Our seasoned Chief Information Security Officers bring strategic guidance to your leadership team, helping you right-size your cybersecurity operations.
You can count on our IR team to contain the damage from a cyberattack, investigate the origins of the breach and build better protections for the future.
Nine Michigan water systems were targeted, and none were breached. There was never any risk to public health.
Michigan is the seventh state pulled into the campaign. Minnesota alone has logged more than 30 attempts in the same wave.
This is not limited to one adversary. A December joint advisory (AA25-343A) warned that pro-Russia hacktivist groups have been targeting critical infrastructure worldwide.
Most of these intrusions are basic. Attackers don't break in so much as walk in, through OT gear left on the open internet with a weak or missing password.
The exposure isn't unique to utilities. Any organization running OT, industrial control systems or connected IoT shares it.
Start by mapping what's reachable from the internet, then run exposure management continuously rather than annually.
Suspected Iranian-backed hackers recently targeted nine municipal water systems across Michigan. It's likely part of a coordinated campaign being tracked by both the FBI and the Cybersecurity & Infrastructure Security Agency (CISA)
The good news: none of the systems were actually breached, and there was never any risk to public health. So, the defenses did their job this time.
But there is a bigger pattern at play here. Michigan is now the seventh state pulled into this attacker campaign. Minnesota alone has logged more than 30 attempts in the same wave.
Why Are Water Utilities Such Attractive Targets?
From a cybersecurity perspective, water utilities make attractive targets for pretty basic reasons: they run essential services, they often use aging equipment and a lot of them don't have the budget to modernize. Many researchers have pointed this dollar gap. Smaller and rural systems just don't have the tax base to keep their tech current, and attackers know it.
Is This Limited To One Adversary?
This pressure is not new, and it is not limited to one adversary. Back in December, the FBI, CISA, the NSA and other international partners released a joint advisory (AA25-343A) warning that pro-Russia hacktivist groups have been taking swings at critical infrastructure all over the world — water, food and agriculture, energy — you name it.
How Sophisticated Are These Attacks?
What's notable is how basic many of the attacks are. In many cases they don't really "break" in so much as "walk" in. All it takes is one piece of operational technology (OT) gear sitting on the open internet with a weak or missing password.
That's the real lesson here, and it reaches well beyond public utilities. Any organization running OT, industrial control systems or connected IoT devices — manufacturers, healthcare systems, building operators, logistics firms etc. — shares the same underlying exposure.
What Should Organizations Do To Stay Ahead?
Here's a few tips to help you stay ahead.
Figure out what's sitting on the open internet. Most of these break-ins start with something nobody realized was reachable — a pump controller, a leftover remote-access session, a sensor with a public IP. So step one is straightforward: map your OT and IoT gear, figure out what's exposed and pull anything that doesn't need to be out there back behind real controls. That's the first thing CISA will tell you to do, too: get OT off the public internet and lock down whatever's left with strong authentication.
Keep an eye on exposure year-round. Ever notice how attackers never seem to strike when it works for your schedule? That's the whole idea behind Continuous Threat Exposure Management (CTEM): you keep the loop running all the time — sorting out which gaps actually matter, testing whether they're really exploitable, and fixing them in order of importance. That's how you shut the door before the bad guys come knocking.
Treat it like real risk management. Nobody has unlimited budget, whether you are a public utility in Michigan or a mid-sized business on the other side of the Atlantic. So, you need to spend where it counts: prioritizing the places where a breach would hurt worst and building enough monitoring and response muscle to catch attempts early.
Know where your exposure is — before someone else shows you.
Inversion6 helps organizations map their OT and IoT attack surface, stand up continuous threat exposure management and build the monitoring and incident response to act when it counts. Whether you run a utility, a plant floor, or a connected enterprise, we'll help you right-size the investment to your risk.
Want to see what's exposed in your environment? Let's find out together.