Water Systems Told to Shore Up Basic Cyber Defenses

New TrendAI research describes a growing underground market for access to industrial systems, including water infrastructure. The report identifies remote access, stolen credentials, and vulnerable edge devices as common entry points. A company executive advises utilities to strengthen cybersecurity leadership and focus on basic defenses.
TrendAI's report, released this month, examines how access brokers, ransomware crews, data sellers, and hacktivists use forums, marketplaces, and messaging services to trade entry into critical infrastructure. It says remote-access tools, stolen logins, and exposed edge devices are frequent ways in, with operational technology access sometimes sold as a premium item.
The report arrives amid heightened attention on water and wastewater systems. In July, utilities in at least seven states reported incidents involving Internet-facing programmable logic controllers, per the FBI and EPA. Some states have pursued their own efforts: New Hampshire partnered with the Overwatch Foundation, Kansas began an assessment program in early 2024, and New York, New Jersey, and Massachusetts offer grants.
If access to industrial systems becomes easier to buy, water utilities and the communities they serve may face greater risk of service disruptions, contaminated supplies, or eroded public confidence. Residents, local governments, and operators could bear costs from incident response, upgrades, and tighter monitoring. The push for basic defenses and clearer security leadership may help, but resource-limited systems could struggle to keep pace.