Back to all lessons
Awareness Lessons
2 months ago

Internet-Exposed Water Systems Targeted by Iranian Threat Actors via Unsecured PLCs

Over 100 water and wastewater systems were targeted because their operational technology (OT) — specifically programmable logic controllers (PLCs) — was directly accessible from the internet via cellular modems, creating an easily exploitable attack surface. This reflects a fundamental configuration failure: critical industrial control systems should never be reachable from public networks without strict access controls and segmentation. The fact that Iranian state-linked actors were able to identify and target these systems at scale suggests they are being actively enumerated through tools like Shodan. While disruptions were limited this time, successful manipulation of water treatment systems could have serious public health consequences. This incident underscores the urgent need for OT/ICS environments to adopt network isolation principles standard in IT security.

Tactical Insight

Immediate actions

  • Disconnect or firewall all internet-facing PLCs and OT devices, replacing direct exposure with VPN-gated or out-of-band access solutions.
  • Audit all cellular modem connections used in OT environments and restrict inbound access using allowlists and strong authentication.

Long-term improvements

  • Implement strict network segmentation between IT and OT networks using industrial DMZs and unidirectional security gateways.
  • Maintain a complete, up-to-date inventory of all internet-exposed OT/ICS assets and conduct regular exposure assessments using tools like Shodan or Censys.
  • Adopt the principle of least privilege for all remote access to industrial control systems, requiring multi-factor authentication at minimum.

Detection measures

  • Deploy OT-specific intrusion detection systems (e.g., Dragos, Claroty) to monitor for anomalous commands or unauthorized PLC interactions.
  • Establish 24/7 monitoring and alerting for any unexpected remote connections to OT network segments, with escalation procedures tied to CISA advisories.