Executive Summary
Between 2024 and 2026, nation-state actors from Iran, Russia, and China have increasingly targeted water and wastewater systems worldwide. These cyberattacks exploit vulnerabilities such as weak passwords, exposed programmable logic controllers (PLCs), and inadequate network segmentation, leading to unauthorized access and potential operational disruptions. Notably, in 2025, Russian-linked actors caused a municipal water tank overflow in Muleshoe, Texas, by accessing a remote industrial interface. Similarly, Iranian groups have been observed exploiting exposed PLCs in the U.S. and Israel, while China's Volt Typhoon group has compromised critical infrastructure, including water systems, aiming for strategic pre-positioning. (darkreading.com)
The current relevance of these incidents is underscored by the persistent and evolving nature of cyber threats to critical infrastructure. The exploitation of basic security oversights by sophisticated threat actors highlights the urgent need for enhanced cybersecurity measures in the water sector to prevent potential disruptions and safeguard public health and safety.
Why This Matters Now
The escalation of cyberattacks on water systems by nation-state actors underscores the critical need for immediate action to secure vulnerable infrastructure. Addressing these threats is urgent to prevent potential disruptions that could have severe consequences for public health and safety.
Attack Path Analysis
Nation-state actors exploited weak passwords and exposed PLCs to gain initial access to water systems. They escalated privileges by exploiting default credentials and misconfigurations. Attackers moved laterally through poorly segmented networks to access critical control systems. They established command and control channels via compromised remote access tools. Sensitive operational data was exfiltrated through unmonitored outbound connections. Finally, they manipulated control systems to disrupt water distribution and treatment processes.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited weak passwords and exposed PLCs to gain unauthorized access to water systems.
Related CVEs
CVE-2025-67038
CVSS 9.8An unauthenticated OS command injection vulnerability in Lantronix and Silex serial-to-IP converters allows remote attackers to execute arbitrary commands.
Affected Products:
Lantronix Serial-to-IP Converter – All versions prior to patch
Silex Serial-to-IP Converter – All versions prior to patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Internet Accessible Device
Exploitation of Remote Services
Insecure Credentials: Default Credentials
Denial of Service
Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Account Management
Control ID: AC-2
PCI DSS 4.0 – Limit Access to System Components and Cardholder Data
Control ID: 7.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Primary target of Iran, Russia, China nation-state attacks exploiting weak passwords, exposed PLCs, and poor segmentation in water infrastructure systems.
Government Administration
Municipal water systems face high sabotage risk from state actors targeting exposed HMIs and legacy SCADA systems for psychological warfare.
Industrial Automation
Critical exposure through programmable logic controllers and human machine interfaces vulnerable to nation-state compromise requiring zero trust segmentation.
Information Technology/IT
Essential for implementing encrypted traffic protection, east-west security, and multicloud visibility controls against infrastructure targeting campaigns.
Sources
- Iran, Russia, China Target Water Systems for Sabotagehttps://www.darkreading.com/ics-ot-security/iran-russia-china-target-water-systems-sabotageVerified
- Hackers are exploiting flaws faster than companies can disclose themhttps://www.itpro.com/security/hackers-are-exploiting-flaws-faster-than-companies-can-disclose-themVerified
- US cybersecurity agency issues an urgent alert as Iranian hackers attack critical infrastructurehttps://www.tomshardware.com/tech-industry/cyber-security/us-cybersecurity-agency-issues-an-urgent-alert-as-iranian-hackers-attack-critical-infrastructure-cisa-guidance-warns-organizations-to-immediately-shield-certain-programmable-logic-controllers-from-the-internet-to-thwart-future-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit weak credentials, move laterally, and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF would likely have limited unauthorized access by enforcing strict identity-based policies, reducing the risk of exploiting weak credentials.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely have constrained privilege escalation by enforcing least-privilege access controls, reducing the attacker's ability to exploit default credentials.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely have restricted lateral movement by enforcing workload isolation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely have detected and constrained unauthorized command and control channels by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely have restricted data exfiltration by controlling and monitoring outbound traffic.
While Aviatrix CNSF would likely have constrained earlier attack stages, residual risks may remain, potentially allowing limited disruption to control systems.
Impact at a Glance
Affected Business Functions
- Water Distribution
- Water Treatment
- Customer Billing
Estimated downtime: 3 days
Estimated loss: $500,000
Customer billing information and internal operational data
Recommended Actions
Key Takeaways & Next Steps
- • Implement strong password policies and regularly update credentials to prevent unauthorized access.
- • Secure PLCs and HMIs by removing default credentials and applying necessary patches.
- • Enhance network segmentation to limit lateral movement within critical infrastructure.
- • Monitor and control outbound traffic to detect and prevent unauthorized data exfiltration.
- • Establish comprehensive incident response plans to quickly address and mitigate potential attacks.



