Global AttacksSecurity

PLC Targeting Highlights Risks Beyond Direct Internet Exposure

The US Water and Wastewater Systems Sector has been the target of increased cyber threat activity in recent weeks. Since July 27, utilities in multiple states, including New Jersey, have reported incidents involving the compromise of internet-exposed programmable logic controllers (PLCs). There have been no widespread disruptions reported in the recent surge of attacks; however, impacts sustained from the incidents include flooding and water pressure reduction. The events highlight a continued interest in accessing sensitive operational environments crucial to public health and safety.

The tactics, techniques, and procedures (TTPs) used in the attacks align with those observed in similar incidents earlier this year. Although no public attribution has been formally made, the activity also appears to be consistent with Iran-linked threat groups. While these attacks continue to center on internet-exposed PLCs, indirect pathways into operational technology (OT) environments remain a security consideration. PLC devices themselves do not need to be directly accessible from the internet to be at risk. The compromise of an internet-facing asset with a network path to a PLC could also potentially provide an attacker with similar access. Therefore, water and wastewater organizations are encouraged to identify all externally accessible devices and remote-access services and evaluate whether those assets provide a network path to PLCs or other OT devices.

PLC exposure is not limited to the Water and Wastewater Systems Sector. These devices are also widely used by the Energy Sector. In December 2025, Poland’s energy infrastructure was targeted in a coordinated cyberattack affecting more than 30 wind and solar facilities and multiple combined heat and power (CHP) plants.

CERT Polska recently disclosed an additional intrusion at a separate CHP plant that occurred as part of the same campaign. In this incident, the PLCs were ultimately targeted, but were not directly exposed to the internet. Instead, attackers gained access through an internet-facing FortiGate device at a wind farm and subsequently compromised a connected cellular router. They then leveraged a misconfiguration in a private cellular Access Point Name (APN) network to pivot into a CHP plant’s operational environment, where they manipulated the PLC devices to shut down a steam turbine and the plant’s process-water treatment systems. This incident demonstrates how internet-facing assets elsewhere in a connected network environment can provide a pathway to PLCs that are not themselves directly exposed.

For additional information on the recent Water and Wastewater Systems Sector activity and recommended mitigations, organizations are encouraged to review the FBI and EPA’s Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions and the joint Cybersecurity and Infrastructure Security Agency (CISA) and partner advisory Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure. Additional technical details regarding the December 2025 attacks against Poland’s energy sector are available in CERT Polska’s Follow-Up Report of the December 2025 Energy Sector Incident.