The US Cybersecurity and Infrastructure Agency (CISA) is urgently warning US organizations of cyberattacks on Operational Technology (OT) devices in water and wastewater systems. Driven by a group of highly skilled, well-funded Iran-affiliated threat actors, the attacks aim to "cause disruptive effects within the United States". The FBI reports that water systems in at least seven states have been targeted over the past week.

CISA observes that "Iranian-affiliated APT campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran and the United States and Israel." These malicious cyber actors are targeting "water entities of all sizes," specifically Programmable Logic Controllers (PLCs), or specialized industrial computers that automate physical processes. These PLCs are typically directly accessible on the internet, making it easy for threat actors to exploit without the need for sophisticated malware. Rather than focusing on stealing data, attackers are interfering with equipment that physically controls water treatment and distribution.

CISA has previously reported on similar activity by CyberAv3ngers, a cyber threat group affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC). CyberAv3ngers initiated a similar campaign in 2023, where at least 75 devices were compromised. The latest incidents, however, have not been officially attributed to any specific group.

Hiding malicious activity in plain sight

The CISA advisory details one particular incident where the threat actors used PLC programming software to upload a malicious program to the system. Most of the original system was left in place to avoid suspicion, with the attackers adding instructions to override safety controls. After the actors extracted the desired project files, modifications were made to the control program, altering information shown on the Human Machine Interface (HMI) display — a screen that lets operators monitor and control industrial equipment. These changes disabled critical alarms and shutdown systems, allowing systems to operate in unsafe conditions without alerting their operators to any anomalies.

This highlights a growing trend in industrial cybersecurity, where attackers are not only targeting the controllers themselves, but the operator's view of the process. By manipulating the HMI display, they can make operators believe systems are functioning normally while malicious activity occurs. This increases the attacks' potential impact since responders may not immediately diagnose a problem. Water systems are critical infrastructure, and even a temporary outage can create significant community impacts.

CISA strongly urges all critical infrastructure organizations to remove all publicly exposed PLCs from the internet "as soon as possible," and to set up secure gateways and firewalls to reduce risk of compromise.