Full Report
When Americans think about cyberattacks on critical infrastructure, they often picture pipelines, banks or the electric grid. But one of the most attractive targets for foreign adversaries flows through nearly every American home every day: our drinking water. Few people stop to consider the consequences if a community’s water or wastewater system were disrupted. Yet…
Analysis Summary
# Incident Report: Emerging Threats to U.S. Water and Wastewater Systems
## Executive Summary
The U.S. water and wastewater sector is increasingly targeted by nation-state actors and cybercriminals seeking to disrupt essential services. These attacks aim to undermine public confidence and probe vulnerabilities in critical infrastructure. While specific recent breaches are referenced as evidence of this growing trend, the overarching threat involves the potential for catastrophic disruption to drinking water safety and availability.
## Incident Details
- **Discovery Date:** Ongoing / September 08, 2026 (Report Date)
- **Incident Date:** Various/Ongoing
- **Affected Organization:** Multiple U.S. Water Utilities
- **Sector:** Water and Wastewater Systems (Critical Infrastructure)
- **Geography:** United States (National)
## Timeline of Events
### Initial Access
- **Date/Time:** Variable
- **Vector:** Phishing, exploitation of internet-facing Industrial Control Systems (ICS), and credential stuffing.
- **Details:** Attackers target poorly secured remote access points and outdated software in small to mid-sized utility providers.
### Lateral Movement
- Moving from IT business networks into Operational Technology (OT) environments to access Supervisory Control and Data Acquisition (SCADA) systems.
### Data Exfiltration/Impact
- **Impact:** Potential manipulation of chemical levels (e.g., chlorine), disruption of pumps, and unauthorized access to facility management software.
### Detection & Response
- **Detection:** Often discovered through manual monitoring of chemical levels or identification of unauthorized remote desktop sessions.
- **Response:** Federal advisories (CISA/EPA), isolation of compromised systems, and shifting to manual operations.
## Attack Methodology
- **Initial Access:** Exploitation of default passwords and lack of Multi-Factor Authentication (MFA).
- **Persistence:** Maintenance of access through backdoors in legacy software.
- **Privilege Escalation:** Exploiting administrative privileges on local workstations to access SCADA interfaces.
- **Defense Evasion:** Use of legitimate remote management tools (Living off the Land) to avoid detection.
- **Credential Access:** Harvesting credentials from unencrypted configuration files.
- **Discovery:** Scanning for internet-connected PLC (Programmable Logic Controller) devices via services like Shodan.
- **Lateral Movement:** Pivoting from enterprise mail servers to OT subnetworks.
- **Collection:** Gathering system telemetry and operator manuals.
- **Exfiltration:** N/A (Focus is on disruption rather than data theft).
- **Impact:** Intentional malfunction of physical water treatment processes.
## Impact Assessment
- **Financial:** Significant costs associated with emergency remediation and potential regulatory fines.
- **Data Breach:** Exposure of facility blueprints and internal network architecture.
- **Operational:** Disruption of water supply and wastewater processing, requiring manual intervention.
- **Reputational:** Severe loss of public trust in the safety of municipal drinking water.
## Indicators of Compromise
- **Network Indicators:** Connections to known malicious IPs associated with nation-state groups (e.g., [defanged] 192[.]168[.]x[.]x).
- **File Indicators:** Unauthorized presence of remote desktop software (e.g., AnyDesk, TeamViewer) on SCADA workstations.
- **Behavioral Indicators:** Sudden spikes in chemical dosing commands or login attempts outside of standard operator hours.
## Response Actions
- **Containment:** Disconnecting ICS/SCADA systems from the public internet.
- **Eradication:** Changing all default passwords and implementing MFA across all access points.
- **Recovery:** Restoring system configurations from verified offline backups.
## Lessons Learned
- **Visibility:** Many water utilities lack sufficient logging to detect unauthorized movement early.
- **Underfunding:** Small utilities often lack the cybersecurity budget of the energy or banking sectors, making them "soft targets."
- **IT/OT Convergence:** The air-gap between business networks and water treatment controls is often non-existent or poorly maintained.
## Recommendations
- **MFA Implementation:** Mandatory Multi-Factor Authentication for all remote access.
- **Asset Inventory:** Conduct comprehensive audits to identify all internet-facing controllers.
- **Redundancy:** Ensure manual override capabilities are tested and operators are trained to recognize cyber-induced anomalies.
- **Network Segmentation:** Physically or logically segment OT environments from the general business network.