Protecting Critical Infrastructure. Securing Our Future.
Florida Caribbean East Africa Email (786) 529-5851
Back to Blogs & Articles

Critical Infrastructure Under Attack: What Recent Cyber Incidents Have in Common

Recent cyberattacks against critical infrastructure reveal a troubling pattern: attackers are repeatedly exploiting Internet-exposed devices, weak remote-access controls, legacy technology, and insufficient OT visibility to move closer to physical operations. From automatic tank gauges and network routers to water utility control systems, these incidents demonstrate why critical-infrastructure organizations must strengthen segmentation, authentication, monitoring, asset inventories, and operational resilience.

Critical Infrastructure Under Attack: What Recent Cyber Incidents Have in Common

By Timehri Networks
August 2026

Cyberattacks against critical infrastructure are often discussed as isolated events—a water utility is disrupted in one state, industrial monitoring equipment is compromised somewhere else, or a nation-state actor targets network routers.

But several incidents reported during the past three months reveal a much more important story.

The technology may be different. The attackers may be different. Their motivations may range from espionage and geopolitical disruption to opportunistic compromise.

Yet the weaknesses being exploited are remarkably similar.

Recent activity involving automatic tank gauge systems, critical-infrastructure network routers, and water and wastewater operational technology demonstrates that attackers do not always need a sophisticated zero-day vulnerability to penetrate critical infrastructure.

In many cases, they are finding something much simpler:

Critical systems that should never have been directly reachable from the Internet.

Three Recent Warning Signs

1. Internet-Exposed Automatic Tank Gauge Systems

In June 2026, the Cybersecurity and Infrastructure Security Agency, National Security Agency, FBI and other federal agencies warned of malicious cyber activity targeting Automatic Tank Gauge, or ATG, systems.

These systems are used throughout the energy, chemical, food and agriculture, transportation and other critical-infrastructure sectors to remotely monitor fuel and liquid storage tanks.

Federal agencies reported that attackers were compromising Internet-accessible ATG systems and executing commands against them. The activity was not publicly attributed to a particular nation-state or threat group. (NSA)

This matters because ATGs are not merely office computers. They may provide operators with information concerning tank levels, temperatures, leak conditions and other operational parameters.

A compromised monitoring device can therefore create consequences extending beyond confidentiality of data into the physical operation of a facility.

The government’s primary recommendation was strikingly simple:

Remove these systems from direct public Internet exposure.

2. Nation-State Actors Targeting Critical-Infrastructure Routers

Only weeks later, U.S. and allied cybersecurity agencies warned that Russian state-sponsored actors were targeting poorly secured networking equipment associated with critical infrastructure.

The campaign included scanning for vulnerable or improperly configured routers and exploiting weaknesses such as insecure management services, weak SNMP configurations and legacy technologies. (SecurityWeek)

Routers may appear to belong primarily to the information-technology side of an organization, but within modern industrial environments they can form part of the communications path connecting remote facilities, SCADA networks, engineering systems and operational assets.

Compromise of an edge device can give an adversary something extremely valuable:

A foothold from which to observe, persist, collect information or potentially move deeper into the environment.

Again, the fundamental problem was not necessarily an exotic attack.

Attackers were looking for systems that were externally reachable, poorly configured, inadequately maintained or using outdated security protocols.

3. Coordinated Attacks Against Water Operational Technology

The warning became significantly more serious in late July.

Minnesota authorities reported that a coordinated cyberattack targeted operational technology at more than 30 community water systems on July 26 and 27, 2026. (mn.gov // Minnesota’s State Portal)

Some utilities experienced disruptions to automated control functions. Braham’s water treatment operations were temporarily affected, while other communities continued operating by switching to manual procedures. (SecurityWeek)

The incidents immediately raised concerns about Internet-accessible industrial controllers.

Unlike an attack that merely steals customer records, compromising a PLC or another operational control device can potentially influence pumps, valves, wells, lift stations, tanks and treatment processes.

Although reporting has linked the broader activity to concerns about Iranian-affiliated actors, public attribution should be treated carefully while federal investigation continues. What is firmly established is more important from a defensive standpoint:

Attackers were targeting operational technology controlling physical infrastructure.

The Similarities Are More Important Than the Differences

Looking across these incidents reveals several recurring patterns.

1. Internet Exposure Remains a Major Critical-Infrastructure Vulnerability

The clearest similarity is direct or insufficiently protected Internet connectivity.

Remote access provides enormous operational benefits.

Utilities can monitor remote pumping stations. Integrators can troubleshoot PLCs without traveling to the site. Tank levels can be checked remotely. Engineers can support facilities hundreds of miles away.

But convenience can quietly become exposure.

A PLC, router, HMI, cellular gateway, VNC server, remote terminal or industrial monitoring device that can be discovered from the public Internet becomes part of the organization’s attack surface.

NIST recently emphasized the same issue in its 2026 cybersecurity guidance for the water and wastewater sector. As utilities increase connectivity to pumping stations, monitoring systems and operational technology, the number of opportunities available to attackers also increases. (NIST)

The problem is therefore not remote access itself.

The problem is uncontrolled remote access.

2. Attackers Are Targeting the Technology Around the Process

Critical-infrastructure cybersecurity discussions often focus on the PLC.

But attackers increasingly have many other potential entry points.

Consider the recent targets:

  • Industrial tank-monitoring systems
  • Internet routers
  • Cellular communications
  • Remote-access infrastructure
  • PLCs and industrial controllers

An attacker does not necessarily need to attack the primary SCADA server first.

The easier route might be the router connecting a remote site.

Or a cellular modem installed several years ago by an integrator.

Or an industrial appliance with a default password.

Or a controller exposed through a firewall rule created to allow remote maintenance.

Once connectivity exists, the security of the industrial process depends on the security of the entire communications architecture surrounding it.

3. Legacy and Insecure Configuration Continues to Matter

Critical infrastructure often has equipment lifecycles measured in decades rather than years.

A PLC installed fifteen years ago may still control a perfectly functional pump.

A router may remain in service long after the technology used to manage it has become outdated.

An integrator may have configured a remote-access connection years earlier and nobody currently operating the facility may know that it exists.

This creates a dangerous cybersecurity reality:

Operational reliability can hide cybersecurity obsolescence.

A device can continue performing its engineering function perfectly while simultaneously becoming increasingly vulnerable from a cybersecurity perspective.

The U.S. Government Accountability Office warned in May 2026 that increasing connections between operational technology controlling pumps, valves and other physical equipment and Internet-enabled systems continue to increase cybersecurity risk for water and wastewater utilities. (GAO)

4. Weak Identity Controls Remain an Attack Enabler

Default passwords, shared credentials, weak authentication and insufficient restrictions on administrative interfaces continue to appear throughout industrial cybersecurity incidents.

In an enterprise IT environment, compromised credentials may expose files or email.

In an OT environment, compromised credentials may provide access to equipment controlling a physical process.

The security requirement must therefore be stronger.

Remote OT access should answer several questions:

Who is connecting?

From what device?

From where?

To what system?

For what purpose?

For how long?

And:

Can the session be monitored and reconstructed afterward?

A username and password alone is increasingly inadequate for critical infrastructure.

5. Asset Visibility Remains a Fundamental Problem

There is another common weakness that receives less attention.

Many organizations do not have a complete inventory of everything connected to their operational environment.

This can be especially difficult in distributed infrastructure.

A water utility might operate dozens or hundreds of:

  • Wells
  • Lift stations
  • Booster stations
  • Water tanks
  • Remote terminal units
  • Cellular gateways
  • PLCs
  • HMIs
  • Radios
  • Engineering workstations
  • Vendor remote-access devices

If cybersecurity personnel do not know that a device exists, they cannot determine whether it is exposed.

They cannot patch it.

They cannot monitor it.

And they cannot protect it.

An effective OT cybersecurity program therefore begins with an accurate inventory of hardware, software, communications paths and remote-access connections.

The Most Concerning Trend: Cyberattacks Are Moving Closer to the Physical Process

Historically, many organizations treated cybersecurity primarily as an information-protection problem.

Protect the database.

Protect customer information.

Protect email.

Protect financial records.

Those objectives remain important.

But attacks against critical infrastructure introduce another dimension:

Cybersecurity becomes operational safety and service reliability.

If a ransomware attack compromises an accounting workstation, the organization has a serious IT incident.

If an attacker modifies the controller responsible for maintaining a water tower level, the organization may have an operational emergency.

If communications with wastewater lift stations are lost, operators may need to dispatch personnel manually.

If monitoring equipment provides incorrect information, operators may make decisions based upon corrupted process data.

The distinction between cybersecurity and operations is therefore disappearing.

For critical infrastructure, cyber risk is increasingly cyber-physical risk.

Manual Operation Is Still a Cybersecurity Control

One of the most important lessons from recent water incidents is also one of the oldest principles in industrial operations.

A utility must remain capable of operating when technology fails.

EPA’s July 2026 National Cybersecurity Drill specifically challenged drinking-water and wastewater utilities to consider operating in an environment where telecommunications, Internet connectivity, cloud services and SCADA remote access were unavailable or unreliable. (US EPA)

That scenario suddenly looks less theoretical.

Utilities should know beforehand:

  • Which facilities can operate locally?
  • Who has authority to place equipment into manual control?
  • Are current PLC programs backed up offline?
  • Can operators reach remote facilities quickly?
  • Are local control panels functional?
  • Are emergency operating procedures documented?
  • Can the utility communicate if normal Internet and cellular services are unavailable?

Cyber resilience means more than stopping the attacker.

It means continuing the mission despite the attack.

What Critical-Infrastructure Organizations Should Do Now

The recent attacks reinforce several priorities that Timehri Networks considers fundamental to protecting industrial environments.

Eliminate unnecessary Internet-facing OT

Organizations should identify every externally accessible PLC, HMI, RTU, industrial gateway, cellular modem, router and monitoring appliance.

If public Internet accessibility is unnecessary, remove it.

Secure remote access

When remote access is operationally necessary, access should occur through controlled architecture using technologies such as secure VPNs or equivalent protected gateways, multifactor authentication, access restrictions, logging and properly segmented jump hosts.

NIST’s 2026 water-sector cybersecurity reference architecture specifically provides practical designs for securing remote access into water and wastewater environments. (NIST)

Segment IT and OT networks

A compromised employee laptop should not provide a pathway directly into the process-control environment.

Likewise, compromise of a remote industrial device should not automatically provide unrestricted access throughout the entire OT network.

Change default credentials

Default passwords should not exist anywhere in critical operational infrastructure.

Shared vendor credentials should also be identified and eliminated wherever technically possible.

Discover unknown remote connections

Organizations should specifically investigate cellular connections, vendor-installed gateways, remote maintenance appliances and historical firewall rules.

The connection nobody remembers may be the connection an attacker finds.

Monitor OT communications

Traditional endpoint security alone provides incomplete visibility into industrial environments.

Organizations should monitor network traffic between SCADA systems, HMIs, PLCs, RTUs and remote facilities to identify unusual communications and changes in normal operational behavior.

Maintain offline backups

PLC programs, HMI configurations, SCADA configurations, firewall configurations and essential engineering documentation should be backed up securely and tested for restoration.

Exercise manual operations

Operators should periodically demonstrate that critical processes can continue when remote communications or supervisory systems become unavailable.

The Bigger Lesson for Utility Leadership

Boards, city managers and utility executives should not interpret these incidents simply as warnings that hackers are becoming more sophisticated.

That conclusion misses the most important lesson.

The attackers are sophisticated.

But many successful attacks still begin with weaknesses that organizations already know how to correct.

An Internet-facing industrial controller.

An inadequately protected router.

A default password.

An undocumented cellular modem.

An outdated firmware version.

A flat network.

An unmonitored vendor connection.

The recurring lesson of the past several months is therefore straightforward:

Critical infrastructure does not necessarily need more connectivity. It needs better-controlled connectivity.

Industrial digital transformation will continue. Utilities will deploy additional sensors, cloud platforms, analytics, remote operations and connected control systems because these technologies provide real operational benefits.

The objective cannot be to disconnect every industrial system.

The objective must be to ensure that connectivity is intentional, inventoried, authenticated, segmented and continuously monitored.

From Cybersecurity to Operational Resilience

The June attacks involving industrial tank-monitoring systems, the July campaign against critical-infrastructure routers, and the late-July attacks against water operational technology appear different when considered individually.

Viewed together, however, they expose the same systemic problem.

Critical infrastructure has become increasingly connected while cybersecurity controls have not always evolved at the same pace.

That gap is exactly where adversaries are operating.

For water utilities, electric utilities, transportation systems, manufacturing facilities and other industrial operators, the next question should therefore not be:

“Could someone attack our infrastructure?”

Recent events have already answered that question.

The better questions are:

What can an attacker currently reach?

What would happen if they reached it?

Would we detect them?

Could we contain them?

And perhaps most importantly:

Could we continue operating safely without it?

Those are the questions that define operational resilience.


About Timehri Networks

Timehri Networks helps critical-infrastructure organizations strengthen the cybersecurity and resilience of their operational technology and SCADA environments. Our approach emphasizes practical OT risk assessment, secure network architecture, remote-access security, continuous monitoring, incident preparedness and the protection of essential industrial operations.

Florida • Caribbean • East Africa

I’d recommend publishing this as an analysis/thought-leadership article rather than a news article. Its strongest message is that the recent attacks demonstrate a repeatable architecture problem: attackers are exploiting the exposed edges of OT environments to get progressively closer to the physical process.

Request Assessment