary mechanical safeguards prevent physical safety incidents.
Suspected Threat Actor Mechanics
Iranian-aligned threat actors, including groups affiliated with the Islamic Revolutionary Guard Corps (IRGC), frequently employ low-barrier attack vectors against Western infrastructure targets. Rather than deploying custom malware or burning zero-day exploits, these actors scan public IP ranges using internet intelligence tools to locate exposed industrial hardware. Once located, they use basic credential abuse or known device defaults to tamper with device configurations, deface control screens, or disrupt baseline services to achieve maximum political impact for minimal effort.
Defensive Actions
Defending water system PLCs against this campaign requires immediately removing OT control interfaces from direct public exposure. Utility operators must audit their external IP space to ensure no PLCs, HMIs, or Remote Terminal Units (RTUs) are directly reachable over the internet; any required remote access must be routed through a secure firewall and an encrypted VPN enforced with multi-factor authentication, paired with immediate changes to all default vendor passwords.
Related content
Iranian Threat Actors Target Internet-Exposed PLCs Across US Water Systems
Security NewsNew York Allocates $9M for Water Sector Security Following Multi-State OT Attacks
Security NewsCISA Urges Water Sector to Secure Exposed PLCs Following Minnesota Cyberattacks
Security NewsCISA Warns of Surge in Water Utility Cyberattacks as Minnesota Incidents Probed
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call