Seven States, One Weak Spot: What the FBI/EPA PLC Warning Means for Water Utilities

Seven States, One Weak Spot: What the FBI/EPA PLC Warning Means for Water Utilities

On July 30, just a week after CISA issued advisory AA26-097A, the FBI and EPA issued a joint Public Service Announcement confirming what the water and wastewater sector has been bracing for since the Cal Water incident in June: malicious cyber actors, possibly Iranian-affiliated, are now reaching into the operational layer of U.S. water systems, not just the IT systems around it.

Since July 27, water and wastewater utilities in at least seven states have reported incidents to the FBI. The target is specific: PLCs exposed directly to the internet. The attack method is almost primitive: log in, change the IP address, change the password, then lock the operator out of their own device. Some victims have reported loss of pressure and flooding. The FBI notes pressure loss can allow untreated groundwater to seep into distribution pipes, a real public health pathway, not just an operational inconvenience.

The latest incidents are still under investigation, but they’re pointing to a sustained and possibly escalating attack across the U.S. water and wastewater sector. Here’s what we can glean from several attacks over the past few years — and what utility operators can do now at little to no cost to improve their resilience.

Exploiting Near-identical Configurations with Little Effort

In June, Iranian-linked Handala/VOID MANTICORE breached California Water Service, but the attack stopped at the billing environment. It was reconnaissance and data theft at the IT level, framed as a political warning. The OT layer, by Cal Water's own account, was untouched.

Check every device for default or reused credentials, because a public-facing PLC with factory-default credentials is close to guaranteed to be found.

What the FBI is describing now goes further. Actors are reaching PLCs directly and altering their configuration — the same class of access CyberAv3ngers used against the Municipal Water Authority of Aliquippa in 2023 but spread across seven states in a matter of days rather than a single site. That breadth, combined with reports of similar network setups across multiple victims, points to something else: third-party integrators deploying near-identical configurations across many utility customers, so that one working technique against one operator’s setup works against the next.

Water utilities tend to run leaner security programs than other utility sectors, lean more heavily on third-party integrators, and, often for cost or infrastructure reasons, end up with control devices reachable from the public internet more frequently than other critical infrastructure operators would tolerate. That's the condition this campaign is exploiting.

Low Sophistication, High Coordination

It's tempting to read "changed an IP address and a password" as unsophisticated. Reaching a publicly exposed PLC with default or weak credentials doesn't require an exploit, a vulnerability, or any real skill. It requires tools and time, both of which are cheap.

What's changed is coordination. CISA and other federal agencies have tracked Iranian-linked activity against exposed PLCs since April. This event tracks closely with that earlier tradecraft — though no formal attribution has been made, and the pattern could equally reflect an escalation from a group like Sandworm, which has a documented history of targeting water systems. The organized, multi-state nature of this campaign marks a shift from opportunistic, scattershot targeting to something closer to a coordinated operation. The gloves are off in a way they weren't before, largely because previous restraint from adversaries has likely had more to do with fear of consequence than lack of opportunity.

The Physical Slack in Water Systems Buys Time, It Doesn't Buy Safety

Despite their lack of resources, water utilities have a structural advantage that other critical infrastructure sectors don't: most systems are gravity-fed, and the effects of losing a pump or well typically take hours or days to become a health or reliability problem. That window is real, and it's why quickly switching a plant to manual control remains one of the most effective incident responses available.

But that slack is a buffer for response, not a reason for confidence. It gives operators time to catch and correct a problem before it reaches the tap. An attacker who has locked an operator out of monitoring and control has already removed the visibility that buffer depends on. The FBI's own reporting of pressure loss and flooding across current victims shows the buffer is already being tested.

How Water Utilities Can Increase Resilience Now

The FBI/EPA PSA's recommendations line up closely with what Nozomi Networks has been telling water sector customers since the Aliquippa incident: If a device doesn’t need an internet connection for day-to-day functioning, disconnect it now. Most PLCs only need remote connectivity for support and maintenance windows; that's a need you can suspend while this campaign is active. Turn off the physical or software key switch that enables remote programming, so a remote session can't push new logic even if credentials are compromised. And check every device for default or reused credentials, because a public-facing PLC with factory-default credentials is close to guaranteed to be found.

Aside from the immediate response, here are several other important steps to take, in priority order:

1. Find your internet-facing OT before someone else does.

Run your external IP ranges through Shodan or an equivalent tool. For water utilities specifically: Modbus TCP (502) and DNP3 (20000) are common exposure points where SCADA telemetry rides cellular or internet backhaul to remote pump and lift stations. EtherNet/IP (44818) matters wherever Rockwell/Allen-Bradley gear is deployed — which is most of the sector. Web-based HMIs on 80/443 are the fastest-growing exposure class industry-wide. Anything resolving externally that doesn't need to do so should be moved behind a DMZ, MFA and IP allowlisting — or disconnected outright.

2. Rotate every credential you haven't rotated recently, on PLCs, HMIs, modems and any remote-access infrastructure.

CISA's December 2024 advisory on the Aliquippa incident named unchanged default credentials as the primary enabler of that attack. The pattern hasn't changed.

3. Lock devices into run mode as standard operating posture.

Don’t reserve run mode for during active incidents alone. Do treat program/remote mode as a deliberate, logged, temporary state for updates only, during which you review and validate project files before switching back to run, since that switch locks in whatever is currently loaded.

4. Segment OT from IT, and from third-party integrator access specifically.

The FBI noted that similarities in network setups provided by integrators may be letting one technique succeed repeatedly across victims. If an integrator manages remote access across multiple sites with a shared architecture, that architecture is now a shared risk. A deny-by-default firewall policy between IT and OT, and unique credentials and access paths per site, blunts that multiplier effect directly.

5. Get visibility into OT network communications, not just the perimeter.

Baselining normal network traffic and asset behavior so you can detect threats and anomalies is at the core of cyber resilience. For water utilities, it involves passive monitoring of Modbus, DNP3, and EtherNet/IP traffic that baselines what a SCADA master normally polls and flags sessions or function codes outside that baseline. This is the layer that catches an intrusion during the reconnaissance and access phase, before it escalates to the kind of ladder logic tampering the FBI is now reporting.

6. Practice manual operations on a real schedule, not just as a paper plan.

According to the FBI's PSA, the ability to revert to manual control quickly is the single most effective mitigation once a PLC is compromised. Still, it only works if it's been tested recently enough that operators are confident doing it under pressure.

7. Report what you see.

The FBI is explicitly asking for PLC model numbers, serials and IPs, plus any unusual IPs observed on connected networks. Feeding that back to the FBI, IC3, CISA and sector-specific channels like WaterISAC is what turns one utility incident into an early warning for the next one in the campaign.

Expect More Attacks on Water Utilities. And Be Prepared.

Nothing in the FBI’s PSA suggests the campaign is finished. Seven states in four days is a pace, not a conclusion. The utilities that get ahead of this are the ones that treat "internet-facing PLC" as an open door to be closed today, not a finding for next quarter's risk assessment.

Nozomi Networks provides passive OT asset discovery and continuous anomaly detection purpose-built for critical infrastructure environments, along with OT/IoT threat intelligence tracking the TTPs associated with this and related campaigns targeting the water sector. If you want help knowing what’s on your network and understanding your exposure, request a demo or reach out to your Nozomi Networks contact directly.

No items found.
No items found.