I’ve been watching this one unfold since Minnesota first reported it last week. More than 30 municipal water and wastewater systems targeted there on the 26th and 27th. Now the FBI and EPA say water utilities in at least seven states have reported incidents, and some of that activity degraded operations. Michigan has confirmed nine systems saw hostile activity. Georgia and South Dakota (Rapid City lift station) have also come forward. New Jersey is in the mix too. The rest haven’t all been named publicly yet.
The playbook is the same one we’ve been warning about for years: internet-facing PLCs. Mostly Rockwell/Allen-Bradley from what I’m seeing, with others getting touched as well. Actors log in, change the IP address, change the password, and lock the operators out. In some places that meant loss of pressure, flooding, boil-water notices, and a forced switch to manual operations. No confirmed contamination or public health impacts so far. The systems so far have kept delivering safe water. That part is good news.
Intelligence folks are pointing at Iranian-linked actors, I don’t care about attribution. I care about the attack, and how to beat my opponent. Given the current state of things with Iran, that tracks with previous OT targeting patterns. Official attribution is still cautious, which is fine. It doesn’t change the fact that these devices should never have been sitting on the open internet in the first place.
I’ve said it before and I’ll say it again: the water sector is full of small utilities with tiny budgets, aging equipment, and staff who are already stretched thin just keeping the pumps running. NERC CIP-style rules never applied here the way they do in electric. PLCs were never designed to face the public internet, yet there they sit with default or weak credentials. This isn’t sophisticated zero-day stuff. It’s opportunistic access against systems that were left exposed.
CISA’s advice is the correct one: pull those controllers offline or put them behind proper segmentation and access controls yesterday. If your HMI or PLC is reachable from the public internet, you are already behind. Manual operations are better than remote compromise.
Said differently if you have assets on Shodan, you are fucked and have been. DO YOUR JOB!
I know this space. I’ve sat through the hearings. I’ve watched operators scramble. The fact that most systems recovered quickly and water stayed safe is a credit to the people on the ground. The fact that it was this easy is a failure of priorities and basic hygiene.
Leave the critical systems alone. Secure them. The men who just want to keep the water flowing shouldn’t have to fight off remote password changes while the rest of us argue about who to blame.