Nation-state actors have been targeting water and energy infrastructure in the United States and other countries, exploiting vulnerabilities in industrial programmable logic controllers (PLCs) to disrupt operations and cause financial losses. The FBI and Cybersecurity and Infrastructure Security Agency (CISA) have warned of Iran-linked hackers targeting devices at U.S. critical infrastructure sites, including water, energy, and municipal locations.

Background and Context

The recent surge in nation-state cyber activity targeting water systems is a growing concern for governments and industries worldwide. According to the DomainTools Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026, water and wastewater systems have become favored gray-zone targets due to their vulnerability and strategic value. The report highlights that chronic underinvestment and weak baseline operational technology (OT) security make many of these critical systems easy to compromise.

The same report notes that recent nation-state cyber activity targeting water systems includes Iranian IRGC-linked targeting of exposed programmable logic controllers (PLCs), Russian and pro-Russian access to municipal water-control environments, and PRC-linked pre-positioning in U.S. critical infrastructure, including water and wastewater systems. The U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation.

Why it Matters to the Industry

The targeting of water systems by nation-state actors has significant implications for industries that rely on similar infrastructure. The use of PLCs in various industrial settings makes them vulnerable to exploitation, as seen in the recent attacks. This highlights the need for robust security measures and regular updates to ensure the integrity of these systems.

Furthermore, the fact that Iran-linked hackers have targeted devices at U.S. critical infrastructure sites, including water, energy, and municipal locations, raises concerns about the potential for similar attacks on other industries. The use of authentication bypass vulnerabilities in Rockwell Automation's Logix controllers is a prime example of how nation-state actors can exploit weaknesses to disrupt operations.

What Comes Next

The FBI and CISA have issued joint advisories warning of the potential risks and urging security teams to take action. The agencies recommend enabling multifactor authentication, removing devices from the public internet, checking logs for suspicious activity, and placing physical-mode switches on Rockwell devices to the "run" position.

Industry leaders must take heed of these warnings and prioritize the security of their systems. Regular updates, robust security measures, and vigilant monitoring are essential to prevent similar attacks in the future. The targeting of water systems by nation-state actors serves as a stark reminder of the importance of cybersecurity in protecting critical infrastructure.

Key Facts

  • The FBI and CISA have warned of Iran-linked hackers targeting devices at U.S. critical infrastructure sites, including water, energy, and municipal locations.
  • Nation-state actors have exploited vulnerabilities in industrial programmable logic controllers (PLCs) to disrupt operations and cause financial losses.
  • The use of authentication bypass vulnerabilities in Rockwell Automation's Logix controllers is a prime example of how nation-state actors can exploit weaknesses to disrupt operations.
  • U.S. federal agencies, including CISA, FBI, NSA, and EPA, have warned that many utilities remain exposed through internet-facing human-machine interfaces (HMIs) and PLCs, weak credentials, shared accounts, legacy devices, limited monitoring, and poor IT/OT segmentation.
  • The targeting of water systems by nation-state actors has significant implications for industries that rely on similar infrastructure.