Executive Summary

In July 2024, over 100 water and wastewater treatment systems across multiple states were compromised through vulnerable industrial controllers connected directly to public cellular networks. CISA identified the widespread campaign targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment, with attackers gaining operational control and causing service disruptions including pump station failures and boil-water advisories. The incidents exposed critical infrastructure gaps where operational technology exists outside traditional IT security boundaries, with many systems invisible to network scans but trackable through carrier invoices. This campaign highlights the urgent need for comprehensive network visibility and microsegmentation in critical infrastructure, as traditional network perimeter defenses fail to protect cellular-connected industrial control systems that operate independently of municipal IT networks.

Why This Matters Now

Water utility attacks are escalating as threat actors increasingly target cellular-connected industrial controls that exist outside traditional security perimeters, exposing critical infrastructure vulnerabilities that require immediate microsegmentation and zero-trust approaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The vulnerable controllers were never on city networks - they operated on public cellular connections that existed outside traditional IT security boundaries and weren't tracked in asset inventories.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this water utility attack by enforcing segmentation between operational technology networks and limiting lateral movement across municipal infrastructure. The attack's blast radius across water plants, libraries, and municipal services would likely have been substantially reduced through workload isolation and east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The initial compromise through cellular modems would likely still occur, but attackers' ability to reach deeper into SCADA systems and critical infrastructure would be substantially constrained through identity-aware access controls and network segmentation policies.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation attempts would likely be constrained through workload-level isolation policies that prevent compromised credentials from accessing elevated SCADA functions or administrative systems beyond their designated operational scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement across municipal infrastructure would likely be severely constrained, with attackers unable to traverse from water treatment systems to library networks or other municipal services due to enforced microsegmentation policies.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control communications would likely be detected and constrained through comprehensive traffic monitoring and policy enforcement, reducing attackers' ability to maintain persistent administrative access across distributed water system infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration would likely be significantly constrained through controlled egress policies that limit outbound data flows from operational technology networks, reducing the volume and sensitivity of information accessible to attackers.

Impact (Mitigations)

While some operational disruption may still occur within compromised water treatment facilities, the scope of impact would likely be constrained to isolated operational zones rather than cascading across the entire municipal infrastructure network.

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • Wastewater Management
  • SCADA Control Systems
  • Public Utility Services
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of operational technology (OT) systems, SCADA configurations, and water treatment control parameters. Loss of visibility and control over critical water infrastructure affecting over 260,000 people in some cases.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate critical infrastructure systems like water treatment plants from shared municipal networks
  • Deploy Encrypted Traffic (HPE) controls for all cellular and remote connections to prevent interception of SCADA communications
  • Establish East-West Traffic Security monitoring to detect lateral movement between operational technology and information technology networks
  • Enable Multicloud Visibility & Control to maintain centralized oversight of all network-connected devices including cellular modems
  • Implement Egress Security & Policy Enforcement to prevent unauthorized data exfiltration from industrial control systems

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image