When water becomes a weapon

Here we discuss the rise of state-sponsored OT attacks

For a long time now,cyberattacks against critical infrastructure were largely viewed as espionageoperations, that means stealing credentials, collecting intelligence, orpositioning for future conflicts. The landscape however today has changed(pause for affect) dramatically.

State-sponsored threat actors aligned with Russia and Iran are increasingly targeting Operational Technology (OT)environments, shifting their focus from information theft to the systems that keep societies functioning like,

·       water treatment facilities

·       power generation

·       manufacturing

·       industrialcontrol systems.

One point worth emphasizing is that these threat actorsare increasingly conducting OT attacks in parallel with kinetic militaryoperations elsewhere in the world. Rather than viewing cyber and physicalwarfare as separate campaigns, adversarial states are integrating them into asingle strategy.

This approach allows them to project power far beyond thebattlefield. By targeting critical infrastructure—such as water treatmentfacilities, energy grids, transportation networks, and industrial controlsystems—they can disrupt or intimidate adversaries thousands of miles awaywithout deploying troops or launching missiles across an ocean. In effect,cyber operations have become a force multiplier, extending the reach ofconventional conflict into countries that may not be directly engaged in thefighting.

For nations such as Russia and Iran, OT attacks provide arelatively low-cost, low-risk means of imposing strategic pressure, testingdefenses, gathering intelligence, and demonstrating capability. Even when theseattacks stop short of causing physical damage, they serve as a reminder thatmodern conflict is no longer confined by geography. The battlefield nowincludes the critical infrastructure that underpins everyday life, makingcyber-enabled disruption a global instrument of state power.

 

Recent incidents in both over the pond places like Poland andthe United States demonstrate a concerning trend: adversaries are nolonger simply probing industrial networks, …they are actively seeking toinfluence physical operations. 

Poland: A Testing Ground for Hybrid Warfare

Poland has become one ofEurope's primary targets for Russian-backed cyber operations due to itsstrategic role as a NATO member and logistical hub supporting Ukraine.

Over the past year, Polishauthorities have disclosed many compromises of water treatment facilities whereattackers gained access to industrial control systems responsible for pumps,filtration processes, and water treatment operations. In several cases, theattackers reached systems capable of altering operational parameters, althoughdefenders intervened before significant disruption occurred. 

What makes these attacksparticularly significant is that many relied on remarkably simple weaknesses:

  • Internet-exposed industrial control systems
  • Weak or default passwords
  • Poor network segmentation
  • Remote management interfaces accessible from the public     Internet

Rather than relying onsophisticated zero-day exploits, attackers exploited years of accumulatedtechnical debt. 

U.S Faces a Similar Threat

The United States isexperiencing many of the same patterns.

Federal agencies—includingCISA, the FBI, the NSA, and the Department of Energy—have warned that Iranianstate-backed actors are actively targeting programmable logic controllers(PLCs) and other industrial devices used throughout water and energy sectors.Recent advisories note attempts to manipulate industrial equipment andinterfere with safety-related functions rather than merely stealinginformation. 

Thatconcern was reinforced this week when more than 30 community water systems inMinnesota were impacted by a coordinated cyber campaign sharing characteristicswith previous attacks on U.S. water infrastructure. While investigations remainongoing and attribution has not been finalized, officials noted similarities toearlier Iranian-linked activity targeting operational environments.

Arecent incident involving a Quebec municipal water treatment facilityunderscores the growing reality of state-linked threats against North Americancritical infrastructure. According to the Communications Security Establishment(CSE), the Russian hacktivist group NoName gained unauthorized access tothe plant's operational technology (OT) environment, giving the attackers theability to manipulate pumps, chlorine dosing, pressure settings, and monitoringsystems before mitigation efforts were undertaken. While no public safetyimpacts were reported, the incident demonstrates how foreign adversaries aremoving beyond traditional espionage and into the realm of cyber-physicaloperations, where the compromise of industrial control systems can havereal-world consequences for public health and essential services. It serves asa stark reminder that water infrastructure has become a strategic target inmodern geopolitical conflict.

 

Why Operational Technology Is Different

Traditional cybersecurityfocuses on protecting data.

OTsecurity protects physical processes .However, it should be noted that OT security and the surronding architect are alsodesigned to protect historian and configuration data.

When an industrialcontroller is compromised, the consequences can extend far beyond stoleninformation:

  • Interrupting water treatment operations
  • Manipulating chemical dosing
  • Shutting down pumps
  • Disrupting electrical generation
  • Affecting manufacturing processes
  • Creating potential safety hazards for operators and the     public

Unlike conventional ITincidents, OT attacks can produce tangible physical consequences.

The Strategic Shift

Russia and Iranincreasingly view cyber operations as part of broader geopolitical campaigns insteadof isolated technical events.

These operations oftenserve multiple purposes:

  • Testing critical infrastructure resilience
  • Pre-positioning access for future crises
  • Applying political pressure without crossing the     threshold of conventional warfare
  • Demonstrating potential     remote kinetic-like capabilities to influence/disrupt civilian     infrastructure

Hybrid warfare is no longertheoretical. Cyber operations have become an extension of nationalstrategy. 

So what should we do now?

How clear the lessons fromboth Poland and recent U.S. incidents should be noted.

Organizations operatingindustrial environments should do the following,

  1. Eliminating     internet-exposed OT assets
  2. Enforcing     multi-factor authentication for remote access
  3. Segmenting IT     and OT networks
  4. Continuously     monitoring industrial protocols and engineering workstations
  5. Maintaining an     accurate inventory of PLCs, HMIs, and other industrial assets
  6. Developing and     regularly exercising OT-specific incident response plans

Many successful attackscontinue to exploit preventable weaknesses rather than advanced malware.

Looking Ahead

The convergence ofgeopolitical conflict and operational technology has fundamentally changed thethreat landscape.

Critical infrastructure isno longer simply collateral damage, unfortunately It is becoming the maintarget.

As demonstrated by recentactivity affecting Polish water utilities and ongoing campaigns against theStates, infrastructure, defending OT environments is no longer solely anengineering feat.

It has become a nationalsecurity imperative!

Read

Come Spar with Us

TENUMBRIANTs
May 8, 2025
Read

The End of Humanity as We Know It

Emerging Threats
March 13, 2025
Read

Cyber Sex World and Us

Emerging Threats
March 13, 2025

Ready to bolster your defenses

Uncover how we can help put your resilience to the test.

orb
glow

Uplink confirmed

Thank you! Your data packet has been received!

Oops! Something went wrong while submitting the form.