Cookie Consent by Free Privacy Policy Generator

Water utility attacks spread across multiple US states, Iran suspected

Dark Reading reports that cyber attacks targeting water systems have widened across a dozen US states, with attackers exploiting internet-exposed programmable logic controllers (PLCs) used in water treatment and distribution infrastructure. The attacks are suspected to be linked to Iranian threat actors, though attribution remains under investigation. The incidents follow a pattern of targeting poorly secured industrial control systems that are directly accessible from the internet, often with default credentials or outdated firmware. The attacks have raised concerns about the vulnerability of critical infrastructure systems that were not designed with modern cybersecurity threats in mind.

Why this matters for UK organisations

While these attacks are occurring in the United States, the operational lessons are directly relevant to UK organisations managing critical infrastructure, utilities, and industrial environments. Many water companies, energy providers, manufacturing facilities, and building management systems in the UK use similar industrial control systems and SCADA environments, often with legacy equipment that was installed before cybersecurity became a design priority. Internet-exposed PLCs, weak authentication, and a lack of network segmentation between operational technology and corporate IT networks are common vulnerabilities. The widening pattern of attacks suggests that threat actors are systematically scanning for and exploiting these weaknesses, and UK critical infrastructure operators should assume they are being targeted in the same way. The operational impact of these attacks can range from disruption of water treatment processes to loss of visibility and control over critical infrastructure, with potential public health and safety implications. The fact that attackers are targeting multiple states suggests a coordinated campaign rather than isolated incidents, which increases the urgency for UK organisations to review their own OT security posture.

What to review

Organisations managing operational technology, industrial control systems, or critical infrastructure should review whether OT environments are segmented from corporate IT networks, whether internet-facing industrial systems are identified and secured, and whether remote access to these systems is properly controlled and monitored. Consider whether default credentials have been changed across all PLCs, SCADA systems, and industrial devices, whether firmware is up to date, and whether there is visibility into who is accessing these systems and from where. Review whether OT environments have appropriate monitoring and alerting in place to detect unauthorised access, configuration changes, or unusual activity. For organisations that rely on third-party vendors or managed service providers to support OT environments, consider whether those vendors have secure remote access controls and whether their access is logged and reviewed. This is also a prompt to review whether incident response plans cover OT environments and whether there is clarity on who makes decisions during an operational technology incident, particularly if public safety or critical services are at risk.

Source: Dark Reading

News and blog posts
The Gunra ransomware gang, operating as a ransomware-as-a-service model, has...
Today's brief highlights the practical side of operational technology security,...
The NCSC has published new guidance specifically for the water sector, adding a...
Microsoft has released its August 2026 Patch Tuesday updates, addressing 421...