Water Systems Under Siege: Multistate PLC Attacks Expose a Dangerous Weakness in America’s Critical Infrastructure + Video

Listen to this Post

Featured Image

A Quiet Cyber Crisis Beneath the Surface

America’s water infrastructure is facing a cyber threat that is easy to underestimate precisely because the attacks are technically simple. Across multiple states, threat actors have reportedly targeted programmable logic controllers, or PLCs, that help operate water and wastewater facilities. These systems control physical processes that most people never think about until something goes wrong.

The emerging campaign is particularly alarming because it does not appear to require sophisticated malware or futuristic hacking techniques. In many cases, attackers are reportedly reaching industrial controllers that should never have been directly exposed to the public internet, changing credentials, modifying network settings, and disrupting operators’ ability to see or control their own equipment.

The incidents have spread across a growing list of states, including Minnesota, Georgia, Michigan, South Dakota, Alabama, and New Jersey. Federal agencies have warned that the activity is part of a broader increase in attacks against PLCs used by water and wastewater organizations.

The suspected connection to Iranian-linked threat actors adds another layer of concern. However, attribution remains unconfirmed, and responsible analysis requires separating what authorities have established from what security researchers suspect.

The deeper story is not simply about Iran, hacktivists, or a particular group. It is about the uncomfortable reality that thousands of critical infrastructure systems were built around assumptions from another era, when industrial equipment was expected to operate behind physical barriers rather than sit within an interconnected digital environment.

The Campaign Is Expanding Across Multiple States

Minnesota Becomes an Early Warning

Minnesota was among the first states to publicly acknowledge a significant wave of attacks, reporting that attackers had targeted operational technology systems associated with more than 30 water systems.

The attacks reportedly focused on PLCs rather than traditional corporate IT environments. That distinction matters because PLCs are directly involved in physical operations.

When an attacker interferes with an ordinary business computer, the immediate consequence might be stolen files or interrupted email. When an attacker interferes with an industrial controller, the consequences can potentially move from the digital world into the physical world.

CISA Raises the Alarm

Federal Authorities Warn of Increased PLC Targeting

The US Cybersecurity and Infrastructure Security Agency, or CISA, subsequently updated an advisory warning of a significant increase in cyber activity targeting PLCs in the Water and Wastewater Systems sector.

The agency highlighted tactics including changing PLC passwords to prevent legitimate operators from accessing equipment and modifying IP addresses in ways that could disconnect controllers from the systems used to monitor and manage them.

The warning was blunt: organizations operating critical infrastructure should remove publicly exposed PLCs and other operational technology from direct internet exposure as quickly as possible.

That recommendation sounds obvious.

Unfortunately, the fact that authorities need to repeat it demonstrates how difficult the problem has become.

The FBI Connects the Threat to Known PLC Targeting

Iranian Threat Actors Remain a Suspected Connection

The FBI also updated an earlier warning concerning Iranian threat actors targeting PLCs used in critical infrastructure.

The warning specifically referenced equipment manufactured by major industrial technology companies, including Rockwell Automation and its Allen-Bradley products, Schneider Electric, and Siemens, while noting that additional vendors could potentially be affected.

This does not mean every affected device is vulnerable simply because it comes from one of these manufacturers.

The important issue is how these devices are deployed, configured, exposed, maintained, and protected.

A secure industrial controller can become a serious security problem when someone places it directly on the internet, uses weak credentials, leaves unnecessary services enabled, or provides remote access without appropriate segmentation.

The Geography Is Getting Harder to Ignore

Minnesota Is Not an Isolated Incident

The campaign has reportedly touched communities and water organizations in several states.

Officials in Georgia, Michigan, and South Dakota have reported incidents that appear consistent with the wider PLC-targeting activity.

More recently, communities in Alabama and New Jersey have also disclosed attacks.

The geographical spread is important because it changes the interpretation of the incidents.

One compromised water facility might be dismissed as a local security failure. Repeated attacks against organizations across multiple states suggest that attackers are identifying a repeatable weakness and applying the same basic playbook against different targets.

The Most Important Question: Did the Water Stop?
So Far, There Is No Evidence of a Nationwide Water Supply Crisis

Despite the alarming headlines, there is an important distinction between cyber intrusion and catastrophic physical disruption.

Based on publicly reported information in the source material, there has been no broad disruption to the US water supply.

That does not make the attacks harmless.

Several incidents reportedly forced operators to lose visibility or control over PLCs, requiring staff to switch to manual procedures.

For water utilities, even temporary loss of automated control can create operational pressure.

The goal of an attacker does not always have to be destroying equipment.

Sometimes demonstrating that they can interfere with critical systems is enough to create fear.

Georgia Shows What the Risk Could Become

A Water Pressure Problem Raises the Stakes

One of the more serious reported incidents occurred in Georgia.

Cyber activity affecting Clayton County reportedly contributed to a reduction in water pressure and resulted in a boil-water advisory.

Even if such an incident does not produce permanent infrastructure damage, it demonstrates why cyberattacks against water systems cannot be treated as ordinary IT incidents.

A change made to a digital controller can eventually become a physical problem.

That is the central danger of operational technology security.

Why PLCs Are Such Attractive Targets

Industrial Controllers Were Built for Reliability, Not

PLCs have traditionally been designed around reliability, availability, and physical isolation.

They were not necessarily designed with the modern threat environment in mind.

Many older industrial environments were constructed around an assumption that unauthorized outsiders would never be able to reach the equipment.

The internet destroyed that assumption.

Today, remote maintenance, cloud monitoring, cellular connectivity, VPNs, satellite links, vendor support systems, and other technologies can create pathways into industrial environments.

Convenience has quietly expanded the attack surface.

Remote Maintenance Can Become a Hidden Door

Field Technicians Often Have Different Priorities

Industrial environments frequently depend on technicians and third-party integrators.

Their job is to keep pumps running, maintain equipment, repair systems, and prevent downtime.

Cybersecurity is not always their primary responsibility.

A technician might install a cellular modem because it makes troubleshooting dramatically easier.

A contractor might configure remote access because waiting hours to physically reach a facility is unacceptable during an emergency.

A port-forwarding rule might remain active long after the original maintenance job has finished.

None of these decisions necessarily begins with malicious intent.

But attackers do not care why an access path exists.

They care that it exists.

The Scale of

Thousands of Small Utilities Create Thousands of Security Challenges

The US water sector is extraordinarily fragmented.

There are roughly 170,000 drinking water and wastewater systems, according to the expert quoted in the original reporting.

Many are small and decentralized.

Some operate with limited budgets and small technical teams.

Others depend heavily on outside vendors for engineering, maintenance, and cybersecurity.

This creates a difficult contradiction.

The systems are critical.

The organizations operating them may not have the financial resources normally associated with critical infrastructure security.

Cybersecurity Is Competing With Physical Infrastructure

Water Utilities Have More Immediate Problems Than Hackers

A water utility has to maintain pumps, pipes, treatment systems, reservoirs, chemical processes, electrical equipment, vehicles, buildings, sensors, and countless other physical assets.

Every dollar spent on cybersecurity competes with another infrastructure requirement.

That is one reason the problem cannot simply be solved by telling utilities to “do better.”

The sector needs resources, standards, technical assistance, modernization programs, and realistic security requirements designed specifically for small operators.

The Iranian Connection Remains Unproven

Suspicion Is Not Attribution

The possibility of Iranian involvement has received significant attention.

One potential suspect is the pro-Iranian CyberAv3ngers group, which has previously targeted US water infrastructure and has been referenced in earlier CISA warnings.

Security researchers have also identified similarities between the recent PLC activity and previous campaigns associated with Iranian actors.

But similarity does not equal proof.

Federal authorities have not publicly and definitively attributed the latest multistate campaign to Iran, the Islamic Revolutionary Guard Corps, or CyberAv3ngers.

That distinction matters.

Cybersecurity investigations frequently involve incomplete evidence, infrastructure overlap, reused tools, similar tactics, and deliberate deception.

Attribution should therefore remain cautious until authorities release stronger evidence.

The Low Complexity Is Actually Part of the Story
Sophisticated Attackers Do Not Always Need Sophisticated Attacks

There is a dangerous misconception that a serious cyberattack must involve advanced malware, artificial intelligence, zero-day exploits, or highly complex intrusion chains.

Critical infrastructure attacks can sometimes be much simpler.

If a PLC is publicly reachable and protected by weak credentials, an attacker may not need an advanced exploit.

If remote access is improperly configured, the attacker may not need malware.

If network segmentation does not exist, an attacker may not need an elaborate lateral-movement strategy.

The simplest weakness can sometimes produce the biggest consequence.

The Psychological Dimension

“We Can Reach You” Can Be the Message

The apparent objectives of these attacks may extend beyond physical destruction.

Interfering with a water facility sends a powerful psychological message.

It tells operators that someone outside their organization can reach systems that are supposed to control essential services.

For communities, the emotional effect can be even greater.

People rarely think about cybersecurity when they turn on a faucet.

They assume water will be safe, clean, and available.

That trust makes water infrastructure an unusually powerful target for psychological operations.

Why Manual Operations Matter

Human Operators Become the Final Safety Barrier

When automated systems fail, trained personnel can often take control manually.

That redundancy is extremely valuable.

It means that compromising a PLC does not automatically mean compromising the entire water system.

But manual operation comes with limitations.

It can require more personnel.

It can slow response times.

It can increase the possibility of human error.

It can make operations more expensive.

And during a prolonged incident, fatigue becomes another security risk.

The human operator may ultimately become the last line of defense between a cyber intrusion and a physical incident.

Deep Analysis

The First Priority Is Finding Internet-Exposed OT

Identify Publicly Reachable Industrial Systems

Organizations should begin by determining whether PLCs, HMIs, engineering workstations, remote terminal units, or other OT components are reachable from the public internet.

A basic external exposure assessment can start with:

nmap -sV --open <authorized-public-ip>

This should only be performed against systems the organization owns or has explicit authorization to test.

The objective is not to attack the system.

The objective is to determine whether unnecessary services are visible from outside.

Search Firewall Logs for Unexpected Industrial Traffic

Monitor Unusual External Connections

Security teams can examine firewall and gateway logs for unexpected inbound connections involving OT networks.

A simplified Linux environment might use:

grep -Ei 'PLC|SCADA|Modbus|S7|DNP3|OT' /var/log/ 2>/dev/null

Real environments should use centralized logging and SIEM tooling rather than relying on a single local log file.

The important question is whether external systems are repeatedly attempting to communicate with industrial infrastructure.

Watch for Unauthorized Configuration Changes

Password Changes Can Be a Major Warning Sign

The reported attacks included changing PLC credentials.

Utilities should therefore maintain configuration baselines and alert when important controller settings change unexpectedly.

Administrators should track:

PLC authentication changes

IP address modifications

Firmware changes

Program downloads

Remote engineering sessions

New user accounts

Unexpected configuration writes

Changes to firewall rules

Changes to VPN access

A change-management system can make legitimate maintenance distinguishable from suspicious activity.

Segment IT and OT Networks

Separation Can Limit the Blast Radius

A water utility should avoid treating its operational technology environment like another office network.

A basic architecture should separate:

Internet

|

Firewall

|

IT Network

|

OT DMZ

|

Industrial Firewall

|

SCADA / HMI

|

PLC Network

|

Physical Equipment

The precise architecture depends on the facility.

The principle is universal.

A compromise of an employee laptop should not automatically provide a pathway to a pump controller.

Remove Direct Internet Exposure

Publicly Accessible PLCs Are an Emergency Condition

If a PLC does not need direct internet access, it should not have it.

Remote administration should ideally pass through controlled access mechanisms, including strong authentication, carefully restricted VPNs, privileged access controls, and monitoring.

A dangerous configuration can sometimes look deceptively simple:

Internet → PLC

A safer approach is closer to:

Internet

Secure Gateway

MFA

Controlled VPN

Jump Host

OT Firewall

PLC

The goal is to make unauthorized access difficult while preserving legitimate maintenance.

Strengthen Authentication

Default Credentials Must Disappear

Every PLC and associated management system should have unique credentials.

Where supported, multifactor authentication should protect administrative access.

For devices that cannot support MFA directly, compensating controls should protect the network path leading to them.

A password should never be treated as the entire security architecture.

Disable Unnecessary Services

Every Open Service Creates Another Opportunity

Security teams should review unnecessary protocols, ports, management interfaces, and remote access services.

Examples of industrial protocols include:

Modbus/TCP

EtherNet/IP

DNP3

S7

OPC

BACnet

The presence of a protocol is not automatically a vulnerability.

The danger arises when industrial services are unnecessarily exposed or inadequately controlled.

Maintain Offline Backups

Recovery Requires More Than Network Access

Utilities should maintain protected backups of PLC programs, HMI configurations, engineering project files, network configurations, and critical documentation.

A simple inventory might include:

PLC program backups

SCADA configurations

HMI images

Network diagrams

Firewall configurations

Vendor documentation

Firmware versions

Recovery procedures

Emergency contacts

Backups should be protected from attackers who might attempt to modify or delete them.

Test Manual Procedures

The Backup Plan Must Exist Outside the Computer

A utility should know what happens if operators suddenly lose access to automated controls.

Questions should include:

Who takes manual control?

How is equipment operated safely?

Who authorizes emergency changes?

How are water-quality risks monitored?

How are customers notified?

How are vendors contacted?

How is the incident escalated?

A recovery plan that exists only in a document nobody has practiced is not a reliable recovery plan.

Monitor Remote Access

Third-Party Connectivity Needs Special Attention

Vendor access can be extremely useful.

It can also become one of the most dangerous pathways into OT.

Utilities should know:

Which vendors have access.

Which systems they can reach.

When access is permitted.

How access is authenticated.

Whether sessions are logged.

Whether accounts expire.

Whether unused accounts are disabled.

Permanent vendor access should be treated as a major risk.

What Undercode Say:

1. The Real Vulnerability Is Exposure

The most worrying element of this campaign is not necessarily the sophistication of the attackers.

It is the exposure of systems that should have been difficult to reach.

2. Water Infrastructure Has a Unique Risk

Water systems combine digital controls with physical consequences.

A compromised email account is serious.

A compromised pump controller can become a public-safety issue.

3. Simple Attacks Can Become Strategic Attacks

Attackers do not need advanced malware when basic configuration weaknesses already exist.

The easiest path is often the most attractive path.

4. Internet Exposure Is an Organizational Problem

A publicly accessible PLC is rarely the result of one individual’s mistake.

It can involve vendors, contractors, engineering decisions, legacy infrastructure, and years of accumulated configuration changes.

5. Legacy Systems Are Difficult to Replace

Water infrastructure operates for decades.

Replacing every PLC, sensor, controller, and network architecture is financially unrealistic.

Security therefore has to coexist with legacy equipment.

6. Segmentation Should Become Standard

Critical controllers should not be sitting directly behind an internet connection.

Network segmentation should be treated as basic infrastructure hygiene.

7. Remote Access Needs Governance

Remote access is not inherently dangerous.

Uncontrolled remote access is.

Every remote pathway should have an owner, authentication mechanism, logging system, and expiration process.

8. Small Utilities Need Help

It is unreasonable to expect a small municipal utility with limited technical staff to independently solve nation-state-level cybersecurity challenges.

Federal and state assistance can make a meaningful difference.

9. Security Budgets Must Follow Risk

A water system does not need to spend money simply because cybersecurity vendors recommend another product.

It needs to spend money where it reduces the most meaningful operational risk.

10. Asset Inventory Comes First

Organizations cannot protect devices they do not know exist.

A complete inventory of PLCs, HMIs, SCADA servers, gateways, modems, VPNs, and vendor connections should be foundational.

11. Configuration Monitoring Is Critical

Attackers reportedly changed credentials and IP addresses.

Those changes should generate alerts.

12. Operators Need Visibility

Cybersecurity controls should not make legitimate operators blind to what their systems are doing.

Visibility is part of resilience.

13. Manual Control Still Matters

Human operators can prevent a cyber incident from becoming a physical disaster.

Manual procedures therefore deserve the same attention as digital defenses.

14. Attribution Should Remain Careful

Iran may be involved.

CyberAv3ngers may be involved.

But suspicion should not be presented as established fact.

15. Hacktivism Can Still Cause Serious Damage

A group does not need sophisticated espionage capabilities to disrupt public confidence.

Fear itself can be an objective.

16. Psychological Operations Are Increasingly Important

Attacks against visible public infrastructure can generate headlines far beyond the technical impact of the intrusion.

17. Water Is a Symbolic Target

People expect water infrastructure to be dependable.

Attacking it challenges that basic assumption.

  1. The Absence of Catastrophe Is Not Proof of Safety

A failed attempt today can reveal the pathway for a more damaging operation tomorrow.

19. Attackers Learn From Every Incident

Each intrusion can provide information about defensive practices, response times, network architecture, and operator behavior.

20. Defenders Learn Too

Every incident should produce stronger configurations, better monitoring, and better response procedures.

  1. OT Security Cannot Be Treated Like IT Security

The consequences are different.

Operational availability and physical safety must remain central to defensive decisions.

22. Availability Is Not Enough

A PLC that remains online but is controlled by an unauthorized person is not truly available in a security sense.

Integrity matters just as much.

23. Authentication Needs Modernization

Legacy credentials are particularly dangerous when systems become remotely accessible.

24. Vendor Ecosystems Need Scrutiny

Third-party maintenance creates legitimate access requirements.

Those requirements must be balanced against the possibility of abuse.

25. Cellular Connections Deserve Attention

Industrial systems increasingly rely on cellular connectivity.

A cellular modem can become another entry point if improperly secured.

26. Documentation Can Save Systems

When a crisis occurs, accurate network diagrams and recovery documentation can reduce confusion dramatically.

27. Incident Response Must Include Engineers

OT incidents cannot always be handled by a conventional IT security team alone.

Engineers understand how physical processes respond to digital changes.

28. Security Teams Need OT Expertise

Defenders need to understand both the network and the machinery behind it.

  1. Regulation Alone Will Not Solve the Problem

Rules can establish minimum expectations.

They cannot automatically modernize decades-old infrastructure.

30. Funding Is a Security Control

If utilities cannot afford secure architecture, the policy problem becomes a cybersecurity problem.

31. Public-Private Cooperation Is Essential

Manufacturers, utilities, federal agencies, researchers, and security companies need to share information rapidly.

32. CISA Warnings Need Operational Follow-Through

An advisory has limited value if organizations read it and do nothing.

33. Exposure Should Be Treated as Urgent

Publicly reachable critical infrastructure should receive immediate attention.

34. Detection Must Improve

Utilities should know when credentials, IP addresses, configurations, firmware, or control programs change.

35. Recovery Should Be Practiced

A theoretical recovery plan is weaker than a tested recovery process.

36. Resilience Is More Than Prevention

Eventually, some attacks will succeed.

The question is how quickly the organization can detect, contain, and recover.

37. The Attack Surface Is Expanding

Remote monitoring and connected infrastructure bring benefits, but every connection introduces potential risk.

  1. The Cheapest Fix May Be the Most Important

Removing unnecessary internet exposure can sometimes provide more security value than purchasing another expensive security platform.

39. The Warning Should Not Be Ignored

Today’s attacks may be disruptive rather than destructive.

That does not guarantee

  1. America’s Water Security Is Ultimately Everyone’s Security

Cybersecurity failures in water infrastructure do not remain inside an IT department.

They can affect operators, hospitals, businesses, households, and entire communities.

Prediction

(+1) Water Utilities Will Accelerate OT Modernization

The growing number of incidents is likely to push utilities toward stronger segmentation, better remote-access controls, improved monitoring, and more structured asset inventories.

(+1) PLC Exposure Will Receive Greater Government Attention

Federal and state agencies are likely to increase pressure on critical infrastructure operators to identify and remove publicly exposed industrial controllers.

(+1) OT Cybersecurity Spending Will Increase

Security budgets for water and wastewater infrastructure are likely to grow as governments recognize that cybersecurity is increasingly part of physical infrastructure protection.

(+1) Manual Resilience Will Become More Important

Utilities will increasingly invest in procedures that allow operators to maintain essential services when digital controls become unavailable.

(-1) Attackers May Escalate From Demonstration to Disruption

If relatively simple intrusions continue producing attention without major consequences for attackers, more aggressive actors may eventually attempt to cause greater operational disruption.

(-1) Smaller Utilities Will Remain the Weakest Link

Organizations with limited budgets, legacy equipment, and heavy dependence on third-party contractors may continue to face disproportionate cyber risk.

(+1) Visibility Will Become a Priority

Utilities are likely to deploy more OT monitoring systems capable of detecting unexpected PLC changes, unusual remote access, and abnormal network behavior.

✅ Multistate Water Systems Have Reported Cyber Incidents

The supplied article accurately describes a broader wave of reported attacks involving water and wastewater organizations in multiple US states. The incidents have centered heavily on PLCs and operational technology.

✅ CISA Has Warned About Increased PLC Targeting

The article correctly reflects federal warnings about threat actors targeting PLCs in the Water and Wastewater Systems sector. CISA has specifically urged critical infrastructure organizations to remove unnecessary public exposure.

✅ Iranian Actors Are a Suspected Connection

The possibility of Iranian involvement is credible based on previous campaigns and similarities in tactics. However, this should be described as a suspicion rather than definitive attribution.

❌ The Attacks Should Not Be Described as Proof That Iran Conducted the Campaign

No definitive public attribution is established in the supplied material. Treating suspected Iranian involvement as proven would go beyond the available evidence.

✅ Some Incidents Caused Operational Disruption

Operators reportedly experienced loss of control or visibility and were forced to use manual workarounds. The reported Georgia incident demonstrates that even relatively simple cyber interference can have consequences for physical services.

❌ There Is No Evidence Here of a Nationwide Water-Supply Collapse

The available reporting does not establish a broad nationwide disruption of drinking-water availability. The primary concern is the vulnerability and potential for escalation, not a demonstrated national water-system shutdown.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube