Texas Water Utility Ransomware: Why TX Water Systems Are in the 2026 Crosshairs
CyberArmyofRussia_Reborn caused Muleshoe, TX water tank to overflow for 30–45 minutes via an exposed Unitronics PLC and default password. NTMWD (2.2 million people, 13 cities) lost 33,844 files to Daixin Team ransomware. 7 named TX water incidents in 18 months. Here is what every TX water district, MUD, and SUD needs to know — and do.
Research verified across 40+ source citations. Sources include CISA, FBI, EPA, DOJ Treasury, Mandiant, Dragos, AP News, Texas Tribune, WaterISAC, and published incident reports. Last updated June 26, 2026.
In This Brief
- Why TX Water Utilities Are in the 2026 Crosshairs
- The Muleshoe, Texas Water Tower Incident — What Actually Happened
- Aliquippa PA: The Canary in the Coal Mine for TX SUDs
- The TCEQ + EPA Regulatory Stack Post-2024
- Why Generalist MSPs and Antivirus Cannot Cover ICS/SCADA
- What a 30-Minute OT Response SLA Looks Like During a Tank Overflow
- CoreRecon's TX Water Utility Security Playbook
- Next Steps — Free Posture Assessment and Threat Brief
Why TX Water Utilities Are in the 2026 Crosshairs
Four forces have converged to make Texas water systems a priority ransomware target in 2026 — nation-state ICS targeting, ransomware-as-a-service commoditization, AWIA enforcement with financial teeth, and SUD governance gaps that create structural vulnerability. If you manage cybersecurity for a TX water district and have not mapped these four forces to your own exposure, you are operating blind.
1. Nation-state actors have moved from IT to OT targeting
In January 2024, CyberArmyofRussia_Reborn (CARR) — a front organization for Russian GRU Unit 74455 (Sandworm/APT44) — executed a coordinated campaign against Texas Panhandle water systems. CNN | AP News. The group accessed HMI interfaces, manipulated valve and pump controls, and caused physical disruption (tank overflow) at Muleshoe, Abernathy, Lockney, and Hale Center simultaneously. Wired. The U.S. Treasury sanctioned CARR leader Yuliya Pankratova and chief hacker Denis Degtyarenko in July 2024. Treasury Press Release. Mandiant linked CARR directly to Sandworm — the same GRU unit that executed the 2015 and 2016 Ukraine blackouts (1.4M and 700K customer outages). CyberScoop.
This is not hacktivism. This is state-directed ICS disruption with physical consequences.
2. Ransomware-as-a-service has commoditized water sector attacks
Daixin Team — a ransomware-as-a-service group — targeted the North Texas Municipal Water District (NTMWD) in November 2023. NTMWD serves 2.2 million people across 13 cities in Collin, Dallas, Denton, Hopkins, Hunt, Kaufman, Rains, Rockwall, and Tarrant counties. Daixin exfiltrated 33,844 files including operational data, member communications, and sensitive infrastructure information. Resecurity. The lesson: ransomware groups are no longer treating water utilities as too small to be worth the effort. A district serving 2.2M people represents high-value extortion leverage with minimal security investment to exploit.
Other named 2024 water sector incidents include Veolia North America (January 2024, 550 communities, 2.2 billion gallons/day, ransomware disruption), American Water Works (October 2024, 14M customer accounts, SEC 8-K filed, billing paused), and Arkansas City, Kansas (September 2024, manual operations required, FBI/DHS investigation). CSO Online.
3. AWIA Section 2013 enforcement has real financial consequences
The America's Water Infrastructure Act (AWIA), signed October 23, 2018, mandates Risk and Resilience Assessments (RRAs) and Emergency Response Plans (ERPs) for all community water systems serving more than 3,300 people. The second compliance cycle is now active with the June 30, 2026 RRA certification deadline for systems serving 3,301–49,999 people — this is the deadline most TX MUDs and mid-sized SUDs are facing. EPA AWIA. EPA can assess civil penalties of $25,000 per day for non-compliance.
The critical gap: most AWIA RRAs submitted to EPA contain boilerplate cybersecurity sections that do not adequately address OT-specific threats. AWIA requires RRAs to cover the security of "electronic, computer, or other automated systems" — PLCs, SCADA networks, HMIs, and remote access paths. An RRA that does not examine PLC configurations, HMI exposure, network segmentation, or OT-specific threat vectors is not a compliant RRA.
4. SUD governance structure creates structural security gaps
Special Utility Districts (SUDs) in Texas are often governed by elected boards with minimal cybersecurity expertise and IT staff counts that make dedicated security operations impossible. The typical TX SUD operates with one or two IT staff managing billing, compliance, and operations technology simultaneously. The convergence of IT (billing, email, accounting) and OT (SCADA, PLCs, treatment systems) in small districts creates attack surface that nation-state actors and ransomware groups specifically target because it is easy to exploit and difficult to defend.
The Muleshoe, Texas Water Tower Incident — What Actually Happened
On January 18, 2024, Muleshoe, Texas (Bailey County, population ~5,000, Texas Panhandle) experienced a cyberattack on its water system. Hackers accessed the town's industrial control network via an exposed remote login portal and caused a water storage tank to overflow for approximately 30–45 minutes before operators manually intervened. CARR posted video evidence of its HMI/PLC access on Telegram. Texas Tribune | Lubbock Avalanche-Journal.
Attribution — confirmed GRU, not hacktivism
The FBI investigated. Mandiant linked CARR to Sandworm (APT44), Unit 74455 of Russian military intelligence, via shared Telegram channel infrastructure, YouTube channel, and operational patterns. CARR is assessed as a front organization directly controlled by Sandworm leadership. The Texan. Treasury sanctioned CARR leader Yuliya Vladimirovna Pankratova and chief hacker Denis Olegovich Degtyarenko in July 2024. Treasury. A federal grand jury indictment was unsealed against Ukrainian national Victoria Dubranova in January 2025 for her role in CARR — she was extradited and arraigned in December 2025. Treasury confirmed water losses at Abernathy and Muleshoe totaled tens of thousands of gallons. Fortune.
The attack chain — how they got in
CARR's entry vector at Muleshoe was a Unitronics Vision Series PLC with an exposed remote login portal and the default password never changed from installation. The attack chain:
- Scanned for internet-accessible Unitronics PLCs across the Texas Panhandle using Shodan
- Found Muleshoe PLC with remote login portal exposed and default credentials active
- Logged in via the portal and accessed the HMI interface
- Manipulated pump and valve controls to cause tank overflow
- Executed simultaneously at Abernathy, Lockney, and Hale Center — coordinated campaign, not opportunistic
The fundamental vulnerability: default credentials on a PLC with direct internet exposure. This is the same attack chain that hit Aliquippa, Pennsylvania three months earlier. It is reproducible across any TX water system running an exposed Unitronics PLC without credential rotation.
"Every Equipment 'Made In Israel' Is Cyber Av3ngers Legal Target."
— CyberAv3ngers (IRGC-linked), November 2023 — explaining motivation for targeting Israeli-built Unitronics PLCs
Aliquippa PA: The Canary in the Coal Mine for TX SUDs
Three months before Muleshoe — on November 28, 2023 — the Municipal Water Authority of Aliquippa, Pennsylvania experienced a cyberattack on its booster station PLC. The Iran-linked hacktivist group CyberAv3ngers (linked to Iran's Islamic Revolutionary Guard Corps) exploited two conditions: a default Unitronics PLC password (1111) that was never changed, and a PLC directly internet-accessible via Shodan queries. CISA Alert, November 28, 2023. CISA issued the alert within hours, warning all water sector operators to change PLC passwords and eliminate direct internet exposure.
Why TX SUDs face the same exposure:
Unitronics Vision Series PLCs are widely deployed across TX small and medium water systems — they are affordable, easy to program, and commonly used for pump station control, tank level monitoring, and treatment processes. At the time of the Aliquippa incident, Shodan queries showed 200+ exposed Unitronics PLCs in the U.S. — any representing a potential entry point. SecurityWeek. CISA's December 2024 joint fact sheet with EPA explicitly documented how threat actors had "demonstrated the capability to find and exploit internet-exposed HMIs with cybersecurity weaknesses easily" in 2024 incidents where pro-Russia hacktivists "caused water pumps and blower equipment to exceed their normal operating parameters." EPA/CISA HMI Fact Sheet, December 2024.
| Attack Vector | What the Actor Did | TX SUD Vulnerability |
|---|---|---|
| Default PLC password | Logged in with "1111" — never changed from installation | TX SUDs frequently do not change default PLC passwords |
| Internet-accessible PLC/HMI | Found via Shodan, accessed directly without VPN | TX SUDs expose HMI interfaces for vendor remote support |
| No MFA on remote access | Logged in with password only, no second factor | TX SUDs lack MFA on SCADA vendor portals |
| No IT/OT segmentation | Same network for IT and OT — pivoted freely | Small SUDs run IT and OT on same network |
CISA's specific recommendation for all water sector operators: use a non-default TCP port (not 20256), implement VPN + MFA for any remote access, and eliminate direct internet exposure for all PLCs and HMIs. CISA/EPA Top Cyber Actions Fact Sheet, February 2024. A single action — changing the default PLC password — would have prevented both the Aliquippa and Muleshoe attacks.
The Oldsmar, Florida template — lye dosing attack
The 2021 Oldsmar, Florida water treatment incident established the physical consequence template: an attacker accessed the HMI via TeamViewer and increased sodium hydroxide dosing from 100 ppm to 11,100 ppm — a 100x increase that would have been lethal. The plant operator reversed the change within minutes when a supervisor noticed the anomaly. Tampa Bay Times. The attack vector: TeamViewer on Windows 7 with shared credentials, no MFA, no firewall blocking remote access. Xage Security. For a TX water district with a weekend operator and no IT security training, there may be no one watching when the setpoint changes.
SCADA-Aware Monitoring for TX Water Utilities
CoreRecon's OT-aware SOC detects anomalous PLC commands before physical damage occurs. OT-trained analysts, 30-min SLA, SDVOSB, TX residency.
The TCEQ + EPA Regulatory Stack Post-2024
TCEQ Sanitary Survey — Cybersecurity Component Added
In March 2023, EPA issued guidance requiring cybersecurity to be incorporated into Sanitary Surveys — the periodic on-site inspections that TCEQ conducts of public water systems. EPA Cybersecurity Guidance, August 2024 revision. TCEQ's RCAP (Rural Capacity Assistance Program) Security Vulnerability Self-Assessment Guide for Water Systems provides a framework that TX SUDs can use to prepare for cybersecurity-related survey questions. TCEQ RCAP Guide.
AWIA Section 2013 — The Compliance Cliff
AWIA mandates RRAs and ERPs for all community water systems serving more than 3,300 people. Second cycle deadlines are now active:
| Population Served | RRA Deadline | ERP Deadline | TX Exposure |
|---|---|---|---|
| ≥ 100,000 | March 31, 2025 | September 30, 2025 | NTMWD, Trinity River Authority, others |
| 50,000–99,999 | December 31, 2025 | June 30, 2026 | Various regional water authorities |
| 3,301–49,999 | June 30, 2026 | December 31, 2026 | Hundreds of TX MUDs and SUDs — this is the TX majority |
The June 30, 2026 RRA certification deadline is the most significant near-term compliance obligation. Systems self-certify to EPA — there is no pre-approval, but EPA enforcement is active. OHM Advisors AWIA deadlines. The critical compliance gap: AWIA requires that RRAs address "electronic, computer, or other automated systems" — PLCs, SCADA networks, HMIs, remote access paths. Most RRAs delivered by non-OT-specialist engineering firms do not include adequate SCADA cybersecurity analysis.
TX HB 3834 + HB 3512 — Annual Cybersecurity Training Mandate
Texas HB 3834 (2019) requires annual cybersecurity training for government employees — SUDs and MUDs are public water systems subject to this requirement. HB 3512 (2023) added AI training requirements for certain government employees. Texas DIR. For SUD boards and staff, this means documented annual cybersecurity awareness training is a state-level legal obligation, not optional.
CISA Region 6 Free Services for TX Water Utilities
CISA provides free cybersecurity services to water sector entities: vulnerability scanning (vulnerability@cisa.dhs.gov), Regional Cybersecurity Advisors in CISA Region 6 (Dallas), and the Cybersecurity Performance Goals (CPGs) baseline. cisa.gov/water. EPA's RealWaterTA program offers confidential, no-cost gap analysis at epa.gov/cyberwater. These services do not require regulatory disclosure and are available to any TX water utility — the main constraint is awareness that they exist.
Why Generalist MSPs and Antivirus Cannot Cover ICS/SCADA
Generic MSSPs — including national providers that water district IT directors find when searching "managed security" — operate SOCs staffed primarily with IT security analysts. These analysts have no training on DNP3, Modbus, BACnet, or IEC 61850 protocols. They have no tools for SCADA-specific traffic analysis, no experience reviewing AWIA RRA cybersecurity evidence requirements, and no context for water sector OT operations. When a SOC sees SCADA traffic in its SIEM, a generic MSSP analyst will typically alert on it as anomalous or block it as suspicious — not recognize it as legitimate OT traffic. NACWA 10 Steps to Reduce SCADA Risk, October 2024.
The dwell time problem for water OT environments
The global average breach lifecycle is 241 days (IBM Cost of a Data Breach 2025). For water OT environments, this gap is even more dangerous: the OT layer has no EDR equivalent, and field-level PLC command monitoring is nonexistent in most generic MSSP offerings. Dragos Water Cybersecurity. A threat actor probes internet-facing HMI ports across TX water districts, finds a Unitronics PLC with default credentials, logs in, and waits. For weeks. They map the OT network, identify the tank overflow logic, understand the backup procedures. When they act — manipulating the setpoint at 3 AM Saturday — the water district discovers the problem when a driver notices the water tower overflowing at 7 AM. By then, physical damage has occurred and the PLC may be in a fault state requiring manual reconfiguration to restore service.
Pricing benchmark for water utility security
| Vendor Type | Typical Pricing | Water OT Coverage |
|---|---|---|
| Big-4 Consulting (Deloitte, Accenture, PwC) | $250K–$2M+ annually | No OT detection, no AWIA RRA OT analysis, priced for IOUs |
| OT-Native MSSP (Dragos, Claroty) | $500K–$5M+ annually | OT-native but priced for large water authorities, not TX SUDs |
| National Consumer MSSP / Antivirus | $500–$5,000/month | No SCADA coverage, no AWIA compliance, no OT alert triage |
| CoreRecon | $89/endpoint/month | OT-aware monitoring, AWIA RRA support, 30-min SLA, SDVOSB, TX residency |
A 50-employee TX water district with 80 endpoints pays $7,120/month for CoreRecon vs. $250,000+/year for a Big-4 retainer alone. Against a $200K–$2M ransomware incident cost, the annual CoreRecon cost is recovered on the first incident prevented.
What a 30-Minute OT Response SLA Looks Like During a Tank Overflow
CoreRecon's 30-minute SLA is specifically designed for the water OT threat environment — where physical consequences accumulate in minutes and rural districts have minimal overnight staffing. Verizon 2025 DBIR.
The 30-minute window during a PLC manipulation event
| Time | Action | Physical Context |
|---|---|---|
| 0–5 min | Anomalous PLC command detected by OT network monitoring. Alert generated and routed to SOC. Analyst confirms whether alert coincides with known OT threat patterns (CARR/Sandworm, CyberAv3ngers, Daixin). | Water tank level still normal. Attack in progress, not yet causing physical impact. |
| 5–15 min | Human analyst reviews alert, correlates with Unitronics Vision Series command signatures. Confirms command pattern matches CARR-style manipulation (not a legitimate setpoint change from on-site operator). | District night operator has no SCADA monitoring training. Cannot self-diagnose. Generic MSSP alert ticket would sit for 4+ hours. |
| 15–30 min | Analyst calls district emergency contact. On-call operator instructed to switch to manual operations. PLC isolated from network. TCEQ incident notification requirements reviewed. FBI IC3 and CISA reporting initiated. | Tank overflow avoided. Manual operations maintain water service. No physical damage, no regulatory panic, no board briefing on a 3-day outage. |
The contrast: a national MSSP with a 4-hour response SLA means the attacker has a 3.5-hour head start before the district gets an analyst on the phone. For a rural TX water district with a single part-time IT staff member, that gap is the difference between a 30-minute contained incident and a multi-day outage with physical damage, TCEQ notification obligations, and reputational harm.
"At 3 AM Saturday, there is no one watching the HMI. That's when the setpoint changes. The operator finds out at 7 AM when the water tower is overflowing."
— Water sector OT security professional, WaterISAC membership briefing, 2024
CoreRecon's TX Water Utility Security Playbook
CoreRecon offers three service tiers designed for TX water utilities at every scale, from small SUDs serving a few thousand customers to regional water authorities serving millions:
| Tier | Price | OT Coverage | SLA | Best For |
|---|---|---|---|---|
| Sentinel | $89/endpoint/mo | Passive SCADA monitoring, PLC command anomaly detection, IT/OT traffic analysis | 30-min OT response | TX MUDs/SUDs needing OT-aware SOC coverage and AWIA RRA support |
| Fortress | $109/endpoint/mo | Sentinel + IT/OT segmentation architecture, vulnerability management, AWIA RRA gap assessment | 15-min OT response | Mid-sized water authorities with active compliance deadlines (June 2026 RRA) |
| Command | $129/endpoint/mo | Fortress + on-site incident response, annual OT security assessment, direct TCEQ/AWIA documentation support | 10-min OT response | Regional water authorities (NTMWD-class) with multi-city service areas |
SDVOSB advantage for federally funded water projects
CoreRecon's Service-Disabled Veteran-Owned Small Business (SDVOSB) status opens funding pathways that commercial MSSPs cannot access for TX water utilities:
- EPA Drinking Water State Revolving Fund (DWSRF) — Texas TWDB administers DWSRF with set-asides for cybersecurity planning. CoreRecon services can be bundled into DWSRF project scopes for utilities undertaking AWIA compliance-driven upgrades.
- USDA Rural Development loans and grants for water and wastewater infrastructure in communities under 10,000. Cybersecurity is an eligible expense under pre-development and grant programs.
- CISA Regional Cybersecurity Advisors in CISA Region 6 (Dallas) — warm referral pathway to TX water sector clients. SDVOSB status with documented water sector expertise enables leveraging the CISA advisor relationship.
- TX TCEQ SB 1034 implementation contracts — as TCEQ develops rules for SCADA connection restrictions by September 1, 2027, demand for qualified cybersecurity vendors will increase significantly. CoreRecon is positioned for these contracts.
OT-Aware SOC for TX Water Utilities — $89/endpoint/month
30-min response SLA. PLC command anomaly detection. AWIA RRA gap assessment. SDVOSB. TX residency. No commitment required for initial assessment.
Next Steps — Free $2,500 Posture Assessment and Threat Brief
CoreRecon offers a no-cost 30-day security posture assessment for qualifying TX water utilities — delivered by a water-sector-trained team with TCEQ regulatory context and SCADA-specific technical analysis. /for-water-utilities | /assessment | /compare.
OT Asset Inventory and SCADA Exposure Scan
Identify all PLCs, HMIs, RTUs, and SCADA network segments. Audit internet exposure via external perspective (Shodan). Map findings to AWIA §2013 cybersecurity requirements. This is the prerequisite for AWIA RRA compliance and the foundation of OT security.
PLC Credential and Remote Access Path Audit
Identify default credentials on Unitronics, Siemens, Allen-Bradley, or other PLCs. Document all remote access paths (vendor VPNs, cellular modems, exposed HMI ports). Disable or secure everything not provably needed. This single action would have prevented both Muleshoe and Aliquippa.
AWIA RRA Gap Analysis — OT-Inclusive
Evaluate your existing or planned RRA for AWIA §2013 compliance — specifically whether the cybersecurity section addresses PLC security configurations, HMI exposure, IT/OT network segmentation, and OT-specific threat vectors. Map findings to EPA guidance and TCEQ sanitary survey expectations.
Incident Response Plan Assessment — TCEQ + FBI + CISA Notification
Review IR plan for current status, specific OT incident procedures, and notification chain documentation. For water systems, TCEQ notification, FBI IC3 reporting, and CISA reporting have specific timelines — having these documented before an incident matters.
Ransomware Resilience Scoring and Recovery Time Objective Analysis
Evaluate backup integrity, offline/air-gapped SCADA configuration backup status, and recovery time estimates. Compare against 30-minute CoreRecon response SLA. Calculate ROI against potential $200K–$2M ransomware cost.
Source: CoreRecon Research, Report #1471556 (V38 TX Water Utilities & SUDs Threat Brief, 40 verified sources). CoreRecon is a Service-Disabled Veteran-Owned Small Business (SDVOSB). OT-aware SOC coverage for Texas water utilities and special utility districts. TX residency. 30-minute SLA. Contact corerecon@polsia.app or (800) 955-2596.