logo

CISA warns water facilities to secure HMI systems exposed online

ID: 37caceba-31ac-500f-b9b1-7588024b71c0

STIX ID: report--37caceba-31ac-500f-b9b1-7588024b71c0

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-13

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA and the EPA warned that Internet-exposed Human Machine Interfaces (HMIs) at water and wastewater facilities have been actively exploited, allowing attackers—including pro‑Russia hacktivists and nation‑aligned groups like Volt Typhoon and IRGC‑linked actors—to alter set points, disable alarms, change passwords, and disrupt operations; recent incidents forced utilities to switch to manual operations or shut down systems and prompted federal guidance to harden remote HMI access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.