ics-ottrade-pressNewsThe Broadside2 min read

WaterISAC Pushes Faster Threat Sharing After Summer PLC Attacks

CISA, FBI, and EPA have pointed to Iranian-affiliated actors since April, but the structural problem remains unchanged: thousands of internet-exposed controllers, aging hardware, and integrator connections that small utilities don't know they have.


TL;DR

WaterISAC is adopting Cyware's threat intelligence platform to speed cross-sector threat sharing after a summer of attacks on internet-exposed PLCs at water utilities across at least 12 states. Executive Director Tom Dobbins told CyberScoop the sector's biggest vulnerabilities are exposed OT, aging PLCs built "pre-cyber threats," insecure integrator connections, and poor cyber hygiene at smaller utilities. CISA, FBI, and EPA have jointly attributed the PLC-targeting campaign to Iranian-affiliated actors since April, an assessment Dobbins endorsed over President Trump's public dismissal of Iranian involvement.

The computers that automate water treatment across the country were built for durability, not for an internet-connected world. After a summer in which attackers locked operators out of PLCs in at least 12 states (triggering boil-water notices and forcing manual operations) WaterISAC is betting that faster threat sharing can close some of the gap.

Tom Dobbins, WaterISAC's executive director, told CyberScoop the sector's most persistent weaknesses haven't changed: OT systems left accessible from the public internet, PLCs dating to what he called a "simpler, gentler time," and integrator connections that utilities don't always know exist. "If those integrators are working and they have a connection into an OT system that's not managed discretely, then a threat actor can come in through an integrator and get into a system," Dobbins said.

The ISAC announced a partnership with Cyware to use its threat intelligence platform, selecting the vendor partly because of its existing relationships with other industry ISACs. The aim is cross-sector sharing, according to Tom Stockmeyer, Cyware's managing director of government and critical infrastructure. WaterISAC already works with the National Rural Water Association to serve 20,000 of the sector's smallest utilities.

CISA, FBI, and EPA have pointed to Iranian-affiliated actors in joint advisories since April. The July 22 update expanded manufacturer scope to include Schneider Electric and Siemens PLCs alongside Rockwell Automation, and added detection guidance for malicious changes in reusable code modules. Dobbins endorsed that attribution despite Trump's public claim that Minnesota's own incompetence was to blame. "I saw a recent CISA release that pointed to Iran as threat actors," he said. "CISA maybe is more expert in this area than maybe the president."

A Forescout scan published August 6 found 2,844 exposed Rockwell Automation and Allen-Bradley controllers in the United States using EtherNet/IP. The same scan identified 22 exposed devices in cities recently hit by water system attacks. Forescout characterized the activity as "opportunistic, at-scale exploitation" consistent with mass scanning rather than targeted intrusion campaigns. That finding underscores Dobbins's core point: the equipment still works, so there's little incentive for cash-strapped utilities to replace it. The attackers aren't breaking in. The door is open.


Published ·Deep Fathom