Skip to content
    August 7, 2026

    Water Infrastructure Cyberattacks Expose Operational Technology Vulnerabilities

    The past several years have shown a clear evolution in adversarial tradecraft targeting US Water and Wastewater Systems (WWS). What began as reconnaissance-driven intrusions against isolated assets has escalated into coordinated, multi state campaigns aimed at manipulating PLC logic, disrupting automation, and degrading operator control. The July 2026 attacks underscored a critical fact: adversaries now possess the capability—and intent—to directly interfere with physical water operations through exposed operational technology (OT) interfaces.

    This analysis breaks down the attack vectors observed across recent incidents and explains how REMUS™ provides a defensible architecture for asset discovery, protocol inspection, and logic integrity validation at scale.

    Related: AI-Driven Cyber Risk and the Future of Operational Technology Security

    remus-graphic-1-escalation

    Historical Attack Patterns & Technical Indicators

    Bowman Avenue Dam (2013)

    Attackers gained SCADA access through an unsegmented cellular modem connected to a field RTU. The intrusion demonstrated an early but important lesson: standalone cellular gateways deployed for convenience create routable OT/IP pathways completely outside supervisory visibility. Had the sluice gate not been physically locked in manual mode, remote actuation would have been technically feasible.

    Aliquippa / Unitronics Campaign (2023)

    CyberAv3ngers targeted publicly exposed Unitronics PLCs using default credentials, leveraging the absence of authentication on exposed HMIs. The ability to overwrite operational logic and disable automated pump control highlighted the persistent risk posed by PLCs left in “REMOTE/PROGRAM” mode, as well as the complete lack of protocol-aware inspection in many WWS environments.

    Coordinated Multi-State July 2026 Incident

    Beginning July 26, 2026, over 30 utilities experienced simultaneous PLC lockouts, IP address modifications, and forced manual operations. Key technical findings included:

    • Automated scripts performed credential changes and IP reassignments on PLCs, effectively severing operator access.

    • 59% of compromised endpoints were accessible via unmanaged cellular gateways deployed by integrators outside enterprise visibility.

    • Hardware impacted included Rockwell MicroLogix 1400/EtherNet IP, Siemens S7 1200, and Schneider Electric devices lacking hardware logic locking.

    These TTPs strongly aligned with prior IRGC-linked activity, reinforcing attribution assessments and raising the risk of continued adversary activity as the geopolitical situation evolves.

    Root-Cause Vulnerabilities in Modern WWS OT

    Water infrastructure remains uniquely exposed due to several structural issues:

    Legacy Protocols Without Security Controls

    Modbus TCP, EtherNet/IP, and Profinet offer no native authentication, encryption, or integrity checking, making them susceptible to command injection, unauthorized writes, and manipulation of memory/register maps.

    Shadow IT via Vendor Modems

    Unmanaged LTE modems bypass firewalls and IDS entirely. Many support remote diagnostics, open inbound ports by default, and rely on NAT traversal or cloud-based management portals vulnerable to credential compromise.

    Insecure PLC Run Mode States

    PLCs left in remote/program mode allow attackers to:

    • Upload modified ladder logic

    • Clear firmware images

    • Modify networking parameters

    • Push corrupted or empty project files

    Lack of Protocol-Aware Monitoring

    Traditional IT IDS cannot parse CIP (Ethernet/IP), S7Comm, or Modbus function codes. As a result, logic edits, register modifications, and configuration changes occur undetected.

    REMUS: Technical Architecture & Defensive Capabilities

    REMUS is engineered as an OT-native security capability designed to directly integrate OT/ICS designed architecture documentation, live network telemetry, and security tool reporting into a unified Risk management appliance.

    remus-graphic-2-remus-gap

    Automated Asset Discovery & Shadow Mapping

    REMUS enumerates:

    • Network pathways for understanding attack vectors

    • Device Communications to baseline and identify anomalies

    • Undocumented OT or IT devices within the environment for verification

    • All known vulnerable devices linked by Mission Function, System Owner, and Mission Impact

    This eliminates blind spots and provides operators with full visibility into routable OT pathways.

    Zero-Trust OT Microsegmentation

    Instead of protecting PLCs with perimeter firewalls—which fail once traffic reaches internal OT networks—REMUS scrutinizes network traffic configurations and telemetry, tracks and identifies communications between all OT devices, and identifies remote access.  By comparing all communication sources, protocols, and baseline behavior, REMUS alerts operators to any network segmentation limitations and highlights how risk can enter or propagate through the environment.

    Device Configuration Integrity & Recovery

    REMUS identifies unauthorized writes, IP reassignments, and command sequences inconsistent with baseline operations. It maintains knowledge of individual device configurations and PLC project files. If a logic block is changed—whether through malicious write commands or incorrect vendor updates—REMUS flags the modification and supports immediate tracking of its impact.

    Learn More: Download the REMUS Product Slick Sheet to see how its cyber-physical logical twin simulates threats, assesses potential impacts, and tests mitigations across cloud, on-premises, and air-gapped OT/ICS environments

    Next Steps for OT Engineers & ICS Defenders

    Recent incidents confirm that adversaries understand water-sector architecture and are actively exploiting systemic weaknesses. Defenders must move beyond perimeter-centric security and adopt solutions that can understand and validate control-layer behavior.

    REMUS provides the operational visibility, protocol-level awareness, and logic integrity needed to safeguard critical water and OT infrastructure against increasingly capable threat actors.

    Continue the Conversation at the 2026 National Cyber Summit

    The broader OT security discussion extends beyond the water sector. Defense programs, tactical networks, and mission-critical systems face the same structural vulnerabilities – exposed interfaces, unmanaged remote access, and protocols never designed with security in mind.

    To explore how these challenges apply in defense environments, join Chase Taylor, our REMUS solution lead, at the 2026 National Cyber Summit in Huntsville on September 23. He’ll be presenting on managing OT risk with REMUS. You can also connect with our team at Booth 402 throughout the event.

    Mark Nash

    Mark is a cybersecurity and intelligence leader with 30+ years experience guiding complex cyber, analytic, and operational missions across the IC. Before retiring from NSA, he led NSA and interagency efforts to counter cyber threats, inform senior decision-makers, and strengthen national security.

    More from the blog

    View All Posts