A wave of cyberattacks targeting water and wastewater systems across at least a dozen states has exposed a fundamental challenge for critical infrastructure operators: attackers will look for whatever path gives them access to operational systems, and defenders cannot protect connections they do not know exist.
In the recent attacks, adversaries gained initial access through internet-facing operational technology. Attackers remotely accessed industrial controllers and, in some cases, changed network configurations and passwords, disrupting operators’ ability to monitor or control equipment remotely. At some utilities, operators shifted to manual operations to maintain water service. Wireless communications were not identified as the mechanism for initial access. But other attack activity demonstrates that wireless connectivity is part of the attack surface defenders need to consider.
In its July 30 alert, CISA warned that these attacks included targeting cellular modems and urged critical infrastructure organizations to identify and validate external connections. The agency specifically called attention to cellular modems installed by operators, vendors, or system integrators that may not appear in documentation or routine attack-surface scans.
That is an important data point. Cellular connectivity is not simply a theoretical concern. Attackers are targeting equipment that can provide external connectivity to operational environments.
The larger security lesson extends beyond any individual CISA recommendation. Critical infrastructure operators need visibility into potential paths into and through their operational environments. That includes wireless connections that may operate outside the network paths conventional security technologies monitor.
Water Infrastructure Presents Attackers With Multiple Paths
Water and wastewater utilities operate infrastructure that communities depend on continuously. Operational technology controls pumps, valves, treatment processes, pressure, storage, and other physical functions that support reliable water and wastewater services. That dependence makes the sector an attractive target for adversaries seeking to disrupt it.
The latest campaign demonstrates the danger of leaving operational technology directly accessible from external networks. When attackers find an exposed controller or a poorly protected remote-access path, they may not need a sophisticated exploit to disrupt operations.
Utilities should address those obvious entry points first. They should remove unnecessary public internet exposure, strengthen authentication, segment critical systems, restrict and monitor remote access, maintain accurate asset inventories, and prepare to operate critical systems manually when automated controls become unavailable. But securing known network entry points addresses only part of the attack surface.
Water infrastructure often spans large geographic areas. Treatment plants communicate with remote pump stations, wells, tanks, lift stations, monitoring systems, and other distributed assets. Utilities rely on automation to operate and monitor these systems efficiently, and cellular and point-to-point radio links can provide connectivity where dedicated wired connections are impractical.
These wireless connections often support legitimate and necessary operations. Wireless connectivity does not inherently create a vulnerability, nor does it automatically mean that a device is exposed to the public internet. It does, however, create another communications path that defenders need to identify, assess, and monitor.
Cellular Modems Expose a Broader Visibility Problem
The fact that attackers are targeting cellular modems makes wireless connectivity directly relevant to the current threat environment. A cellular modem may support remote monitoring, maintenance, telemetry, or control. An operator may install it. A vendor or system integrator may deploy it as part of another system. A temporary communications device may remain after a project ends. Equipment may change while documentation does not. Any of these connections may serve a legitimate operational purpose. The security problem begins when defenders do not know the connection exists.
Many conventional network and asset-discovery technologies build visibility from known infrastructure, managed endpoints, IP addresses, and traffic traversing monitored network paths. Wireless communications do not always follow those paths. A cellular device can communicate directly over LTE or 5G without routing its traffic through the organization’s managed wired or Wi-Fi network. Point-to-point radio systems can similarly provide communications between operational assets outside the infrastructure that conventional network monitoring observes.
This raises important questions: “What devices connect to our managed network?” and “What devices are communicating wirelessly from our facilities?” The answers may not match.
A utility can maintain a detailed network inventory yet lack visibility into wireless devices operating within its facilities. CISA’s warning about cellular modems that may not appear in documentation or routine attack-surface scans demonstrates why that distinction matters.
Attackers Will Use the Path That Works
Attackers do not need to respect the architectural boundaries defenders use to organize their security programs. They do not care whether a communications path belongs to IT, OT, cellular, Wi-Fi, or another technology. They care whether it provides a useful route toward their objective. That principle matters throughout the attack chain.
An overlooked wireless connection could provide an initial-access path if it exposes a reachable service or establishes connectivity to a protected environment. After gaining access through another vector, an attacker could use a wirelessly connected device as an alternative path to other systems, depending on the network architecture, device configuration, interfaces, and privileges involved.
A device or service accessible through a poorly monitored wireless connection could also create opportunities for persistence or command-and-control communications outside the network paths defenders routinely inspect. In other architectures, an attacker could use an overlooked connection to bypass network segmentation or create a path between systems defenders believed were isolated.
These scenarios do not describe what investigators have reported in the current water-utility attacks. They illustrate the possibilities defenders need to consider when assessing an environment with wireless communication paths that their existing security technologies may not see. The exact attack chain will depend on the device, architecture, configuration, access controls, and adversary objective. The defensive principle remains the same: every unmonitored communications path creates uncertainty about what an attacker could do with it.
Organizations naturally apply their strongest controls to infrastructure they know exists. Security teams patch known systems, monitor known networks, restrict known remote-access paths, analyze known logs, and investigate activity that appears in monitored environments. An unknown connection creates a different problem. Defenders may not realize they need to assess the device, restrict access to it, monitor its activity, or determine which other systems it can reach. That makes visibility foundational to attack-surface management.
Attackers will look for the path of least resistance, and an unmonitored path can create an advantage because defenders may not know that it needs to be assessed, hardened, or monitored.
Network Visibility Is Not Wireless Visibility
Traditional network monitoring remains essential, but it does not necessarily provide an independent view of the RF environment. A vendor-installed cellular modem may not appear in a conventional network scan. An unauthorized wireless device may never authenticate to the organization’s Wi-Fi network. A point-to-point radio may communicate outside monitored network infrastructure. Yet each device still generates RF emissions when it transmits.
RF monitoring provides an independent source of visibility by observing transmissions rather than relying on devices to appear through the managed network infrastructure. Critical infrastructure operators can use that perspective to compare documented assets and monitored networks with the wireless activity actually occurring in the environment.
How Bastille Adds RF Visibility
Bastille Wireless Airspace Cybersecurity extends asset visibility beyond conventional network monitoring by independently observing the RF environment. Bastille uses 100% passive RF monitoring to detect wireless devices through their radio-frequency emissions without requiring them to connect to the organization’s network. Bastille monitors the RF spectrum from 100 MHz to 6 GHz, with Wi-Fi coverage extending to 7.125 GHz.
For water and wastewater utilities, this visibility can help security teams identify unknown or unauthorized RF-enabled devices, detect LTE and 5G activity, and investigate wireless communications that may fall outside established policy or conventional network visibility.
When Bastille detects a device of interest, its patented algorithms and analysis help security teams physically locate the device for investigation and remediation. Teams can then determine whether the device belongs in the environment, who owns it, what function it performs, and whether its use complies with policy. Bastille does not replace the network, OT, identity, segmentation, vulnerability management, authentication, or secure remote-access controls needed to protect industrial systems. It adds visibility into a part of the attack surface those controls may not observe.
Continuous RF Monitoring Provides an Independent View
Asset inventories document known devices. Continuous RF monitoring provides an independent view of what is actually transmitting. A spreadsheet, configuration database, network scan, or periodic assessment reflects what defenders know about the environment at a particular point in time. It may not reveal a cellular modem installed later by a contractor, an undocumented radio link, a forgotten communications device, or an unauthorized wireless device introduced into a facility.
Bastille’s 100% passive continuous monitoring observes RF activity as devices appear, disappear, move, or change. Security teams can compare observed wireless activity with documented assets and established policies, and then investigate any discrepancies. That independent visibility becomes increasingly important as critical infrastructure relies on more distributed automation and wireless connectivity.
Defenders Need Visibility Into Every Path
The latest water-sector attacks demonstrate why critical infrastructure cybersecurity requires both prevention and resilience. Utilities need to remove unnecessary internet exposure, strengthen authentication and access controls, segment critical systems, secure remote access, maintain accurate inventories, continuously monitor operational environments, and practice operating critical processes when automated systems become unavailable. But defenders should not stop at the entry points their existing tools already show them.
The current attacks provide a useful example. Adversaries gained initial access through network-facing operational technology. CISA stated that cellular modems are among the equipment being targeted. Those facts are not contradictory. They illustrate the larger attack-surface problem. Attackers can pursue different paths at different stages of an attack. One connection might provide initial access. Another might offer a route toward additional systems. Another could support persistence, command-and-control, or communications outside heavily monitored network paths.
Defenders therefore need to think about the attack surface in terms of actual connectivity, not just the connectivity visible through existing network-security infrastructure. The path an attacker chooses may not be the most sophisticated one. It may simply be the connection receiving the least defensive attention.
See the Wireless Devices Your Network Tools May Miss
Bastille Wireless Airspace Cybersecurity helps critical infrastructure organizations discover, identify, locate, and monitor wireless devices and activity across the RF spectrum. Its continuous, 100% passive RF monitoring provides security teams with visibility into wireless devices and communications that conventional network-based technologies may miss.
For water utilities and other critical infrastructure organizations, that visibility complements existing IT and OT security by helping defenders identify wireless connections and communications paths that need to be assessed, governed, and incorporated into the broader cybersecurity program. Strong attack-surface management starts with a simple principle: defenders need visibility into every communications path an attacker could use.
Learn how Bastille can help your organization gain visibility into wireless devices and communications across the RF spectrum.