In November 2023, Iranian hackers compromised the Municipal Water Authority in Aliquippa, Pennsylvania, by exploiting a vulnerable control system and defacing it with anti-Israel messages.
Following that, in January 2024, Russian cyber operatives targeted water facilities in Muleshoe and Abernathy, leading to minor issues like tank overflows. These incidents underscore the fragility of critical infrastructure in the U.S., particularly when industrial control systems (ICS) and human-machine interfaces (HMIs) are inadequately protected.
Recent investigations by Censys have revealed that a vast number of internet-connected ICS devices are susceptible to cyber threats. This situation highlights an urgent need for bolstered security measures across water management systems and other essential services.
An in-depth analysis of internet-exposed ICS devices in both the U.S. and the U.K. identified three key components that require attention:
- Automation Protocols: These facilitate communication between ICS components but often lack strong authentication.
- Human-Machine Interfaces (HMIs): These are the main control points for operators and increasingly allow remote access, making them attractive targets.
- Web Administration Interfaces: Many of these interfaces, which manage PLCs, RTUs, and other ICS elements, are often left with default settings, creating significant vulnerabilities.
The study aimed to assess the digital presence and security weaknesses of SCADA systems within critical infrastructure. It emphasized the heightened risks posed by internet-connected systems, particularly those with remote access capabilities and insufficient security configurations.
Findings indicate a critical need for improved cybersecurity practices to defend against potential threats from state-sponsored and other malicious actors. Exposed automation protocols and administration interfaces present substantial security risks that can be exploited even by those with limited system knowledge.
Many of these ICS devices in the U.S. connect via cellular networks or commercial ISPs, and often automation protocols do not provide clear ownership information. This lack of transparency complicates efforts to identify and alert affected parties, leaving numerous vulnerabilities unresolved.



