Cybersecurity News

Not Every Cyberattack Starts With Phishing: Lessons From Recent Water-System Attacks

Recent water utility attacks targeted exposed PLCs, showing why OT security, process discipline, and human-risk training must work together.

Water utility industrial control system under cyberattack pressure

Recent cyberattacks against U.S. water and wastewater utilities offer an important reminder: not every cyberattack begins with a phishing email.

On July 30, 2026, the FBI and Environmental Protection Agency warned that water utilities in at least seven states had reported incidents involving internet-facing operational technology. Attackers remotely accessed Rockwell Automation/Allen-Bradley MicroLogix programmable logic controllers, or PLCs, and changed device passwords and IP addresses. Those changes caused utilities to lose monitoring and, in some cases, control of connected equipment.

Reported operational effects included pressure loss and flooding. At least one affected organization also discovered changes to PLC project files, the programming used to govern how industrial equipment operates.

These were not conventional data breaches. They were attacks against the technology responsible for monitoring or controlling physical processes.

What Made These Water Systems Vulnerable?

PLCs are industrial computers used to operate or monitor equipment such as pumps, valves, pressure systems, and treatment processes. They are essential to many water facilities, but they can become high-risk targets when they are directly reachable from the public internet.

In the incidents described by federal agencies, attackers did not need to compromise a corporate email account before reaching the targeted controllers. The PLCs themselves provided a remote attack path.

CISA urged water organizations to remove publicly exposed PLCs and other operational technology from the internet. The agency also warned that utilities may have cellular modems installed by operators, vendors, or system integrators that are not documented in asset inventories or detected by routine attack-surface scans.

The FBI noted another important risk: several affected organizations appeared to have similar network configurations provided by third parties. When a vulnerable design is repeated across multiple customers, attackers may be able to reuse the same approach against multiple facilities.

This Was Not a Confirmed Phishing Attack

The federal alerts describe attackers remotely accessing internet-facing operational technology. They do not identify phishing or another form of employee-targeted social engineering as the initial access method.

That distinction matters.

Security awareness training cannot remove a PLC from the public internet. A phishing simulation cannot configure a firewall, secure a cellular modem, segment an operational network, or detect unauthorized changes to industrial control logic.

It would therefore be inaccurate to claim that security awareness training, or PhishingBox specifically, could have directly prevented these incidents.

That does not make the human layer irrelevant. It clarifies where human risk management belongs within a larger cybersecurity strategy.

What Could Have Reduced the Risk?

The controls most directly relevant to these incidents are technical and operational. The FBI, EPA, and CISA recommend that water utilities:

  • Remove PLCs and other operational technology from direct public-internet exposure.
  • Route necessary remote access through a monitored secure gateway, jump host, or VPN.
  • Replace default or weak passwords with strong, unique credentials.
  • Use firewall rules and access-control lists to permit only expected communications.
  • Secure cellular modems with strong authentication and logging.
  • Review PLC project files for unauthorized changes.
  • Maintain verified, known-good backups of PLC configurations and logic.
  • Preserve and regularly test the ability to operate essential systems manually.
  • Identify, isolate, and eventually replace unsupported or end-of-life equipment.

These controls address the attack path described in the federal warnings. They reduce the ability of an external actor to connect directly to industrial equipment and make unauthorized changes.

Where the Human Layer Still Matters

Technology does not deploy, document, or maintain itself. People and processes determine how equipment is installed, how remote access is approved, how vendors connect, and how quickly suspicious activity is escalated.

The human layer matters in several areas surrounding an OT environment.

Following Secure Remote-Access Procedures

Employees, contractors, and vendors need to understand that convenience cannot override security policy. An unapproved modem, shared account, temporary firewall exception, or undocumented maintenance connection can create a long-term exposure.

Training does not technically block those connections, but it can help personnel understand why approved access procedures exist and when an unusual configuration should be reported.

Protecting Administrative Credentials

Phishing was not identified as the entry vector in these incidents. However, credentials for VPNs, engineering workstations, vendor portals, and administrative systems remain valuable targets.

After direct access is closed, an attacker may look for another route. Personnel responsible for OT and remote administration should be prepared to recognize credential-harvesting emails, impersonated vendor messages, fraudulent support requests, and other social engineering attempts.

Managing Third-Party Risk

Utilities often depend on equipment manufacturers, contractors, consultants, and system integrators. Everyone with access to the environment needs to understand the organization's security and reporting requirements.

A strong internal program can still be undermined when third-party access is undocumented, unnecessarily broad, or poorly secured.

Recognizing and Reporting Abnormal Activity

Operators may be among the first people to notice that a controller is unavailable, a password no longer works, a device has changed addresses, or equipment is behaving unexpectedly.

Employees need a clear process for escalating those observations. Quick reporting can help security and operations teams distinguish an equipment failure from malicious activity and begin containment sooner.

Preparing for Manual Operations

The FBI specifically recommended maintaining the ability to operate OT systems manually. That capability depends on more than a written recovery plan. Personnel must understand their roles, know how to initiate manual procedures, and practice those procedures before a real emergency.

Where PhishingBox Fits

PhishingBox is designed to help organizations manage human risk. The platform combines phishing simulations, cybersecurity training, behavioral risk measurement, suspicious-email reporting, and security-operations workflows.

Those capabilities can support a broader critical-infrastructure security program by helping organizations:

  • Test employees with realistic phishing scenarios involving password resets, remote-access notices, vendor communications, and technical-support impersonation.
  • Deliver role-appropriate training to operators, administrators, help-desk personnel, contractors, and other targeted groups.
  • Identify users or departments that may need additional coaching.
  • Reinforce secure password, reporting, and verification practices.
  • Give employees a consistent way to report suspicious email through KillPhish.
  • Help security teams review and respond to reported messages through Security Inbox.

But PhishingBox is not a replacement for operational-technology security. It does not perform OT asset discovery, network segmentation, firewall configuration, PLC integrity monitoring, or industrial incident response.

Those responsibilities require appropriately designed technical controls and personnel with OT security expertise.

The Real Lesson Is Defense in Depth

The recent water-system attacks should not be used to argue that every cybersecurity incident is fundamentally a phishing problem. They demonstrate the opposite: organizations cannot depend on any single layer of defense.

An effective security program brings three elements together:

Layer What It Contributes
Technology Secure gateways, network segmentation, firewalls, access controls, monitoring, protected backups, and properly configured industrial equipment reduce direct technical exposure.
Process Accurate asset inventories, vendor-access requirements, change-management procedures, incident-response plans, and tested recovery processes ensure that security controls are consistently applied.
People Trained employees and contractors follow approved procedures, protect their credentials, question suspicious requests, report unexpected activity, and respond effectively when technology fails.

Weakness in any one of these areas can undermine the others. Strong technical controls can be bypassed through stolen credentials. Well-trained employees cannot compensate for an internet-facing PLC. A detailed policy is ineffective when no one knows how to follow or enforce it.

Questions Organizations Should Ask Now

Although the current warnings are directed at the water and wastewater sector, the lessons apply to any organization operating industrial or operational technology:

  1. Which operational devices can be reached from outside the organization?
  2. Does the asset inventory include cellular modems and connections installed by vendors or system integrators?
  3. Is all remote access mediated, authenticated, logged, and limited to authorized systems?
  4. Are default passwords, shared credentials, and unsupported devices still present?
  5. Can the organization identify unauthorized changes to controller configurations or project files?
  6. Are employees and contractors trained to recognize attempts to steal remote-access or administrative credentials?
  7. Do personnel know how to report both suspicious communications and abnormal equipment behavior?
  8. Can essential operations continue safely if remote monitoring or automated control becomes unavailable?

These questions span technology, process, and human behavior because effective resilience requires all three.

Security Awareness Is One Layer, Not the Only Layer

Recent attacks against water utilities are not a reason to force a phishing connection where one does not exist. They are a reason to reject one-dimensional security strategies.

PhishingBox would not have prevented attackers from connecting directly to an exposed PLC. Preventing that required secure OT architecture, controlled remote access, accurate asset inventories, strong device configurations, monitoring, and tested recovery procedures.

PhishingBox can help protect the people working around those systems. Through realistic phishing simulations, targeted cybersecurity training, measurable human-risk programs, and suspicious-email reporting, organizations can reduce the likelihood that attackers will find an alternate route through employee credentials or social engineering.

The goal is not to ask one product or control to solve every cybersecurity problem. It is to apply the right control to each risk and make sure technology, processes, and people reinforce one another.

Strengthen the Human Layer of Your Security Program

PhishingBox helps organizations test employee readiness, deliver targeted cybersecurity training, measure human risk, and create stronger reporting habits.

Request a demo or start a 14-day free trial to see how PhishingBox can support the human layer of a broader defense-in-depth strategy.