If your organization relies on Operational Technology (OT), a recent wave of industrial cyberattacks carries an urgent message.
While a joint FBI and Environmental Protection Agency (EPA) warning is currently highlighting malicious actors hijacking control systems across U.S. water utilities, the underlying threat extends far beyond municipal water. The same industrial controllers targeted in these attacks run critical systems in hospitals, manufacturing plants, energy grids, and commercial facilities.
Attackers are exploiting internet-exposed Rockwell Automation controllers across at least seven states. They are resetting passwords, changing IP addresses, and locking operators out of their own systems.
When control hardware fails, physical consequences follow immediately. Water facilities faced pressure losses, contamination risks, flooding, and needed to ask all the public to boil water before consumption. For healthcare facilities, chemical plants, or smart buildings, a similar lockout can mean HVAC failures, power disruptions, or compromised medical sterilization systems.
If you manage Critical Infrastructure or OT networks, these attacks prove that unmonitored field hardware is now a prime target. They bring into the spotlight the importance of network visibility, as well as sector and location specific intelligence to help prepare for attacks.
Quick Facts: FBI Warning on Water Sector Cyber Attacks
|
What Makes Critical Infrastructure Control Systems Vulnerable to Remote Exploitation?
Unmonitored internet connections and legacy field hardware allow attackers to bypass traditional corporate security firewalls.
Industrial facilities rely on Programmable Logic Controllers, known as PLCs, to manage physical machinery like pumps, valves, and HVAC units. Most of these industrial computers were designed for isolated operational environments. They lack basic modern security controls, encryption, or multi-factor authentication.
The primary targets in these recent attacks are Rockwell Automation MicroLogix 1100 and 1400 series PLCs. These legacy devices have reached End-of-Life status, meaning the manufacturer no longer issues security patches or firmware updates.
The biggest vulnerability stems from unmonitored entry points across field sites. To allow remote access, contractors often install 4G or 5G cellular modems directly onto control hardware. These shadow cellular connections rarely appear on central IT inventories or network maps.
Threat actors use automated web scanners to discover exposed cellular IP addresses across the internet.
Once connected, attackers log in using default credentials or unpatched vulnerabilities. They change administrative passwords, reconfigure device IP addresses, and alter the underlying ladder logic. Modifying this ladder logic rewrites the digital instructions that keep physical systems running safely.
What Are the Real-World Impacts of These Breaches?
Manipulating industrial control hardware causes immediate physical damage, operator lockouts, and community-wide public health hazards.
When attackers hijack a control device, operators lose visibility into real-time facility operations. Plant screens go dark or display false data while physical equipment continues running unmonitored.
Lockouts happen in seconds. Adversaries change device IP addresses and enable administrative passwords, stripping plant personnel of remote control.
These digital intrusions quickly trigger physical failures. Uncontrolled valve changes and pump shutdowns cause pressure drops in municipal water networks. Loss of water pressure allows untreated groundwater to seep into distribution pipes, contaminating clean water supplies.
Facilities also face physical destruction. Altered control settings can force pumps to overfill storage tanks, causing severe flooding in treatment facilities.
When safety thresholds are breached, local authorities must issue emergency boil-water notices, halting daily life and business operations across entire regions.
Who Is Behind the Attacks and What Does Threat Intelligence Show?
While the official FBI Cyber Alert stops short of formal attribution, security researchers note the tactics align directly with Iranian state-sponsored campaigns.
The recent FBI alert regarding compromised PLCs across seven states does not formally attribute the activity to a specific group, nor does it include technical indicators. The public Indicators of Compromise (IoCs) available for this activity come from the joint CISA and FBI Cybersecurity Advisory AA26-097A, which publishes 21 IP addresses used by the actors against the same class of internet-facing PLCs, each with its actor-association timeframe. That advisory details campaigns driven by Iranian Islamic Revolutionary Guard Corps (IRGC) actors operating under the moniker CyberAv3ngers.
CyberAv3ngers has targeted water sector controllers since 2023. Cybersecurity researchers note that this latest wave of industrial attacks is entirely consistent with the group’s established operational playbook.
Threat actors rely on these specific IP addresses and command infrastructure to scan for exposed controllers and execute unauthorized changes. Tracking these indicators allows security teams to identify malicious traffic before systems are locked out.
To investigate these threat actors and analyze the 21 associated Indicators of Compromise, access the full threat profile on the Lumu Maltiverse Threat Observatory.
How Can You Protect Industrial Networks Without Software Agents?
Analyzing network metadata across industrial environments provides complete visibility without touching sensitive hardware.
Traditional endpoint software cannot run on legacy industrial controllers. Devices like PLCs and cellular modems lack the processing power, storage, and operating systems required for standard security agents.
Lumu Defender provides this network-level visibility without software agents. By continuously ingesting metadata from DNS, NetFlow, firewall logs, and gateway traffic across your entire infrastructure.
This agentless approach reveals hidden entry points instantly. Unmonitored cellular modems and third-party access points become visible the moment they generate network traffic.
When an exposed controller attempts to connect to a suspicious external IP address or command server, Lumu Defender detects the breach immediately. Security teams can automate Lumu’s response playbooks to send block rules directly to firewalls and gateways. This isolates threat vectors in seconds before operators lose control.
What Steps Should Security Teams Take Right Now?
Security teams must execute a five-step defense playbook to secure field hardware and prevent operational failure.
- Sever Direct Internet Exposure: Remove PLCs and controllers from public-facing networks immediately. Mediate all remote access through secure gateways and jump hosts.
- Eliminate Shadow Cellular Connections: Audit remote field sites for undocumented 4G and 5G modems. Use Lumu Discover to continuously scan your attack surface and uncover exposed cellular connections before threat actors map them.
- Lock Hardware Key Switches: Set physical key switches on controllers to the RUN position. This physically prevents unauthorized remote changes to system logic and firmware.
- Audit and Verify System Logic: Compare active PLC project files against known-good backups. Use vendor integrity tools to ensure programs have not been altered.
- Automate Real-Time Containment: Deploy continuous network metadata monitoring across both IT and OT boundaries. Lumu Defender syncs directly with your existing firewalls and gateways to automatically isolate malicious actors the moment they touch your network.
Don’t wait for physical disruptions to reveal a breach.
To stay ahead of any attack, check out Lumu Maltiverse’s Threat Observatory. It gives you the sector- and location-specific intelligence you need to keep your critical infrastructure secure.