ISI Insights

Security Advisory: Operational Technology Is Being Actively Targeted

Written by Muhammad Ali | Vice President, Cybersecurity Operations | Aug 17, 2026, 3:11:49 PM

As part of our ongoing monitoring of the threat landscape, ISI Cyber wanted to share a recent development involving Operational Technology (OT). This is especially relevant to organizations operating industrial, manufacturing, building management, or other connected physical systems.

WHAT HAPPENED

The FBI and EPA recently warned that malicious actors are actively targeting internet facing Programmable Logic Controllers (PLCs) used in water and wastewater facilities. Since July 27, incidents have been reported across at least seven states.

Key threat insights:

  • Attackers gained access to exposed PLCs, typically internet facing devices
  • Device settings, including IP addresses and passwords, were changed
  • Organizations lost visibility and control of equipment
  • Reported impacts included loss of water pressure and flooding

THE IMPACT OF AN OT CYBER ATTACK

An OT compromise can look very different from a traditional IT incident.

An IT incident may affect data or system availability. An OT incident can affect production, equipment, safety, infrastructure, and potentially mission readiness.

That distinction is getting more attention from Department of War (DoW) Chief Information Officer (CIO), Kirsten Davies, who has publicly stated that OT will receive more focus from her office. The recent Brilliant at the Basics guidance reinforces fundamental OT controls including asset visibility, segmentation, secure remote access, continuous monitoring, and documented incident response plans.

WHAT THIS MEANS FOR YOU

This communication is advisory only.

If your organization doesn’t operate OT, industrial control systems, or connected physical equipment, no immediate action is required.

If you do operate OT, consider reviewing:

  • Your inventory of PLCs, controllers, HMIs, engineering workstations, gateways, and remote access paths
  • Whether any OT management interfaces are directly exposed to the internet
  • Segmentation between IT and OT networks
  • Authentication and access controls for remote OT access
  • Monitoring for unexpected configuration, authentication, or control logic changes
  • Compensating controls for legacy systems that can’t easily be patched or replaced
  • Known good configurations, backups, recovery procedures, and OT specific incident response plans

Organizations should also understand who owns and supports each OT system, including any third-party integrators or specialized OT providers.

We’re sharing this because the FBI activity provides a real-world example of the same OT risks the DoW CIO is now putting additional focus on across the Department and Defense Industrial Base.

Stay safe, stay secure.

-ISI Cybersecurity Team

REFERENCES