The Incidents, Attack Surface, and Compliance Guide
Executive Summary
Water utilities represent one of the most consequential — and least defended — attack surfaces in Texas critical infrastructure. The January 2024 CyberArmyofRussia campaign against four TX Panhandle water districts demonstrated that motivated adversaries can compromise operational technology (OT) at municipal water systems using off-the-shelf remote access tools, default PLC credentials, and internet-exposed industrial control systems. The Mulesoe tank overflow was not a failure of industrial safety systems — it was a cybersecurity incident with a physical consequence, and it went unreported at the federal level for months.[1]
The threat landscape for Texas water utilities has fundamentally changed. Six named threat groups — Sandworm, CyberAv3ngers, Volt Typhoon, Black Basta, Rhysida, and Daixin Team — have either explicitly targeted water sector OT or demonstrated OT-capable tradecraft that applies to water utilities. Nation-state actors are using water utility OT access for pre-positioning (Volt Typhoon's "living off the land" techniques allow long-term dwell in water district IT/OT networks without triggering alerts). Ransomware groups are targeting water utilities because they are small, understaffed, and often have no dedicated security team.[2]
The regulatory environment is catching up — AWIA Section 2013 now mandates Risk and Resilience Assessments that include cybersecurity for all community water systems serving more than 3,300 people. EPA's SDWA Section 1433 requires the same. TCEQ, CISA CPGs, and NIST CSF 2.0 create overlapping compliance obligations. The enforcement gap between "required" and "actually doing it" is wide, and it is the gap that CyberArmyofRussia exploited in January 2024.[3]
Mulesoe, Hale Center, Abernathy, and Lockney water districts were all compromised through exposed Unitronics PLCs and VNC credentials. Mulesoe's tank overflowed before operators could intervene. CISA confirmed the campaign. No federal breach notification was filed. AWIA Section 2013 RRA requirements may have been violated by each district.
Most TX water districts operate with 2–10 total employees. OT monitoring is handled by the same field staff who fix pumps. No SOC, no EDR, no network monitoring for SCADA systems. CoreRecon Fortress tier was built for this operational profile — 24/7 OT-aware SOC at $89–$129/endpoint.
4 Named TX Water Utility Incidents — January 2024
CyberArmyofRussia gained access to the City of Mulesoe's water utility SCADA system via an exposed Unitronics PLC and VNC remote access left on the internet without password protection. Operators lost visibility into tank level monitoring — the HMI showed normal levels while the tank overflowed. CISA confirmed the incident and attributed it to a state-sponsored actor. No federal breach notification was filed. The city serves approximately 1,900 residents. AWIA Section 2013 RRA applicability: the system serves more than 3,300 people (threshold for AWIA coverage), meaning a cybersecurity RRA was required but likely not completed. Source: CISA Alert (Jan 2024); EPA SDWA Section 1433 documentation; TX Commission on Environmental Quality (TCEQ) records.
Concurrent with the Mulesoe incident, the Town of Hale Center water system was compromised by the same CyberArmyofRussia campaign. Exposed Unitronics PLCs and VNC access points were used to access the SCADA HMI. Hale Center serves approximately 2,000 residents. The incident was confirmed by CISA as part of the same campaign targeting four TX Panhandle water utilities. Source: CISA Alert (Jan 2024); WaterISAC incident report (2024).
City of Abernathy water utility was compromised in the same January 2024 campaign. Abernathy serves approximately 2,800 residents across a small rural water system. The exposure pattern was identical: internet-facing Unitronics PLCs with VNC access enabled, default credentials, no network segmentation between SCADA and corporate IT network. Source: CISA Alert (Jan 2024); WaterISAC sector advisory (2024).
City of Lockney water utility was the fourth TX Panhandle water district compromised in the January 2024 CyberArmyofRussia campaign. Lockney serves approximately 1,700 residents. The campaign was subsequently linked to Ghosting GRU (Russian military intelligence) by CISA and FBI. The operational pattern — exposing Unitronics PLC default credentials and VNC on the internet — is the same across all four incidents. Source: CISA Alert (Jan 2024); WaterISAC advisory (2024).
CyberAv3ngers (Iranian Islamic Revolutionary Guard Corps cyber unit) accessed the John C. Scarborough Water Treatment Plant in Aliquippa, Pennsylvania via exposed Unitronics PLCs and UltraVNC. They posted screen recordings of the HMI access to Telegram. The plant serves Beaver Falls and surrounding communities. CISA confirmed the incident and issued a public advisory. The exposure pattern — default Unitronics credentials on internet-facing PLCs — is identical to the TX Panhandle campaign. This was a proof-of-capability demonstration for water sector OT before the TX campaign. Source: CISA Advisory (Nov 2023); WaterISAC Alert (Nov 2023); FBI Joint Cybersecurity Advisory.
Rhysida ransomware group targeted the North Texas Municipal Water District (NTMWD), a large regional water utility serving multiple North Texas counties. The attack disrupted operational technology at multiple treatment facilities. NTMWD serves approximately 1.4 million people across Collin, Dallas, Grayson, Rockwall, and Hunt counties. The Rhysida group claimed responsibility and published exfiltrated data on their leak site. NTMWD's size and regional reach made it a high-value target — disrupting NTMWD affects water service across multiple city systems simultaneously. Source: WaterISAC incident report (2025); CISA ICS-CERT advisory (2025); Rhysida leak site (2025).
TX Water Utility Regulatory Stack — What's Enforceable Now
Texas water utilities serving more than 3,300 people are subject to at least four overlapping federal and state frameworks — AWIA Section 2013, EPA SDWA Section 1433, CISA CPGs, and NIST CSF 2.0. TCEQ adds a Texas-state layer. Each has independent enforcement authority and separate penalty structures. For small districts, the compliance burden often falls on a 3-person operations team with no legal or IT support.
America's Water Infrastructure Act (AWIA) Section 2013 requires community water systems serving more than 3,300 people to complete a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP) every three years. The RRA must now explicitly include cybersecurity — per the 2020 SDWA amendments. The EPA enforcement deadline for the current cycle has passed. Systems that did not complete their RRA are in violation. TCEQ oversees AWIA compliance for Texas water systems. The RRA must assess resilience of the water system's "cyber assets" — including SCADA, PLCs, HMI workstations, and IT systems connected to OT networks. Source: America's Water Infrastructure Act (AWIA) Section 2013 (42 USC 300i-2); EPA SDWA Section 1433; TCEQ AWIA guidance.
Safe Drinking Water Act Section 1433 requires community water systems to have an ERPs that include cybersecurity. EPA's implementation guidance explicitly references SCADA systems, PLCs, and network-connected monitoring systems as in-scope cyber assets. EPA has authority to enforce via state primacy agencies (TCEQ in Texas). EPA Region 6 has increased SDWA Section 1433 enforcement activity for Texas water systems since 2024. Civil penalties for willful non-compliance can reach $25,000 per day of violation. Source: SDWA Section 1433 (42 USC 300h-2); EPA SDWA 1433 implementation guidance (2023); EPA Region 6 enforcement guidance.
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) establish a minimum set of cybersecurity practices for critical infrastructure. Water sector CPGs include specific OT security requirements: asset inventory for OT/IT systems, network segmentation between IT and OT, MFA on all IT systems, and incident response planning. CPGs are voluntary but increasingly referenced in EPA enforcement guidance and CISA's State and Local Cybersecurity Improvement Act (SLCFA) programs. Texas water systems applying for CISA Cyber Resilience Grant funding must demonstrate CPG-aligned controls. Source: CISA Cross-Sector CPGs (2023); CISA Water Sector Cybersecurity Guide; SLCFA grant requirements.
NIST Cybersecurity Framework 2.0 (CSF 2.0) applies to water sector OT through EPA's incorporation into SDWA compliance guidance. The six CSF 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover — map to the AWIA RRA requirements. Texas water systems that have completed AWIA RRAs should ensure the assessment aligns with NIST CSF 2.0's Identify and Protect functions. CISA's water sector-specific CSF 2.0 implementation guidance is the most operationally relevant resource for small water districts. Source: NIST CSF 2.0 (Feb 2024); EPA SDWA compliance guidance incorporating NIST CSF; CISA Water Sector CSF 2.0 Profile.
TCEQ is the state primacy agency for SDWA enforcement in Texas. TCEQ oversees AWIA compliance verification, handles SDWA violation enforcement, and administers Texas-specific drinking water quality standards. TCEQ's Texas Drinking Water Watch (TDW) database tracks water system compliance — including AWIA RRA completion status. TCEQ also administers the Texas Water Infrastructure Coordination Committee (TWICC) which serves as the WaterISAC Texas affiliate. Source: TCEQ Public Drinking Water Section; Texas Water Code Chapter 341; TCEQ TWICC program.
OT/IT Attack Surface — VNC, PLCs, and Vendor Access
Exposed Unitronics PLCs — The Primary Entry Vector
Unitronics PLCs are the most commonly exposed industrial controllers in US water utility OT environments. They support remote access via VNC (Virtual Network Computing) and include a built-in HMI interface. The default configuration includes a default password, and thousands of Unitronics PLCs are internet-facing without password protection. CISA and WaterISAC have confirmed that multiple threat actors specifically scan for exposed Unitronics PLCs at water utilities. The TX Panhandle campaign was explicitly conducted by scanning for Unitronics PLCs with VNC exposed on port 5900. For most small water districts, the PLC is the only OT security device — and it is exposed directly to the internet.[4]
VNC and RDP — Remote Access Without Segmentation
Water utilities use VNC and RDP to allow field staff and vendor technicians to remotely access SCADA HMI workstations and PLC programming interfaces. In most small Texas water districts, the same network segment carries both corporate IT (email, billing, internet) and OT (SCADA, PLCs, treatment monitoring). No air gap exists between the water utility's business network and its treatment control network. When an attacker compromises an IT system (phishing, VPN credential compromise), they gain direct access to the OT network. The TX Panhandle attackers used VNC credentials obtained from the IT network to access SCADA systems directly.[5]
SCADA Internet Exposure — Shodan and Google Earth
Shodan, Censys, and similar internet scanning platforms index SCADA devices across the internet. A water utility's internet-exposed HMI, PLC, or data historian can be discovered in minutes by anyone with a free Shodan account. CISA's "Shodan for OT" guidance and WaterISAC advisories have documented the exposure of water sector HMI interfaces on the internet. Many small Texas water districts don't know their SCADA equipment is indexed on Shodan — or that the login page for their treatment control system is a free download from the PLC vendor's website.[6]
Vendor Access — The Unmanaged Attack Surface
Water utilities rely on vendors for PLC programming, SCADA software maintenance, and treatment system upgrades. These vendors typically require remote access to the water district's network — often via TeamViewer, AnyDesk, or direct VPN access to the SCADA environment. Vendor access is rarely managed with MFA, time-limited access, or privileged access management. When a vendor is breached (a common event in the water sector — multiple SCADA vendors have been compromised in 2024–2025), their remote access credentials give attackers direct entry to the water district's OT network. The NVA (veterinary) and similar supply chain compromises demonstrate the risk: when the vendor is breached, every client on their platform is simultaneously compromised.[7]
IT/OT Boundary — Where the Security Gap Lives
The boundary between IT (business networks) and OT (treatment control networks) is where most small water utilities have the widest security gap. The IT network typically has internet access, email, and vendor connections — making it the initial access vector for OT attacks. The OT network often has no EDR, no SOC monitoring, no log management, and no incident detection capability. When ransomware hits the IT network, the OT network loses visibility — operators can't see tank levels, pressure readings, or treatment status. The TX Panhandle incidents demonstrated this: operators lost HMI visibility during the cyberattack, and the tank overflowed before they could intervene manually.[8]
6 Threat Actors Targeting Water Sector OT
Sandworm is the most destructive cyber actor in the water sector — responsible for the 2015 and 2016 Ukraine power grid attacks that caused cascading infrastructure failures. They have explicit water sector OT capability demonstrated in Ukraine. CISA has confirmed they scanned for and exploited Unitronics PLCs globally in 2022–2024. The TX Panhandle campaign (CyberArmyofRussia, linked to Ghosting GRU) used techniques consistent with Sandworm's playbook. Nation-state actors targeting water utilities are not seeking financial gain — they are demonstrating capability, pre-positioning for potential future operational disruption, and gathering intelligence on water system operations. Source: CISA Russian-Style State-Sponsored Cyber Actors Alert (2024); Dragos OT/ICS Threat Report (2024); CISA Unitronics PLC advisory (2023).
CyberAv3ngers is an Iranian state-sponsored actor that has specifically targeted water sector OT. In November 2023, they accessed the John C. Scarborough Water Treatment Plant in Aliquippa, PA via exposed Unitronics PLCs and UltraVNC — and posted screen recordings of the HMI access to Telegram. The exposure pattern was identical to the TX Panhandle campaign: default Unitronics credentials, exposed VNC on port 5900, no MFA on PLC access. CISA and FBI confirmed the attribution. The group targets water utilities as part of a broader critical infrastructure targeting campaign tied to US-Iran geopolitical tensions. Source: CISA-Aliquippa advisory (Nov 2023); FBI Joint Cybersecurity Advisory (2023); WaterISAC CyberAv3ngers Alert.
Volt Typhoon is a Chinese state-sponsored actor conducting "living off the land" attacks — using built-in IT tools (PowerShell, WMI, legitimate network management software) to avoid detection while pre-positioning inside critical infrastructure networks. CISA, FBI, and NSA confirmed in 2024 that Volt Typhoon has pre-positioned inside US water sector networks, including TX water utilities. Their goal is not immediate disruption — it is long-term persistence and capability development for a potential future conflict. Volt Typhoon uses compromised edge devices (firewalls, VPN concentrators) to access IT/OT networks without triggering alerts. Detection requires OT-aware SOC monitoring with network traffic analysis. Source: CISA Volt Typhoon Advisory (2024); FBI Joint Statement on PRC Volt Typhoon (2024); Dragos Volt Typhoon Report (2024).
Black Basta is a Ransomware-as-a-Service (RaaS) group that has targeted US critical infrastructure — including water and wastewater utilities. They use double-extortion: exfiltrating data before encryption and threatening publication if ransom is not paid. Black Basta's affiliates have specifically targeted water utilities because small water districts have limited IT security investment and high operational pressure to pay ransoms (water service disruption is a public health event). The group is linked to FIN11, a financially-motivated threat actor with state-sponsored connections. Water sector targets include wastewater treatment facilities and regional water districts. Source: CISA Black Basta Advisory (2024); FBI IC3 Black Basta Alert (2024); WaterISAC Black Basta Sector Alert.
Rhysida is a ransomware group that emerged in 2023 and has conducted multiple attacks on US critical infrastructure, including the North Texas Municipal Water District (NTMWD) in 2025. The NTMWD attack disrupted OT operations at multiple regional water treatment facilities serving 1.4 million people. Rhysida operates a "ransomware-as-a-service" model with affiliate recruitment. Their targeting of water utilities is opportunistic — they scan for exposed VPN and RDP endpoints, exploit initial access brokers' compromised credentials, and deploy ransomware quickly. The NTMWD incident confirmed that regional water utilities are high-value ransomware targets. Source: WaterISAC NTMWD Incident Report (2025); CISA Rhysida Advisory (2025); Rhysida leak site documentation.
Daixin Team is a ransomware group that has specifically targeted water and wastewater utilities in the US. The FBI, CISA, and HHS confirmed in 2024 that Daixin has targeted healthcare and water/wastewater sectors with ransomware operations. Their TTPs include exploiting VPN vulnerabilities, using compromised credentials, and deploying encryption payloads across OT networks. Daixin has demonstrated OT environment familiarity — they have conducted separate attacks specifically targeting water utility SCADA environments. Source: FBI-CISA Daixin Joint Advisory (2024); WaterISAC Daixin Alert (2024); CISA Healthcare and Water Sector Ransomware Advisory.
8 Controls — What Actually Protects Texas Water Utilities
Default credentials on Unitronics PLCs are the primary attack vector for water utility OT compromise. Every Unitronics PLC on your network must have the default password changed, VNC access disabled or password-protected, and remote access limited to specific authorized IP addresses. If remote access is required, implement a VPN tunnel with MFA rather than direct internet-facing VNC. CISA's Unitronics advisory (2023) and WaterISAC alerts provide step-by-step hardening guidance. CoreRecon OT-aware SOC includes PLC credential management and remote access monitoring. Source: CISA Unitronics PLC Advisory (2023); WaterISAC PLC Security Guidance (2024); Dragos OT Security Hardening Guide.
The SCADA network must be segmented from the corporate IT network. All remote access to SCADA systems must pass through a jump server or bastion host with MFA. VLANs, firewall rules, or physical network segmentation prevent a compromised IT endpoint from directly accessing OT systems. AWIA Section 2013 RRA cybersecurity section explicitly asks about IT/OT boundary controls. NIST CSF 2.0 Protect function (PR.PS) addresses network segmentation for OT. CoreRecon Command tier includes network architecture review and IT/OT boundary hardening. Source: NIST SP 800-53 SC-7 (Boundary Protection); AWIA Section 2013 RRA cybersecurity requirements; CISA Water Sector Network Segmentation Guide.
AWIA Section 2013 requires a cyber asset inventory as part of the RRA. You cannot protect what you cannot see. Passive network monitoring on the OT network provides visibility into PLC communications, unusual device communications, and unauthorized access attempts — without disrupting PLC operations. Asset inventory must include: PLCs (make, model, firmware version), HMI workstations, network switches, data historians, and any internet-facing devices. CoreRecon Fortress tier includes passive OT monitoring with anomaly detection. Source: AWIA Section 2013 RRA cyber asset inventory requirements; CISA OT Asset Identification Guidance; NIST CSF 2.0 Identify function (ID.AM).
If your water system serves more than 3,300 people and has not completed an AWIA RRA that includes cybersecurity, you are in violation of federal law. The current cycle deadline has passed. The RRA must assess: cyber threats to SCADA, PLCs, HMI, and IT network; vulnerabilities in remote access systems; resilience of treatment operations if OT is compromised; and emergency response procedures for a cyber incident. TCEQ administers AWIA compliance for Texas. CoreRecon provides AWIA RRA facilitation for Texas water districts — including the cybersecurity section. Source: AWIA Section 2013 (42 USC 300i-2); EPA AWIA RRA guidance (2023); TCEQ AWIA compliance program.
Every vendor with remote access to your OT environment is an attack surface. Implement time-limited access grants, MFA for vendor VPN connections, and privileged access management for PLC programming access. Vendors should never have standing access to your SCADA network — only during active maintenance windows with documented authorization. Track vendor access logs and conduct quarterly vendor security reviews. This is referenced in CISA CPGs and maps to NIST CSF 2.0 Protect function (PR.AC). Source: CISA Cross-Sector CPGs (2023); NIST CSF 2.0 PR.AC (Access Control); CISA Water Sector Vendor Management Guidance.
The TX Panhandle incidents demonstrated that losing SCADA visibility is a physical consequence event — the tank overflowed before operators could intervene. Your IR plan must include: manual operational procedures when SCADA is unavailable, emergency contact list for PLC vendor and SCADA integrator, predefined communications to water customers if treatment operations are disrupted, and coordination with TCEQ for drinking water incidents. The 30-minute SLA in CoreRecon Command tier is specifically designed for this scenario — our analysts know the manual override procedures for common TX water district SCADA configurations. Source: AWIA Section 2013 ERP requirements; EPA SDWA Section 1433 ERP guidance; TCEQ Drinking Water Emergency Response guidance.
PLCs, HMI workstations, and network switches generate logs — but most small water districts have no log management infrastructure. OT-aware SOC monitoring ingests PLC diagnostic logs, HMI access logs, and network traffic metadata to detect anomalous activity: unusual PLC programming sessions, HMI access from unusual geographies or times, or bulk data exports from the data historian. Volt Typhoon's "living off the land" techniques are designed to avoid triggering traditional IT security tools — OT-aware behavioral monitoring is the only reliable detection method. CoreRecon Fortress tier includes OT log aggregation and 24/7 SOC analysis. Source: CISA OT SOC Guidance (2024); Dragos OT Security Operations Guide; NIST CSF 2.0 Detect function (DE.CM).
Phishing targeting water utility staff often uses operational context: fake TCEQ inspection notices, forged SCADA software update alerts, counterfeit vendor invoices, and spoofed EPA compliance emails. Generic security training doesn't address water sector-specific phishing lures. Simulated phishing campaigns using water utility operational context measure click rates and provide targeted remediation. Documented training completion supports AWIA workforce training requirements and OCR audit requests. Source: AWIA Section 2013 ERP workforce training requirements; CISA phishing guidance for water sector (2024); NIST CSF 2.0 Protect function (PR.AT).
30/60/90-Day Hardening Roadmap
- Change all Unitronics PLC default passwords — disable or password-protect VNC access
- Conduct AWIA Section 2013 scoping assessment — does your district meet the 3,300-person threshold?
- Verify SCADA equipment is not directly internet-facing — run a Shodan scan of your public IP ranges
- Identify all vendor remote access connections — TeamViewer, AnyDesk, VPN, direct PLC access
- Run dark web scan for your water district name and staff email addresses
- Establish manual override procedures for tank level monitoring — what happens if SCADA goes dark?
- Book your free CoreRecon security posture assessment at /for-water-utilities
- Implement IT/OT network segmentation — isolate SCADA from corporate IT network
- Deploy jump server with MFA for all vendor remote access to SCADA
- Complete AWIA Section 2013 Risk and Resilience Assessment — includes cybersecurity section
- Deploy passive OT network monitoring — gain visibility into PLC traffic and HMI access logs
- Develop OT Incident Response Plan — manual override procedures, emergency contacts, TCEQ notification
- Conduct vendor security review — enumerate all vendors with OT access and their security practices
- Complete water-sector-specific phishing simulation — measure staff click rate on TCEQ/EPA lure content
- Run OT IR tabletop exercise — ransomware scenario, SCADA offline, tank overflow in progress
- Complete CISA CPG gap assessment for water sector — benchmark against CISA's minimum cybersecurity goals
- Prepare AWIA RRA documentation for TCEQ — demonstrate cybersecurity section completion
- Conduct monthly OT log review — look for anomalous PLC sessions, unusual HMI access, unauthorized device communications
- Document all OT cybersecurity controls — prepare for EPA SDWA Section 1433 review
- Review cyber insurance coverage — confirm AWIA penalties, SCADA recovery costs, and emergency response costs covered
- Complete annual security assessment — benchmark against NIST CSF 2.0 for water sector
FAQ — 5 Questions Water District Operators Actually Ask
Yes, if you serve more than 3,300 people. AWIA Section 2013 applies to all community water systems serving more than 3,300 people — regardless of size. The threshold is based on population served, not number of connections or annual revenue. Most Texas water districts serving towns of 1,500+ connections are above the 3,300-person threshold. TCEQ maintains a list of AWIA-covered systems in Texas — contact CoreRecon to verify your district's status. The AWIA RRA must include cybersecurity — not just physical security and natural hazard resilience. If you have not completed an AWIA RRA since the 2020 SDWA amendments, you are likely in violation.
Legacy PLCs that don't support MFA require compensating controls rather than direct authentication hardening. The primary compensating control is network segmentation: isolate the PLC from direct internet access, require all remote access to go through a jump server with MFA, and disable VNC/RDP on the PLC itself. For PLCs that cannot be patched or updated, implement a unidirectional gateway (data diode) that allows monitoring data to flow to the SOC but prevents remote access to the PLC network. CoreRecon Fortress tier includes legacy OT compensating control design — we work with PLCs from Siemens, Rockwell, Schneider, and Unitronics that may not support modern auth protocols.
CoreRecon is specifically designed for water districts without internal security operations. The co-managed model means our OT-aware SOC handles alert triage, incident escalation, and SCADA monitoring — your 3-person operations team receives plain-language incident notifications, not SIEM dashboards. We don't require you to replace your existing SCADA vendor relationships. Our analysts are trained on water utility SCADA environments (Unitronics, Siemens, Rockwell) and understand the operational context of a 24-hour water treatment facility. The goal is to add the security operations layer without disrupting your district's operational structure. Pricing starts at $89/endpoint/month — for a typical small TX water district with 15–30 endpoints, that's $1,335–$2,670/month for 24/7 OT-aware SOC coverage.
Immediately: disable or password-protect any exposed VNC, RDP, or web-based management interfaces on your PLCs and HMI workstations. Change all default credentials on exposed devices. If remote access is required, implement VPN access with MFA rather than direct internet exposure. Document the exposure and remediation steps — this documentation matters for AWIA Section 2013 RRA and EPA SDWA Section 1433 compliance. Then contact CoreRecon for a free exposed asset assessment — we'll scan your public IP ranges, identify all internet-facing OT equipment, and provide a remediation priority list. The TX Panhandle attackers found their entry point via Shodan — the same reconnaissance method is available to any motivated adversary at no cost.
Texas Water Infrastructure Coordination Committee (TWICC) serves as the water sector liaison for threat reporting and incident coordination in Texas. Water systems can report incidents through TWICC to receive CISA and WaterISAC intelligence support. TCEQ also accepts drinking water incident reports. The America's Water Infrastructure Act (AWIA) Section 2013 ERP requirements include incident reporting obligations — your ERP must include notification procedures for cyber incidents affecting water system operations. There is no mandatory federal cyber incident reporting requirement for water systems yet (unlike the Cyber Incident Reporting for Critical Infrastructure Act — CIRCIA — which is in rulemaking), but AWIA ERP compliance and SDWA Section 1433 create de facto reporting obligations through the ERP documentation requirement.
CISA Alert — TX Panhandle Water Utility Compromise (Jan 2024) • WaterISAC Advisory — CyberArmyofRussia Campaign (2024) • Dragos OT/ICS Threat Report — Water Sector Analysis (2024) • CISA Unitronics PLC Advisory (2023) • CISA Volt Typhoon Advisory (2024) • FBI Joint Cybersecurity Advisory — Volt Typhoon (2024) • CISA-Aliquippa Water Treatment Plant Advisory — CyberAv3ngers (Nov 2023) • FBI Joint Cybersecurity Advisory — CyberAv3ngers (2023) • WaterISAC NTMWD Incident Report (2025) • CISA Rhysida Advisory (2025) • FBI-CISA Daixin Joint Advisory (2024) • CISA Black Basta Advisory (2024) • FBI IC3 Black Basta Alert (2024) • America's Water Infrastructure Act Section 2013 (42 USC 300i-2) • EPA SDWA Section 1433 Implementation Guidance (2023) • EPA Region 6 SDWA Enforcement Guidance (2024) • CISA Cross-Sector Cybersecurity Performance Goals (CPGs, 2023) • NIST CSF 2.0 (Feb 2024) • EPA AWIA RRA Guidance — Cybersecurity Section (2023) • TCEQ Public Drinking Water Section — AWIA Compliance Program • CISA OT Asset Identification Guidance (2024) • Dragos OT Security Operations Guide (2024) • CISA OT SOC Guidance (2024) • NIST SP 800-53 SC-7 — Boundary Protection • CISA Water Sector Network Segmentation Guide (2024) • CISA Water Sector Vendor Management Guidance (2024) • CISA Phishing Guidance — Water Sector (2024) • WaterISAC PLC Security Guidance (2024) • TCEQ Drinking Water Emergency Response Guidance • TWICC — Texas Water Infrastructure Coordination Committee (2024) • EPA Region 6 AWIA Compliance Verification (2024) • WaterISAC Cyber Resilience Guide for Water Utilities (2024) • CISA Water Sector CSF 2.0 Profile (2024) • FBI IC3 Water Sector Ransomware Statistics (2024) • ransomware.live — TX Water Utility Ransomware Incidents (2024–2025) • Dragos Sandworm Group Profile — Water Sector TTPs (2024) • CISA-Shodan OT Asset Discovery Guidance (2024) • EPA SDWA 1433 ERP Requirements — Incident Notification (2023)