HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Iran-Linked Hackers Breach US Water Utilities in New Jersey and Alabama, Manipulating PLC Settings

Iran‑linked threat actors accessed industrial control systems at water utilities in New Jersey and Alabama, changing PLC configurations to block remote access. The incidents are part of a wave affecting at least 12 states and highlight the need for continuous OT monitoring and SOC 2 evidence collection.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Iran-Linked Hackers Breach US Water Utilities in New Jersey and Alabama, Manipulating PLC Settings

What Happened — Iran‑linked threat actors accessed industrial control systems (ICS) at water utilities in New Jersey and Alabama, altering programmable logic controller (PLC) configurations to block remote access. The incidents coincided with a broader wave that has now affected at least 12 states, though water service and quality remained uninterrupted.

Why It Matters for Compliance & Audit Readiness

  • Shows why continuous monitoring of OT environments is required to satisfy SOC 2 CC6.1 (System Operations) and CC6.2 (Change Management) controls.
  • Emphasizes the need for auditable logs that prove who changed critical PLC settings and when—exactly the evidence Verisq’s Control‑Mapping capability can capture automatically.
  • Demonstrates that a Trust Center view of OT control evidence can streamline audit readiness and provide defensible proof of due‑diligence.

Who Is Affected — Municipal water and wastewater utilities, industrial control system vendors (e.g., Rockwell Automation), and the broader critical‑infrastructure sector.

Recommended Actions

  • Map the PLC‑access incident to SOC 2 CC6.1/CC6.2 controls and collect the relevant logs as audit evidence.
  • Deploy continuous OT‑monitoring that feeds into a centralized Trust Center for real‑time compliance reporting.
  • Review and harden remote‑access configurations, enforce least‑privilege policies, and run tabletop simulations of control‑system compromise. Source: Security Affairs

Technical Notes — The attackers targeted Rockwell Automation PLCs via known vulnerabilities and credential reuse, modifying settings to disable remote management. No water‑quality data was exfiltrated. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197012/hacking/iran-linked-hackers-target-more-us-water-infrastructure-in-new-jersey-and-alabama.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →