In some cases, the attacks resulted in loss of remote monitoring capabilities, control, pressure loss, flooding, and a need to revert to manual operations. To make matters worse, we are unsure about the breadth of this attack. Water cannot be taken for granted and the risk vector across critical infrastructure is too large to ignore.
From Cyber Intrusion to Operational Disruption
Attacks like these are not new. Across the news, we have seen attacks against power plants, airports, and water facilities at an increasingly alarming rate. What makes these incidents unique, however, is that this activity targeted industrial control equipment responsible for monitoring and controlling physical water operations.
The FBI and Environmental Protection Agency reported that malicious actors were remotely accessing Programmable Logic Controllers (PLCs), changing IP addresses and passwords, and causing organizations to lose visibility or control of connected equipment. At least one affected organization also identified modified PLC project files.
The operational consequences included loss of water pressure and flooding, with the severity of the impact depending on what the compromised PLC controlled and whether the affected organization could transition to manual operations. These operational consequences quickly can turn to real life consequences as water can get contaminated, pipes can explode under pressure, and people can be killed.
This distinction is important in understanding the difference between IT and OT cybersecurity. In a traditional IT environment, a compromise may threaten data confidentiality, system availability, or business operations. Within OT, however, a compromised system can affect the physical process itself. A change to a controller can affect how equipment operates, remove an operator’s visibility of a process, and can prevent operators from managing equipment as expected. An OT cybersecurity incident can become a matter of public safety.
Nation-state threat actors, hacktivists, and other cybercriminals have shown interest in attacking critical infrastructure in the past. In 2021, the Colonial Pipeline ransomware attack shutdown a major US pipeline. In 2024, the US healthcare system was crippled for weeks due to a cyber-attack that disrupted pharmacies and medical billing. These incidents have all been against poorly secured industrial systems.
While the latest water incidents have not been publicly attributed to a specific threat at this time, the underlying problem remains the same. If OT infrastructure is exposed, an attacker will try to exploit it to create an operational problem.
Internet-Exposed OT Remains a Critical Risk
One of the clearest lessons from these incidents is the risk associated with directly accessible industrial equipment. The FBI and EPA found attackers targeting unpatched vulnerabilities in internet facing controllers. After gaining access, the hackers changed device configurations and credentials. Although those controllers were observed during the incidents, federal authorities have emphasized that the same security considerations apply across manufacturers and PLC platforms.
This is not a new cybersecurity principle. CISA, the EPA, and the FBI have previously identified reducing public internet exposure as one of the most important actions water organizations can take, alongside changing default passwords, maintaining accurate IT and OT asset inventories, conducting cybersecurity assessments, backing up systems, and exercising incident response and recovery plans.
The challenge is that external connectivity within OT environments is not always obvious. Remote pumping stations may communicate over cellular networks. Vendors and system integrators may require remote maintenance access. HMIs, engineering workstations, telemetry devices, remote terminal units, and PLCs may have been installed at different points in the lifecycle of a facility. Some connections may have existed for years, while others may have been introduced as temporary solutions that gradually became permanent. Without strong asset and connectivity management, organizations can lose sight of exactly how their OT environment is accessible from outside the facility.
This makes understanding the architecture essential. Organizations need visibility not only of the assets within their OT environment, but also of the pathways that could allow an external user to reach those assets. That includes vendor and third-party connectivity, which can create additional risk when similar hardware, configurations, or architectures are deployed across multiple customers. The FBI noted similarities in network configurations provided by third parties across several affected organizations, highlighting the potential for the same weakness to be repeated across multiple facilities.
How Water Organizations Can Reduce Their Exposure
The immediate response should start with understanding what is connected and why. OT asset inventories should include counts of PLCs, HMIs, engineering workstations, communications equipment, cellular connections, remote access platforms, and other technologies supporting operational processes.
Additionally, you should understand the protocols that are used to communicate across the network as well. Every connection to the internet, vendor connection, cellular modem, and remote access pathway should also have an operational purpose and a control owner. From here, access can be granted based on its criticality to the system and can significantly reduce the available attack surface by ensuring that only approved devices can access the network.
An assessment may identify a missing firewall rule, an exposed connection, or an outdated PLC. A mature OT security program goes further by determining what those weaknesses mean within the wider operational architecture. The objective is to establish whether they provide a credible pathway to process disruption and then prioritize remediation according to the potential impact on operations.
Preparation Is Key
Critical infrastructure organizations should assume that technology may become unavailable, inaccessible, or untrusted at any time. Is your organization able to continue operating safely when that inevitably happens?
Business continuity and disaster recovery plans and maintaining good backups both contribute to operational resilience. However, these capabilities only provide meaningful assurance when they are tested regularly. It is one thing for a procedure to state that operators can switch a process to manual control.
What we find most often is that an organization does not know how long that transition takes, whether the required personnel are available and aware of the current process, and how long manual operations can realistically be sustained. The same principle applies to incident response planning and execution.
An OT cyber exercise should evaluate what happens to the physical operation while that investigation is underway. Operators need to continue delivering critical services while engineering teams determine what systems have been compromised and who needs to be contacted. In critical infrastructure, successful incident response is about maintaining safe and reliable operations while containment, investigation, and recovery functions take place.
The Path Forward: Building Operational Resilience
The Midwest water attacks are not an isolated event. As technology continues to get more deeply embedded into our world, we must remember that technology is also opening paths between external networks and critical physical processes and creating new risks. Security must evolve alongside that connectivity.
Organizations need to understand what they operate, determine how those assets can be reached, and implement controls proportionate to that risk. Most importantly, organizations need to prepare for the possibility that preventative controls may eventually fail. As such, we must ensure that the compromise of a single component does not become a compromise of the entire operation. Understanding how a cyber event could affect the physical processes allows organizations to prioritize the controls that matter most and maintain safe operations even when technology cannot be trusted.
How Bridewell Can Help
These recent attacks provide an opportunity to validate assumptions made about the following areas before they are tested during a real event:
- Asset identification
- IT/OT segmentation
- Securing aging infrastructure
- Vendor access management
- Remote connectivity
- Your ability to continue operating through a cyber incident
Understanding your exposure before an attacker does can be the difference between a cybersecurity event and an operational crisis.