The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Environmental Services
Breach intelligence, attack campaigns, and threat reports targeting the Environmental Services sector.
Explore Other Sectors
Environmental Services Threat Reports
SpyCloud Exposes Massive Credential Theft Threatening U.S. Water Infrastructure
In December 2024, cybersecurity firm SpyCloud published research revealing that nearly 20% of U.S. water and wastewater organizations have identity data actively exposed through infostealer malware. The study analyzed 10,000 EPA-registered water systems and found 1,787 organizations with active credential exposure, including a critical supply chain incident where a single compromised device at a smart meter technology provider exposed login credentials for approximately 167 different utility companies. Attackers leveraging these stolen credentials can bypass multi-factor authentication through session hijacking and gain persistent access to corporate networks. This research comes amid heightened scrutiny of critical infrastructure security following multiple cyberattacks on water systems throughout 2024, with U.S. officials attributing many incidents to Iranian threat actors targeting operational technology systems.
2 days ago
Kill Chain
Critical GeoNetwork Vulnerabilities Threaten 121 Government Geoportals Worldwide
In July 2026, GeoNetwork, an open-source geospatial metadata catalog used by government agencies worldwide, patched two critical vulnerabilities that could be chained together for unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6) allows anonymous file uploads to the formatter directory, while CVE-2026-58400 (CVSS 9.1) enables malicious XSLT stylesheets to execute operating system commands through the Saxon transformation engine. Security researcher Rafael Castilho identified 121 exposed instances across 39 countries, with 89% belonging to government, military, or national agencies running the vulnerable software behind critical geoportal infrastructure. This incident highlights the growing targeting of geospatial infrastructure, following recent exploitation of GeoServer vulnerabilities for cryptocurrency mining and backdoor deployment. As governments increasingly digitize spatial data services and critical infrastructure mapping, these specialized systems present attractive targets for nation-state actors and cybercriminals seeking to compromise sensitive geographic intelligence.
3 weeks ago
Kill Chain
Cyberattacks Reveal Critical Vulnerabilities in U.S. Water Systems
In late July 2026, a series of cyberattacks targeted water and wastewater systems across at least 12 U.S. states, including Michigan, South Dakota, and Georgia. Attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), specifically the MicroLogix 1100 and 1400 models, to remotely alter configurations, leading to operational disruptions such as pressure loss and flooding. Despite prior federal warnings, over 4,000 such controllers remained accessible online, with 2,844 located in the United States. This incident underscores the persistent vulnerabilities in critical infrastructure due to inadequate cybersecurity measures. The exploitation of known vulnerabilities in widely used industrial equipment highlights the urgent need for enhanced security protocols and the removal of operational technology from direct internet exposure to prevent future attacks.
1 month ago
Kill Chain
Iranian Cyberattacks Expose Vulnerabilities in U.S. Water Utilities
In late July 2026, a coordinated series of cyberattacks targeted over 30 community water systems across Minnesota, with similar incidents reported in at least 12 other states. The attackers, suspected to be Iranian-affiliated hackers, exploited vulnerabilities in internet-exposed programmable logic controllers (PLCs) that manage critical water infrastructure. These breaches led to operational disruptions, including temporary shutdowns of water treatment plants and manual operation shifts, though no contamination of drinking water was reported. ([techradar.com](https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers?utm_source=openai)) This incident underscores the escalating threat to U.S. critical infrastructure from state-sponsored cyber actors. The attacks highlight systemic vulnerabilities in aging water systems, many of which lack adequate cybersecurity measures. The urgency for enhanced security protocols and infrastructure investment is paramount to prevent future disruptions and safeguard public health.
1 month ago
Kill Chain
CISA Issues Alert on Iranian Cyber Actors Targeting U.S. Critical Infrastructure PLCs
In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including water and wastewater systems. These actors exploited vulnerabilities in PLCs from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens, leading to operational disruptions and financial losses. The attackers manipulated data on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) displays, causing outages and misleading operators about system statuses. This incident underscores the escalating threat landscape where state-sponsored actors are increasingly focusing on industrial control systems. The expansion of targeted PLC brands highlights the need for organizations to reassess and fortify their operational technology (OT) security measures to prevent potential disruptions to essential services.
1 month ago
Kill Chain
Minnesota Water Utilities Face Coordinated Cyberattacks in July 2026
In late July 2026, over 30 community water systems in Minnesota experienced a coordinated cyberattack targeting their operational technology (OT) systems. The attacks, occurring on July 26 and 27, led to temporary disruptions in water treatment and distribution processes. For instance, the City of Braham reported its water plant was taken offline due to a malicious cyberattack but managed to restore operations within hours. The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities, collaborating with federal, state, local, Tribal, and private-sector partners to investigate and mitigate the incident. This incident underscores the escalating threats to critical infrastructure, particularly in the water sector. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has emphasized the importance of isolating key OT systems to ensure continuity of critical services during cyberattacks. ([cyber.gov.au](https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems?utm_source=openai))
1 month ago
Kill Chain
Coordinated Cyberattack Disrupts 30+ Minnesota Water Systems
In late July 2026, a coordinated cyberattack targeted operational technology at over 30 community water systems across Minnesota, leading to service disruptions in cities including Braham, Plymouth, South St. Paul, and Maple Plain. The attacks affected automated controls and communications, with Braham's water plant temporarily going offline. State and federal agencies, including Minnesota IT Services (MNIT), the Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA), initiated a comprehensive response to contain the incidents and restore services. The attackers' methods and identities remain under investigation, with no confirmed attribution to date. This incident underscores the escalating threat to critical infrastructure, particularly water systems, from cyberattacks. The similarities between this attack and previous campaigns targeting industrial control systems highlight the urgent need for enhanced cybersecurity measures and vigilance in protecting essential services.
1 month ago
Kill Chain
ZionSiphon Malware: A New Threat to Israeli Water Infrastructure
In April 2026, cybersecurity researchers identified a new malware strain named ZionSiphon, specifically engineered to target Israeli water treatment and desalination systems. The malware exhibits capabilities such as establishing persistence, modifying local configuration files, and scanning for operational technology (OT) services within local networks. Notably, ZionSiphon is designed to operate exclusively within Israeli IP address ranges and targets processes associated with water treatment operations, including chlorine dosing and pressure control systems. While the current version contains a flaw that prevents full execution, its architecture indicates a significant advancement in OT-targeted cyber threats. ([thehackernews.com](https://thehackernews.com/2026/04/researchers-detect-zionsiphon-malware.html?utm_source=openai)) This discovery underscores a growing trend of politically motivated cyberattacks aimed at critical infrastructure. The emergence of ZionSiphon highlights the increasing sophistication of threats targeting OT environments, emphasizing the need for enhanced security measures to protect essential services from potential sabotage.
5 months ago
Kill Chain
Iranian APT Exploits PLC Vulnerabilities in U.S. Critical Infrastructure
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors targeted internet-facing operational technology (OT) devices, specifically programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, across multiple U.S. critical infrastructure sectors. These attacks led to disruptions in energy, water, and government facilities by manipulating project files and tampering with human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([databreaches.net](https://databreaches.net/2026/04/07/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure, highlighting the urgent need for enhanced cybersecurity measures and vigilance in protecting OT environments.
5 months ago
Kill Chain
Iranian APT Exploits U.S. Critical Infrastructure PLCs in 2026
In April 2026, Iranian-affiliated advanced persistent threat (APT) actors exploited internet-facing operational technology (OT) devices, notably Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), across multiple U.S. critical infrastructure sectors. The attackers accessed these devices via default or weak credentials, leading to disruptions through malicious interactions with project files and manipulation of data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruptions and financial losses. ([publicpower.org](https://www.publicpower.org/periodical/article/iranian-affiliated-cyber-actors-exploit-programmable-logic-controllers-across-us-critical?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting critical infrastructure. The exploitation of OT devices highlights the urgent need for organizations to secure internet-facing systems, implement strong authentication measures, and regularly update and patch their systems to mitigate such risks.
5 months ago
Kill Chain
Ransomware Attack Hits Romanian Water Authority: A 2024 Critical Infrastructure Wake-Up Call
In June 2024, Romania’s National Water Administration (Administrația Națională Apele Române) suffered a ransomware attack that disrupted key systems and operational processes. The attack, identified over the weekend of June 8–9, targeted core IT infrastructure, encrypting file servers and temporarily interrupting the administrative management of the country’s water resources. While water supply to the public reportedly remained unaffected, the incident led to delays in critical public and environmental services and highlighted gaps in incident response capabilities and network segmentation. Early indications suggest the attackers used a known ransomware variant, gaining access via a vulnerable remote service. This breach comes amid a surge in ransomware attacks on public utilities across Europe, emphasizing the increasing threat to operational technology and critical infrastructure. Heightened regulatory scrutiny and an evolving threat landscape put additional pressure on agencies to improve cyber resilience and visibility.
8 months ago
Kill Chain
Opportunistic Pro-Russia Hacktivist Attacks on Critical Infrastructure (2025)
In May and December 2025, joint advisories from CISA, FBI, NSA, Department of Energy, and international partners highlighted a surge in opportunistic attacks on US and global critical infrastructure mounted by pro-Russia hacktivist groups such as Cyber Army of Russia Reborn, Z-Pentest, NoName057(16), and Sector16. These actors leveraged poorly secured, internet-facing Virtual Network Computing (VNC) connections to infiltrate operational technology (OT) systems, targeting assets ranging from water treatment plants to energy and pipeline operators. The attacks, while generally less sophisticated than those carried out by advanced persistent threat (APT) groups, resulted in varying degrees of impact including service disruptions and, in some cases, physical damage to critical assets. This campaign reflects a growing trend of hacktivist groups exploiting low-hanging vulnerabilities in OT environments, often amplifying their impact through sensationalist or exaggerated public claims. The continued prevalence of exposed VNC devices and basic authentication weaknesses underscores the importance for asset owners and operators to harden access, enforce strong authentication, and monitor for anomalous activities to combat evolving hacktivist TTPs.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports