WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts OT/ICS Awareness – Password Attacks Observed on SCADA Network VPN Web Clients
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

OT/ICS Awareness – Password Attacks Observed on SCADA Network VPN Web Clients

Author: Chase Snow

Created: Tuesday, October 8, 2024 - 18:25

Categories: Cybersecurity, Federal & State Resources, OT-ICS Security

The Colorado Information Analysis Center (CIAC) recently shared intelligence with WaterISAC regarding password attack activity targeting the SCADA networks of a water sector entity. WaterISAC is sharing this TLP:CLEAR report (attached below) for member awareness of targeted attacks in the water sector.

A water sector entity in Colorado has reported suspicious activity where their SCADA networks were targeted by cyber attackers. A number of accounts within their SCADA network became temporarily inaccessible due to a vulnerability that allowed access to a VPN portal login page, allowing attackers to conduct password attacks against the accounts on the SCADA network.

WaterISAC urges members to monitor their firewall and EDR appliances if applicable for suspicious activity and to follow the recommendations included in the report.

Recommendations From the Report:

  • Assess the necessity of maintaining web-accessible VPN portals exposed to the internet.
  • Consider disabling non-essential access points to reduce the risk of password-based attacks.
  • Aim to minimize access points to sensitive infrastructure.
  • Ensure strict controls are implemented for any remaining access points to critical systems.

Report Suspicious Activity

WaterISAC encourages all utilities that have experienced malicious or suspicious activity to email an*****@*******ac.org, call 866-H2O-ISAC, or use the confidential online incident reporting form. Confidentially reporting to WaterISAC helps utilities and stakeholders maintain awareness of the threat environment of the sector. Additionally, to report incidents or suspicious activity to the FBI, contact your local field office at www.fbi.gov/contact-us/field-offices or the 24/7 Cyber Watch (CyWatch) at (855) 292-3937 or Cy*****@*bi.gov. You can also report activity to CISA, via its online tools, at (888)282-0870, or ce*****@******hs.gov.

Access the full report below

Attached Files:

(TLP_CLEAR) SCADA Network VPN Web Clients Targetted by Password Attacks

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar