WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 Hacktivist Targeting of Small Texas Utility Demonstrates Interest in Less-Secure OT Networks
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Hacktivist Targeting of Small Texas Utility Demonstrates Interest in Less-Secure OT Networks

Author: April Zupan

Created: Tuesday, October 22, 2024 - 14:31

Categories: Cybersecurity, Intelligence, OT-ICS Security

CSO Online has published an article revealing details on a recent ICS/OT-related cyberattack targeting the water system of Stanton, Texas. Despite only serving a population of 2,700, Russia-linked hacktivists still breached the utility’s network in order to access a human-machine interface (HMI) and manipulate its settings. Due to the threat actor’s inexperience, they were only capable of randomly changing settings, resulting in the loss of some untreated water. However, a more sophisticated state adversary with the same level of access could cause more significant damage.

Small American water utilities are a popular target for patriotic hacktivists linked to U.S. adversaries due to their resource poor, target rich environments that often have low standards of security, making it easier for threat actors with less technical skill to gain credibility in their community for executing an attack that appears like it has a significant impact or gains widespread attention. While their lack of ICS/OT experience means this impact usually ends up being minimal, the consistent pace of attacks resulting in successful OT-level access demonstrates the water and wastewater sector’s vulnerability if geopolitical realities change and advanced persistent threat (APT) state actors utilize sympathetic hacktivists to do more.

Small and medium sized utility members should consider their OT security efforts in light of these current trends. Being a smaller utility can actually make an organization a more attractive target as they are perceived to have weaker security and less resources, creating a higher chance of a successful attack. Read more at CSO Online.

Previous WaterISAC Coverage on Hacktivist Threat Activity:

  • EPA Report – Water Sector Incident Analysis Pertaining to People’s Cyber Army of Russia Reborn (CARR) | October, 2024
  • CISA Alert – Threat Actors Continue to Exploit OT/ICS through Unsophisticated Means | September, 2024
  • (TLP:AMBER) Threat Advisory – Russian-linked Threat Actors Targeting Water Utilities | September, 2024
  • Situational Awareness – U.S. Issues Sanctions Against CARR Attackers who Breached U.S. Water Utilities | July, 2024
  • WaterISAC Notification – EPA Issues Enforcement Alert to Drinking Water Systems to Address Cybersecurity Vulnerabilities | May, 2024

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar