Water utility PLC attacks: the control layer that was never designed to authenticate
What the July 2026 water utility PLC attacks reveal about internet-exposed control systems, default credentials, and the limits of exposure measurement data.
Tag archive
What the July 2026 water utility PLC attacks reveal about internet-exposed control systems, default credentials, and the limits of exposure measurement data.
The UK government confirmed that a cyber-attack blamed on hackers linked to Iran shut down a small-scale energy generator for four days last month, the first publicly acknowledged British power generation outage caused by an intrusion.
A new system for generating industrial controller code refuses to let the model declare success until the specification, the compiler and a live runtime all independently agree, exposing a wide gap between code that compiles and code that behaves.
Explore the essentials of ICS-SCADA, its components, challenges, and effective strategies for better operational efficiency.
Federal authorities, including the FBI and EPA, are investigating a wave of cyberattacks against water and wastewater facilities in at least seven U.S. states. The attacks, suspected to be linked to Iranian actors, target internet-exposed Rockwell Automation PLCs, causing operational disruptions like loss of water pressure and forcing utilities to switch to manual operations.
The Federal Communications Commission (FCC) has issued a final rule, effective September 29, 2026, requiring U.S. broadcasters to implement specific cybersecurity measures for the Emergency Alert System (EAS). The rule mandates patching, strong passwords, and firewalls to prevent hijacking and the broadcast of false alerts.
The FBI and CISA have issued an urgent joint advisory following a series of cyberattacks targeting the U.S. Water and Wastewater Systems (WWS) sector. Malicious actors are exploiting internet-exposed Rockwell Automation MicroLogix PLCs in at least seven states, leading to significant operational disruptions. Attackers have been observed locking out operators by changing passwords and altering IP addresses, causing loss of pressure, flooding, and forcing utilities to issue boil water notices. The agencies urge all critical infrastructure operators to immediately remove OT assets from the public internet, implement network segmentation, and enforce strong access controls. The coordinated nature of the attacks across more than 30 systems suggests a concerted effort exploiting a common vulnerability or service provider.
A widespread, coordinated cyberattack targeted the operational technology (OT) of over 30 community water systems across Minnesota, forcing some facilities into manual mode and one offline. The incident, which occurred on July 26-27, is being investigated by state and federal agencies, with security researchers noting similarities to the Iranian-affiliated threat group CyberAv3ngers. The attacks highlight the vulnerability of critical infrastructure with internet-exposed control systems.
Cybersecurity agencies from the Five Eyes nations (U.S., U.K., Australia, Canada, New Zealand) have jointly released the "CI Fortify" guide. The document provides critical infrastructure operators with practical advice on how to isolate their most vital Operational Technology (OT) systems from IT and other networks. The goal is to ensure that essential services can be maintained even during a major cyberattack by enabling isolated, resilient operations.
A new report from SonicWall finds the manufacturing sector is at a 'breaking point' due to increasingly targeted and precise cyberattacks. While the overall volume of attacks has decreased, threats exploiting IT/OT convergence, legacy IoT devices, and SCADA systems are growing in sophistication and impact. A single five-year-old vulnerability in Hikvision cameras (CVE-2021-36260) was responsible for 43 million attack attempts in H1 2026, highlighting the risk of unpatched legacy systems on the factory floor.
Dassault Systèmes has patched a critical "Deserialization of Untrusted Data" vulnerability in its 3DEXPERIENCE platform. The flaw, affecting the Station Launcher App in releases R2023x through R2026x, could allow a remote, unauthenticated attacker to achieve remote code execution. Given the platform's deep integration into engineering and manufacturing, a compromise could lead to intellectual property theft or production disruption. Users are urged to apply the patches immediately.
CISA and international partners from the UK, Australia, and Canada have released new guidance, "CI Fortify – Advice for Isolating Vital Systems." It urges critical infrastructure (CI) operators to develop and practice plans for physically isolating operational technology (OT) from enterprise IT networks during a cyber crisis. The framework emphasizes identifying vital systems, mapping dependencies, and using physical separation or strong cryptography to protect essential services like water and energy from cyberattacks.