Cyberattacks targeting programmable logic controllers (PLCs) at water and wastewater utilities across more than a dozen U.S. states have exposed a direct vulnerability for the electric power sector, since the same PLC technology controls an estimated 50 to 80 percent of grid endpoints. Federal agencies have confirmed incidents in Michigan, South Dakota, and Minnesota, with Wisconsin on alert, and while no major service disruptions have occurred, the FBI and CISA have linked the activity to Iranian-affiliated threat actors who previously targeted similar equipment in U.S. and Israeli water systems. The attacks serve as a live-fire demonstration of the risk that internet-accessible industrial control hardware poses to critical infrastructure.
The convergence of operational technology across water and power systems means a single exploit class can cascade across sectors. PLCs are the workhorses of automation — managing pumps, valves, breakers, and increasingly, distributed energy resources like inverters. When those controllers are reachable from the public internet, whether through misconfiguration or legacy remote-access designs, they become targets for automated scanning and rapid weaponization. Energy Central contributor Richard “Dick” Brooks, a software engineer and cybersecurity specialist, warned that a coordinated, simultaneous strike against PLC-dependent grid assets could materially affect power supply, especially as AI tooling compresses the time from vulnerability disclosure to active exploit to mere minutes.
Mitigation requires more than perimeter defenses. Brooks and federal guidance both emphasize zero-trust architecture — eliminating implicit trust for any device, user, or network segment — and establishing direct vulnerability notification channels with equipment manufacturers. Many utilities still rely on vendors for firmware patches but lack formal agreements for early warning of newly discovered flaws. Closing that gap is essential, because the window to apply mitigations before an exploit is exercised in the wild has effectively vanished. CISA’s “Secure by Design” alerts and vendor security advisories should be treated as operational inputs, not optional reading.
The water-sector incidents are not isolated anomalies; they are the leading edge of a threat landscape that will only expand as grid modernization adds more connected inverters, smart sensors, and remote-accessible controls. Regulators and industry groups are already moving toward mandatory cybersecurity baselines for critical infrastructure, but compliance timelines lag behind adversary capability. For power professionals, the message is clear: the PLCs running your substations and DER fleets are the same targets hit in the water sector. Hardening them, segmenting their networks, and demanding vendor accountability are no longer discretionary investments — they are prerequisites for grid reliability.
Read the full report at Energy Central.