Since July 27, 2026, the FBI has been tracking a campaign against water and wastewater utilities across at least seven states. The methods used by the attackers were old school - no custom malware or zero-day exploits. They found programmable logic controllers (PLCs) from a major manufacturer sitting exposed on the open internet, changed the IP addresses and passwords, and walked away with something more useful than data: control.
The FBI's alert describes the result as a "loss of monitoring and control functionality." This phrase is significant. This wasn't a breach in the sense the word usually implies: no exfiltrated records, no ransom note. It was simpler and, in a way, more unsettling. Operators lost the ability to see and manage critical equipment, often because those devices were publicly accessible without the operators' knowledge
Call it what it actually is: an asset visibility failure that happened to land on a PLC instead of a laptop. The controllers involved, which operate pumps, lift stations, and treatment processes, had likely been online for years. Nobody exposed them to the internet on purpose that week. A misconfigured firewall, a vendor's remote access tool nobody closed out after a service call, a network change made for a completely different reason six months back: any one of these can quietly expose a device that used to be invisible. It usually stays that way, exposed and unnoticed, until someone outside the building finds it first.
Swap the device type and this is a fleet management story that physical security teams would recognize immediately. A camera, an access control panel, a sensor: installed once, configured once, then left running for the length of its hardware life. The devices involved are different, PLCs and HMIs instead of cameras and access panels. The exposure pattern is the same: a distributed fleet running whatever configuration it shipped with, drifting out of sync with whatever the network around it has become, invisible to whoever's supposed to be watching until it suddenly isn't.
Even working devices can present risks
A camera or an access panel doesn't need to go dark to become a problem. Sometimes it's the opposite: the device keeps running exactly as installed, and that's precisely what makes it useful to somebody else. Check Point Research has documented Iran-linked hackers exploiting known vulnerabilities in internet-connected cameras across the Middle East since early 2026, using that access for reconnaissance ahead of missile strikes. The same research ties this activity back to industrial control system attacks by the same actors, the pattern behind the water utility campaign already described above.
A separate incident, documented by cybersecurity firm S-RM, shows a quieter version of the same problem. When endpoint protection blocked a ransomware group's attempt to encrypt a Windows server, the attackers didn't back off. They scanned the network, identified an unsecured webcam outside the security team's view, and used it as a persistent pivot point to re-enter the network and deploy ransomware.
Neither incident involved a broken device. Both involved one that was on, working, and completely outside anyone's field of view, until it became the way in.
Ask the question these water utilities couldn't answer fast enough: If one device on your fleet went dark tonight, or someone quietly changed its credentials, how long before that shows up on anyone's screen? For a team managing several thousand devices across dozens of sites, the honest answer usually lands somewhere between "we'd catch it eventually" and "depends which vendor's dashboard someone happened to check that week."
Water utilities got a federal alert and national coverage because they're regulated critical infrastructure with an obvious public safety story attached to them. While physical security device fleets face these exact exposure risks, many organizations have yet to recognize enterprise cameras and access panels as critical attack vectors until a breach occurs.
The regulatory ground underneath that difference is shifting fast. Regulatory frameworks, including NDAA supply chain provisions, FCC rules, and the EU Cyber Resilience Act, are increasingly pointing toward a shared standard: requiring organizations to maintain complete visibility over networked devices, firmware integrity, and credential management.
The attackers behind the water utility campaign didn't do anything clever. They found doors nobody remembered were unlocked, on systems the country happened to be watching closely enough to notice. Most physical security fleets are carrying the same kind of door. Most of them haven't been checked in a while.
To identify any unlocked doors across your fleet, speak to us about getting a free platform preview.