Iranian‑Linked Cyberattacks Disrupt Water & Wastewater Utilities in 12 U.S. States
What Happened — A coordinated campaign attributed to Iranian‑state‑aligned actors is targeting internet‑exposed programmable logic controllers (PLCs) at water and wastewater utilities. The attackers remotely access the PLCs, change passwords and disable monitoring, causing service interruptions, boil‑water advisories and manual‑operation switches in at least twelve states.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of logical‑access controls and privileged‑account management – core SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) controls.
- Continuous monitoring of OT assets and evidence of remediation (e.g., removal of public‑facing PLCs) are required to demonstrate a defensible audit trail.
- Leveraging Verisq’s SOC 2 Access Controls capability helps you map OT access‑control gaps, collect real‑time evidence, and satisfy the “monitoring” and “incident‑response” criteria auditors expect.
Who Is Affected – Water and wastewater utilities (critical infrastructure) across the United States; downstream municipal customers and public health agencies.
Recommended Actions
- Inventory all internet‑exposed OT devices and enforce network segmentation.
- Apply SOC 2‑aligned privileged‑access management: rotate passwords, enforce MFA, and log all PLC access.
- Deploy continuous monitoring tools that capture access logs as audit evidence for SOC 2 readiness.
- Update incident‑response playbooks to include OT‑specific scenarios and conduct tabletop exercises.
Source: DataBreachToday
Technical Notes – Attack vector: exploitation of publicly accessible PLCs (misconfiguration) combined with stolen or weak credentials; no specific CVE disclosed. Impact: service disruption, potential water quality risk. Source: FBI / CISA advisories