Iran-Linked Hackers Breach US Water Utilities in New Jersey and Alabama, Manipulating PLC Settings
What Happened — Iran‑linked threat actors accessed industrial control systems (ICS) at water utilities in New Jersey and Alabama, altering programmable logic controller (PLC) configurations to block remote access. The incidents coincided with a broader wave that has now affected at least 12 states, though water service and quality remained uninterrupted.
Why It Matters for Compliance & Audit Readiness —
- Shows why continuous monitoring of OT environments is required to satisfy SOC 2 CC6.1 (System Operations) and CC6.2 (Change Management) controls.
- Emphasizes the need for auditable logs that prove who changed critical PLC settings and when—exactly the evidence Verisq’s Control‑Mapping capability can capture automatically.
- Demonstrates that a Trust Center view of OT control evidence can streamline audit readiness and provide defensible proof of due‑diligence.
Who Is Affected — Municipal water and wastewater utilities, industrial control system vendors (e.g., Rockwell Automation), and the broader critical‑infrastructure sector.
Recommended Actions —
- Map the PLC‑access incident to SOC 2 CC6.1/CC6.2 controls and collect the relevant logs as audit evidence.
- Deploy continuous OT‑monitoring that feeds into a centralized Trust Center for real‑time compliance reporting.
- Review and harden remote‑access configurations, enforce least‑privilege policies, and run tabletop simulations of control‑system compromise. Source: Security Affairs
Technical Notes — The attackers targeted Rockwell Automation PLCs via known vulnerabilities and credential reuse, modifying settings to disable remote management. No water‑quality data was exfiltrated. Source: Security Affairs