The past several years have shown a clear evolution in adversarial tradecraft targeting US Water and Wastewater Systems (WWS). What began as reconnaissance-driven intrusions against isolated assets has escalated into coordinated, multi state campaigns aimed at manipulating PLC logic, disrupting automation, and degrading operator control. The July 2026 attacks underscored a critical fact: adversaries now possess the capability—and intent—to directly interfere with physical water operations through exposed operational technology (OT) interfaces.
This analysis breaks down the attack vectors observed across recent incidents and explains how REMUS™ provides a defensible architecture for asset discovery, protocol inspection, and logic integrity validation at scale.
Attackers gained SCADA access through an unsegmented cellular modem connected to a field RTU. The intrusion demonstrated an early but important lesson: standalone cellular gateways deployed for convenience create routable OT/IP pathways completely outside supervisory visibility. Had the sluice gate not been physically locked in manual mode, remote actuation would have been technically feasible.
CyberAv3ngers targeted publicly exposed Unitronics PLCs using default credentials, leveraging the absence of authentication on exposed HMIs. The ability to overwrite operational logic and disable automated pump control highlighted the persistent risk posed by PLCs left in “REMOTE/PROGRAM” mode, as well as the complete lack of protocol-aware inspection in many WWS environments.
Beginning July 26, 2026, over 30 utilities experienced simultaneous PLC lockouts, IP address modifications, and forced manual operations. Key technical findings included:
Automated scripts performed credential changes and IP reassignments on PLCs, effectively severing operator access.
59% of compromised endpoints were accessible via unmanaged cellular gateways deployed by integrators outside enterprise visibility.
Hardware impacted included Rockwell MicroLogix 1400/EtherNet IP, Siemens S7 1200, and Schneider Electric devices lacking hardware logic locking.
These TTPs strongly aligned with prior IRGC-linked activity, reinforcing attribution assessments and raising the risk of continued adversary activity as the geopolitical situation evolves.
Water infrastructure remains uniquely exposed due to several structural issues:
Modbus TCP, EtherNet/IP, and Profinet offer no native authentication, encryption, or integrity checking, making them susceptible to command injection, unauthorized writes, and manipulation of memory/register maps.
Unmanaged LTE modems bypass firewalls and IDS entirely. Many support remote diagnostics, open inbound ports by default, and rely on NAT traversal or cloud-based management portals vulnerable to credential compromise.
PLCs left in remote/program mode allow attackers to:
Upload modified ladder logic
Clear firmware images
Modify networking parameters
Push corrupted or empty project files
Traditional IT IDS cannot parse CIP (Ethernet/IP), S7Comm, or Modbus function codes. As a result, logic edits, register modifications, and configuration changes occur undetected.
REMUS is engineered as an OT-native security capability designed to directly integrate OT/ICS designed architecture documentation, live network telemetry, and security tool reporting into a unified Risk management appliance.
REMUS enumerates:
Network pathways for understanding attack vectors
Device Communications to baseline and identify anomalies
Undocumented OT or IT devices within the environment for verification
This eliminates blind spots and provides operators with full visibility into routable OT pathways.
Instead of protecting PLCs with perimeter firewalls—which fail once traffic reaches internal OT networks—REMUS scrutinizes network traffic configurations and telemetry, tracks and identifies communications between all OT devices, and identifies remote access. By comparing all communication sources, protocols, and baseline behavior, REMUS alerts operators to any network segmentation limitations and highlights how risk can enter or propagate through the environment.
REMUS identifies unauthorized writes, IP reassignments, and command sequences inconsistent with baseline operations. It maintains knowledge of individual device configurations and PLC project files. If a logic block is changed—whether through malicious write commands or incorrect vendor updates—REMUS flags the modification and supports immediate tracking of its impact.
Recent incidents confirm that adversaries understand water-sector architecture and are actively exploiting systemic weaknesses. Defenders must move beyond perimeter-centric security and adopt solutions that can understand and validate control-layer behavior.
REMUS provides the operational visibility, protocol-level awareness, and logic integrity needed to safeguard critical water and OT infrastructure against increasingly capable threat actors.
The broader OT security discussion extends beyond the water sector. Defense programs, tactical networks, and mission-critical systems face the same structural vulnerabilities – exposed interfaces, unmanaged remote access, and protocols never designed with security in mind.
To explore how these challenges apply in defense environments, join Chase Taylor, our REMUS solution lead, at the 2026 National Cyber Summit in Huntsville on September 23. He’ll be presenting on managing OT risk with REMUS. You can also connect with our team at Booth 402 throughout the event.