Cybersecurity Updates
The water and wastewater industry faces a constant and serious cybersecurity challenge. Water utilities must proactively identify threats, vulnerabilities, and potential impacts to safeguard their systems, ensure safe water delivery, and maintain public confidence. As critical infrastructure becomes increasingly digital, the water sector is targeted by a growing number of cyber threats, from opportunistic hackers to sophisticated state-sponsored groups, each with their own motives. These attacks can disrupt essential services, jeopardize water quality, and endanger public health. A key target is often the Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems that manage water treatment and distribution. Attackers, including cybercriminals and nation-state actors, may exploit vulnerabilities like outdated software, weak authentication, and poor network segmentation to penetrate these vital systems. WWEMA will provide resources addressing all facets of cybersecurity.
August 5, 2026
Case Study: China’s Intelligence Services Recruited Insider to Obtain Sensitive, Non-Public US Economic Information
The FBI prepared this Liaison Information Report (LIR) to provide the financial services sector and academic community a case study illustrating how China’s intelligence services (CIS) spot, approach, develop, and task people to provide sensitive, non-public information. This study is intended to sensitize readers to concerning behaviors and suspicious activities that could be indicative of CIS intelligence gathering. CIS are very interested in acquiring US sensitive, non-public information and frequently target individuals who can provide that information, regardless of where they work. Such information could provide the Chinese Government with key insights into high-level US decision-making processes and policies.
Click here for LIR Alert.
July 30, 2026
Malicious Cyber Actors Targeting Water and Wastewater Sector InternetFacing Programmable Logic Controllers, Causing Operational Disruptions
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/AllenBradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
Click here for full Alert.
June 12, 2026
WWEMA was invited to a debrief by the FBI Office of Private Sector regarding China late last Friday. Please find the Liaison information Report (LIR) for additional information on the Foreign Enterprise Human Resources Services Company (FESCO) and indicators to look for when working with Chinese based staffing companies.
IMPORTANT NOTE: This alert is classified as “TLP: GREEN” which means we can share these details with our members to help strengthen our collective defense. However, it cannot be shared via publicly accessible channels, including on public websites, social media, or other searchable channels. Please keep these insights within our member community.
Click here for LIR Report
March 24, 2026
The FBI’s Counterterrorism, Counterintelligence, and Cyber Divisions, in coordination with the Office of Private Sector, prepared a Liaison Information Report (LIR) to inform private industry partners about Iranian threat vectors and potential indicators of illicit Iranian activity following the escalation of hostilities in the Middle East involving Israeli and US military strikes against Iran. Iran persistently engages in lethal targeting of current and former US Government (USG) officials and Jewish and Israeli interests; transnational repression (TNR)a targeting dissidents and anti-regime activists; traditional intelligence collection and espionage; cyber intrusions; and technology procurement and sanctions evasion.
IMPORTANT NOTE: This alert is classified as “TLP: GREEN” which means we can share these details with our members to help strengthen our collective defense. However, it cannot be shared via publicly accessible channels, including on public websites, social media, or other searchable channels. Please keep these insights within our member community.
Click here for LIR Report