
The Canadian Centre for Cyber Security (Cyber Centre) is warning operators of critical infrastructure to be on high alert following a series of recent cyber incidents targeting internet-connected industrial control systems (ICS) across Canada, including one that tampered with municipal water pressure values that degraded service for the community.
In collaboration with the Royal Canadian Mounted Police (RCMP), the Cyber Centre has received multiple reports of ICS systems being accessed or manipulated by unauthorized actors throughout October. Other incidents include false alarms triggered in an oil and gas company’s tank monitoring system, and the manipulation of temperature and humidity levels in a grain-drying silo on a Canadian farm.
Identifying details about the hacks were not made available by Canadian authorities.
“Organizations are advised to conduct a comprehensive inventory of all internet-accessible ICS devices and assess their necessity,” the Cyber Centre said in its alert. “While individual organizations may not be direct targets of adversaries, they may become victims of opportunity as hacktivists are increasingly exploiting internet-accessible ICS devices to gain media attention, discredit organizations, and undermine Canada’s reputation.”
Subscribe to our Newsletter!
The latest environmental engineering news direct to your inbox. You can unsubscribe at any time.
In early 2024, two small U.S. towns of about 5,000 residents had water treatment infrastructure targeted by two separate Russian hacking groups. Later in the year, the Regional Municipality of Durham, Ontario, revealed a digital security breach at the Duffin Creek Water Pollution Control Plant that occurred on October 1.
ICS vulnerabilities pose growing risk
ICS components such as programmable logic controllers, supervisory control and data acquisition (SCADA) systems, and industrial Internet of Things (IIoT) devices are widely used to control essential services including water treatment, energy distribution, and manufacturing. When left unprotected, the Cyber Centre warns that these systems can be manipulated remotely, threatening public safety and service reliability.
In 2023, many cybersecurity groups sounded alarms over attacks on Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) commonly used in water and wastewater systems.
The Cyber Centre cautioned that many organizations still lack clear divisions of responsibility for securing operational technologies, leaving critical systems vulnerable. It urged stronger coordination among all levels of government, particularly in sectors where cybersecurity regulations remain limited, such as water, food production, and manufacturing.
Steps to strengthen protection
The advisory recommends the following for municipalities, utilities, and private operators:
- Conduct a full inventory of all internet-accessible ICS devices and assess whether remote access is necessary.
- Use secure alternatives such as virtual private networks (VPNs) with two-factor authentication rather than exposing systems directly to the internet.
- Implement continuous monitoring, intrusion prevention systems, and regular penetration testing.
- Follow vendor guidelines and Cyber Centre frameworks, such as the Cyber Security Readiness Goals, to secure devices from deployment through decommissioning.
In October, the U.S. EPA released new resources to ensure all water systems have the best information and emergency safeguards available to maintain cyber security protections for drinking water and wastewater treatment operations: -
- Emergency Response Plan (ERP) Guide for Wastewater Utilities: This updated plan describes strategies, resources, plans, and procedures utilities can use to prepare for and respond to an incident, natural or man-made, that threatens life, property, or the environment.
- Template for Developing an Incident Response Plan: This new template assists drinking water and wastewater systems with developing a Cybersecurity Incident Response Plan (CIRP).
- Incident Action Checklists: EPA is publishing two new checklists, as requested by the water sector, to help drinking water utilities prepare for, respond to, and recover from specific emergencies such as wildfires, power outages, floods, and cybersecurity incidents.
- Cybersecurity Procurement Checklist: This checklist will help water and wastewater utilities incorporate cybersecurity into the procurement process. It will help utilities generally assess the cybersecurity practices of suppliers, including vendors and manufacturers, and their products during procurement; and conduct tabletop exercises to clarify roles and responsibilities and strengthen incident response plans.






