>samit_hota
Back to security news
SN-2026-291HighOpen

New York Allocates $9M for Water Sector Security Following Multi-State OT Attacks

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
US Water and Wastewater Infrastructure, Municipal OT Networks
#news#data-breach#new

Following a wave of cyber incidents targeting industrial control systems at municipal water utilities across the United States, New York State is awarding over $9 million to help 153 local drinking water and wastewater providers harden their infrastructure. Announced by Governor Kathy Hochul, the funding is delivered through the state’s Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements (SECURE) grant program.

The state assistance comes as critical infrastructure operators face aggressive scanning and exploitation targeting operational technology (OT) connected directly to the public internet. Under the SECURE program, individual utilities can receive up to $50,000 for technical cybersecurity assessments and up to $100,000 to implement remediation measures, alongside technical support from the New York State Environmental Facilities Corporation (EFC).

The Multi-State Attack Campaign

The grant deployment follows a coordinated cyber campaign that impacted water and wastewater operations across at least seven states. On July 26 and July 27, malicious activity surged across Minnesota, targeting more than 30 community water systems.

While manual override procedures allowed most affected facilities to maintain continuous water service and safety standards, several municipalities experienced direct disruptions to their automated control functions:

  • Braham, Minnesota: Attackers successfully shut down operating controls, forcing the municipality to temporarily take its water treatment plant and supply well offline to regain manual operational control.
  • Rapid City, South Dakota: Municipal officials confirmed an incident targeting a local wastewater lift station.
  • Additional States: Confirmed malicious targeting also hit facilities in Michigan and Georgia, among others.

While federal investigators have not issued a formal attribution, the operational profile matches known tactics of Iran-linked threat groups. Historically, groups such as CyberAv3ngers have systematically targeted sector-specific hardware—notably exposed Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs)—to deface control displays, disrupt municipal pump operations, and post political messaging.

Why Water Sector OT Is Vulnerable

The fundamental issue in most water utility attacks is not a zero-day exploit, but direct internet exposure paired with weak authentication. Small-to-medium municipal water systems frequently operate on tight budgets with limited dedicated IT or security staff. To allow remote monitoring by system operators or third-party contractors, facility management often connects PLCs, remote terminal units (RTUs), and supervisory control and data acquisition (SCADA) HMIs directly to public IP addresses.

Attackers routinely locate these assets using specialized search engines like Shodan or Censys. Once identified, adversaries gain administrative access through several recurring security flaws:

  1. Default Credentials: Many industrial controllers ship with factory-set passwords (e.g., admin/admin or manufacturer-specific codes) that are never changed upon installation.
  2. Unauthenticated Protocols: Legacy industrial protocols (such as Modbus TCP, EtherNet/IP, or unencrypted VNC feeds) lack native authentication mechanisms, allowing anyone who reaches the open port to send start/stop commands directly to physical machinery.
  3. Unpatched Management Interfaces: Web management portals integrated into cellular routers or PLCs frequently contain known, unpatched web vulnerabilities that allow remote code execution or bypass controls.

Blast Radius and Operational Impact

Because physical water distribution relies on automated feedback loops—where sensors tell PLCs when to start wells, open valves, or inject water treatment chemicals—tampering with these controllers breaks the automated chain.

The blast radius in these attacks typically manifests as a loss of control or loss of view for plant operators. If an attacker forces a PLC to shut down a lift station pump or alter chemical dosing parameters, safety features or physical pressure alarms usually trip. This forces operators to fall back to manual hand-controls.

While manual operations prevent public health catastrophes like water contamination, they place an immense burden on rural or small municipal staff, who must run facilities around the clock manually until control systems are wiped, isolated, and reprogrammed.

New York’s funding is designed to enforce baseline security controls established by the state in March. Those regulations mandate that utilities assign a designated cybersecurity lead, conduct operator security awareness training, establish formal incident reporting procedures, and implement risk-based safeguards around critical operational networks.

For water and wastewater operators nationwide, the Cybersecurity and Infrastructure Security Agency (CISA) strongly advises taking immediate steps to secure operational technology networks:

  • Eliminate Direct Internet Exposure: Place all PLCs, HMIs, and OT devices behind physical firewalls. Never expose port-mapped controller interfaces directly to public IP addresses.
  • Secure Remote Access: Mandate multifactor authentication (MFA) and route all remote operator connections through secure VPN gateways or zero-trust network access (ZTNA) solutions rather than direct VNC or web connections.
  • Harden Default Configurations: Change all default vendor passwords on industrial equipment, cellular modems, and routers immediately upon deployment.
  • Implement Network Segmentation: Strictly separate the administrative IT network from the operational OT network to prevent lateral movement if enterprise workstations are compromised. Restrict management connections to explicit, trusted IP allowlists.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call