Cyber Incident Victim: Nevada Water and Wastewater System
Date:
Mar 2021
Location:
United States of America
Summary
The Nevada Water and Wastewater System experienced cyber threats involving spearphishing, exploitation of outdated systems, and insecure remote access, leading to compromises in both IT and operational technology networks. Threat actors employed tactics including ransomware attacks and insider threats, risking operational disruption and unauthorized access to critical infrastructure systems. These incidents highlighted vulnerabilities in control system devices and firmware, reflecting broader malicious activities targeting water sector facilities to disrupt services or compromise safety mechanisms.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Malicious cyber activity targeting U.S. Water and Wastewater Systems (WWS) facilities occurred between 2019 and 2021, with documented incidents continuing through early 2021. Threat actors employed tactics including spearphishing campaigns to gain initial access, exploitation of outdated operating systems and software vulnerabilities, and compromise of internet-facing control system devices with weak authentication protocols. These attacks affected both IT and operational technology (OT) networks, with actors leveraging insecure remote access configurations to move laterally across networks. Specific techniques involved ransomware deployment to encrypt critical systems and insider threats exploiting privileged access. Operational disruptions included temporary loss of visibility into process control systems and manipulation of critical functions, though the advisory does not specify duration or geographic extent of service interruptions for individual facilities.

The joint advisory highlighted consequences such as compromised ability to monitor water treatment and distribution systems, potential risks to water quality assurance protocols, and interruptions to maintenance scheduling systems. Response actions by sector facilities included implementing enhanced network monitoring for anomalous traffic patterns, isolating compromised workstations and servers, and activating manual operational controls to maintain service continuity during IT system outages. Organizations conducted forensic reviews of affected systems to identify intrusion vectors and deployed patches for vulnerable industrial control system components. Facilities also initiated password resets for accounts with elevated privileges and reviewed remote access logs to identify unauthorized connections. The advisory noted sector-wide efforts to improve cyber-physical safety mechanisms designed to prevent malicious manipulation of chemical dosing levels or pressure management systems.
