Executive Summary
In July 2024, over 100 water and wastewater treatment systems across multiple states were compromised through vulnerable industrial controllers connected directly to public cellular networks. CISA identified the widespread campaign targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment, with attackers gaining operational control and causing service disruptions including pump station failures and boil-water advisories. The incidents exposed critical infrastructure gaps where operational technology exists outside traditional IT security boundaries, with many systems invisible to network scans but trackable through carrier invoices. This campaign highlights the urgent need for comprehensive network visibility and microsegmentation in critical infrastructure, as traditional network perimeter defenses fail to protect cellular-connected industrial control systems that operate independently of municipal IT networks.
Why This Matters Now
Water utility attacks are escalating as threat actors increasingly target cellular-connected industrial controls that exist outside traditional security perimeters, exposing critical infrastructure vulnerabilities that require immediate microsegmentation and zero-trust approaches.
Attack Path Analysis
Attackers compromised water utility controllers through exposed cellular modems, gaining direct access to SCADA systems. They escalated privileges within industrial control systems, moved laterally across unsegmented operational technology networks, maintained persistent command channels through cellular connections, exfiltrated operational data and system configurations, and ultimately disrupted water treatment operations causing service outages and boil-water advisories.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers identified and exploited water treatment controllers connected directly to public cellular networks, bypassing traditional network perimeters entirely
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Hardware Additions
Unsecured Credentials: Private Keys
Exploitation of Remote Services
Network Sniffing
Network Denial of Service
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Network Segmentation and Micro-segmentation
Control ID: Networks.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.04
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
DORA – ICT risk management framework
Control ID: Article 8
PCI DSS 4.0 – Network Security Controls
Control ID: 1.2.1
ISO 27001:2022 – Network controls
Control ID: A.13.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water treatment facilities face infrastructure compromise through unencrypted cellular connections, requiring zero trust segmentation and egress security for critical SCADA systems.
Government Administration
Municipal networks lack unified ownership across departments, exposing water plants, libraries, and facilities through inadequate east-west traffic security and visibility controls.
Information Technology/IT
IT departments must implement microsegmentation and multicloud visibility to prevent lateral movement across disparate municipal systems sharing common network infrastructure.
Public Safety
Critical infrastructure like 911 dispatch and traffic management require threat detection and anomaly response capabilities to prevent operational disruption from network intrusions.
Sources
- In most cities, nobody owns the whole networkhttps://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/Verified
- CISA Advisory - Iranian-Affiliated Actors Targeting Water and Wastewater Systemshttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- FBI and EPA Joint Report on Water Utility Incidentshttps://www.epa.gov/waterutilityresponseVerified
- Clayton County Water Authority Cyber Incident Reporthttps://www.ccwa.us/Verified
- Texas Water Development Board Cybersecurity Requirementshttps://www.twdb.texas.gov/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this water utility attack by enforcing segmentation between operational technology networks and limiting lateral movement across municipal infrastructure. The attack's blast radius across water plants, libraries, and municipal services would likely have been substantially reduced through workload isolation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise through cellular modems would likely still occur, but attackers' ability to reach deeper into SCADA systems and critical infrastructure would be substantially constrained through identity-aware access controls and network segmentation policies.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts would likely be constrained through workload-level isolation policies that prevent compromised credentials from accessing elevated SCADA functions or administrative systems beyond their designated operational scope.
Control: East-West Traffic Security
Mitigation: Lateral movement across municipal infrastructure would likely be severely constrained, with attackers unable to traverse from water treatment systems to library networks or other municipal services due to enforced microsegmentation policies.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be detected and constrained through comprehensive traffic monitoring and policy enforcement, reducing attackers' ability to maintain persistent administrative access across distributed water system infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration would likely be significantly constrained through controlled egress policies that limit outbound data flows from operational technology networks, reducing the volume and sensitivity of information accessible to attackers.
While some operational disruption may still occur within compromised water treatment facilities, the scope of impact would likely be constrained to isolated operational zones rather than cascading across the entire municipal infrastructure network.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Wastewater Management
- SCADA Control Systems
- Public Utility Services
Estimated downtime: 2 days
Estimated loss: $500,000
Potential exposure of operational technology (OT) systems, SCADA configurations, and water treatment control parameters. Loss of visibility and control over critical water infrastructure affecting over 260,000 people in some cases.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate critical infrastructure systems like water treatment plants from shared municipal networks
- • Deploy Encrypted Traffic (HPE) controls for all cellular and remote connections to prevent interception of SCADA communications
- • Establish East-West Traffic Security monitoring to detect lateral movement between operational technology and information technology networks
- • Enable Multicloud Visibility & Control to maintain centralized oversight of all network-connected devices including cellular modems
- • Implement Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from industrial control systems



