CoreRecon Threat Intelligence  •  Water & Wastewater Utilities  •  June 2026

Texas Water Utilities:
Foreign Target

In January 2024, CyberArmyofRussia — a Sandworm-linked hacktivist group — compromised HMI systems at four Texas Panhandle water utilities via exposed VNC with no authentication. In Muleshoe, a tank overflowed before operators noticed. AWIA Section 2013 now requires SCADA cybersecurity in every Risk & Resilience Assessment. Most Texas water systems still aren't in compliance.

Download the Full Threat Brief — Free
June 2026 CoreRecon Intelligence Report V34 48 Verified Sources AWIA + EPA RY2 + TCEQ + CISA CPGs
4
TX Panhandle water
utilities compromised
January 2024
1.1M
Customer records stolen
North TX Municipal
Water District 2023
7,000+
TX public water
systems — most with
no IT staff
30min
OT incident response SLA
from CoreRecon
Fortress tier
What This Brief Covers

TX Water Utilities
Cyber Threat Brief

Full intelligence report on the attack surface facing Texas water and wastewater systems — from the CyberArmyofRussia Muleshoe attack and Daixin Team breach at North TX MWD, to AWIA Section 2013 compliance gaps, Unitronics PLC exposure, and the regulatory stack that puts water districts at risk. 48 verified sources. No marketing fluff. Documented incidents, applicable regulations, and actionable controls built for water district managers, operators, and public works directors.

48 Verified Sources Including:

  • CISA Emergency Advisory AA24-057A — CyberArmyofRussia / Sandworm-linked water utility compromise (Jan 2024)
  • CISA ICS Advisory ICSA-23-320-05 — Unitronics Vision series CVSS 10.0 auth bypass affecting TX water utilities
  • AWIA Section 2013 — full RRA cybersecurity requirements for community water systems >3,300 served
  • EPA Risk & Resilience Assessment guidance — SCADA cybersecurity mandatory scope and audit framework
  • CISA Cross-Sector CPGs — 17 water-sector applicable goals with implementation guidance
  • 6 named threat actors targeting water sector OT: Sandworm, CyberAv3ngers (IRGC), Daixin Team, Rhysida, Black Basta, Volt Typhoon
  • 3 confirmed incidents: Muleshoe TX (2024), North TX Municipal Water District (2023), Aliquippa PA (2023)
  • Oldsmar FL (2021): TeamViewer sodium hydroxide manipulation — direct remote access attack vector
  • TX SB 820, TDPSA, TCEQ Chapter 290 — state-specific compliance obligations
  • 8 water-utility-specific controls with 30/60/90 implementation roadmap

Access the Full Brief

We email it once. No newsletter. No spam. PDF delivered to your inbox.

Work email required. Free email providers (Gmail, Yahoo, Outlook, etc.) are not accepted. By submitting, you consent to CoreRecon processing your information per our privacy policy.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

Book Free Posture Assessment →
SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 48 verified sources
✅ AWIA + EPA RY2 + TCEQ + CISA CPGs
✅ 8 water-utility controls
✅ OT attack surface: Unitronics, Modbus, DNP3
✅ No spam — one email delivery