Skip to content

Details

In late July 2026, attackers reached into water and wastewater utilities in at least 12 US states. They exploited internet-exposed programmable logic controllers (PLCs), including Allen-Bradley MicroLogix 1100/1400, Schneider Modicon M340, and Siemens S7-1200 units. The attackers changed IP addresses and passwords to lock operators out of monitoring and control. In some cases they altered ladder logic in PLC project files. Utilities reported pressure loss and localized flooding, and operators had to fall back to manual operations. On July 30 the FBI and EPA issued a joint alert, and an Iran-linked group claimed responsibility.
The campaign follows a pattern that is years in the making. In 2023, CyberAv3ngers defaced Unitronics controllers at the Municipal Water Authority of Aliquippa. In 2024, American Water, the largest regulated U.S. water utility, was hit by a cyberattack, and Arkansas City switched to manual operations after an incident. In 2025, Poland reported ICS intrusions at five water treatment plants. The attack surface hasn't changed much in that time. It is still exposed PLCs and HMIs, default or shared credentials, integrator-managed remote access, and small utilities with few security staff.
The attackers and vulnerabilities in the core OT control system and SCADA technologies are not the only pieces of the puzzle that has created this perfect storm. The way that Water Utility OT systems have been designed, constructed, built, commissioned, and managed without cybersecurity oversight or involvement over the last several decades presents another unique problem in this critical infrastructure sector. System Integrators and Engineering firms who have been at the core of these processes are not trained and are not generally aware of the cybersecurity requirements that should have been incorporated into these systems, and the recent advisory from CISA reinforce this part of the problem:
FBI, CISA Warn of Third-Party ICS Integrator Risks:
https://securitytoday.com/articles/2026/09/28/fbi-cisa-warn-of-third-party-ics-integrator-risks.aspx
Lastly, we will wrap the session with recent cybersecurity regulations in Water-adjacent sectors that hint that this may be brought into the Water Utility sector in the near future
This session looks at the following geo-political, technical, and sector-specific issues and ends with a case study for a practical 3-step process that has been proven to solve this issue with over a dozen successful implementations in the water/waste water industry:
1. Geo-political and Financial Gain motivations for why the US Water Utility Industry is being targeted
2. Technical vulnerabilities that have allowed the attacks to work: How attackers find and take over exposed controllers and what the attacks do at the logic and network layers
3. Unique challenges that have arisen over decades of not having cybersecurity-in-the-loop as Water Utility OT Systems are designed, constructed, built, commissioned, and managed (Systems Integrators and Engineering Firms lacking core cybersecurity knowledge and awareness
4. What the sector needs moving forward > How do we fix this?
⁃ Which defensive measures work: removing direct internet exposure, segmenting control networks behind secure gateways, strict access control lists, locking PLCs against unauthorized logic changes with key switches, verifying project file integrity, monitoring for configuration changes, and keeping manual operation ready
⁃ Review of a case study for how these challenges are being resolved with a practical and proven 3-step process >> Assess, Remediate, and Monitor/Manage
5. How the federal response and the push for water-sector security standards may shape utility obligations in the months ahead.

CLICK HERE TO REGISTER FOR THE EVENT

https://events.zoom.us/ev/ApKX1nFSLqCRXnhywmb3cc6AYYdqth4h3zEVp4p_Fx--qMYpThB5~AnlUbVQxeBjTcH4oWOzHRlfhrvI4POitE6vq-frJoCfAWVK7cqHeC7PrGeht702WNXpQ2V6Hz4hVUv3Mxre2CjLmsA

---------------------------------------------------------
Becoming a paid member is quick and easy (and helps us keep offering free educational opportunities!). Please join now! https://www.cs2ai.org/plans-pricing

All past seminars and symposiums are available to paid CS2AI.ORG members. Check out the Resources area of our website in the Members Portal https://www.cs2ai.org/

Certificates for Professional Development/Continuing Education Units (PDUs/CEUs) are available for all registered individuals who attend at least one hour of the event. https://www.cs2ai.org/get-involved

*Please note that (CS)²AI Online™ events are provided free of charge as educational career development content through the support of our paid members and the generous contributions of our corporate Strategic Alliance Partners. Contact information used in registering for our directly supported seminars may be shared with sponsors funding those specific events. Unless noted on our Zoom Event registration page, all events are open for direct funding support.

© Control System Cyber Security Association International 2026

Related topics

Cybersecurity
Network Security
Industrial Networking
Industrial Internet of Things (IIOT)
SCADA and Industrial Controls Security

Sponsors

KPMG

KPMG

Financial Support

Fortinet

Fortinet

Strategic Alliance Partner

Level Zero Conference

Level Zero Conference

Strategic Alliance Partner

CambiOS Academy

CambiOS Academy

Strategic Alliance Partner

You may also like