London Daily

Focus on the big picture.
Tuesday, Mar 31, 2026

Cybercriminals are selling access to water treatment plants like the one hacked in Florida — here's why experts think the problem could get worse

Cybercriminals are selling access to water treatment plants like the one hacked in Florida — here's why experts think the problem could get worse

Experts expect that "we'll see more news of attack scenarios and how those attacks can be monetized" because of ongoing security vulnerabilities.
Cybercriminals in underground forums have offered to sell access to hacked systems that control US power plants and water treatment systems, according to a new report from the threat intelligence firm Intel 471. Hackers likely took advantage of common security vulnerabilities in these systems, experts say — and they fear that such attacks could become more common as bad actors find ways to monetize the hacks.

The systems that cybercriminals offered access to bore a striking resemblance to the Oldsmar, Florida water treatment plant that was compromised by a hacker last week. Law enforcement officials said an unknown intruder gained access to software used by plant managers to remotely control its systems and attempted to raise the amount of sodium hydroxide — also known as lye — in the drinking water to dangerous levels.

Intel 471 researchers were careful to note that they don't have hard evidence proving that the cybercriminals offering access to hacked industrial systems are the same ones who hacked the Oldsmar plant. But their findings illustrate broader cyber vulnerabilities in US systems that control infrastructure. For years, experts have sounded alarm bells about potential issues with these so-called Supervisory Control and Data Acquisition systems (or SCADA systems), which monitor and control machines in the field.

"Attacks on SCADA systems are not new," an Intel 471 spokesperson said in response to emailed questions from Insider following the report. "It is often easy for non-sophisticated threat actors to identify internet-facing SCADA systems and gain access with very little effort."

In one instance logged by Intel 471, a cybercriminal in a Telegram channel popular with hackers offered in May 2020 to sell access to a "Groundwater Recovery & Treatment System" located in Florida. The hacker claimed to have broken into software used by administrators to remotely control the system, and included a screenshot that showed levels of sodium hydroxide in the water.

The person who posted the screenshots in the Telegram channel was likely an Iranian actor, Intel 471 researchers said. The Telegram channel in question was also tied to a 2020 hack of an Israeli water reservoir. There's no evidence to suggest that this person was motivated by anything other than monetary gain and notoriety, the spokesperson said.

The researchers' findings illustrate broader weaknesses in the cyber defenses of US critical infrastructure. Many industrial control systems can be easily located using online directories like Shodan, which logs internet-connected devices. From there, experts say even low-level hackers can scour out stolen or default login credentials to try to break into the software that controls the systems.

"SCADA systems are notorious for using weak default admin credentials, non-standard ports, and other technical identifiers," the spokesperson told Insider.

Too much critical infrastructure is connected to the public internet with lax security protections, in part because of egregiously low cybersecurity budgets.

Industrial systems are a growing target for profit-driven hackers across the board. In the past year, researchers have tracked cybercriminals probing computers connected to critical infrastructure and reselling access to those computers to more sophisticated hacking groups, according to the security firm Kaspersky.

"We believe the malicious actors have had, for quite a while, access to not only industrial organizations but also lots of information on their technological processes," Evgeny Goncharov, Kaspersky's head of Industrial Control Systems Cyber Emergency Response Team, said in a webinar Thursday. "Probably in the near future we'll see more news of attack scenarios and how those attacks can be monetized."

The FBI published a joint advisory with the Cybersecurity and Infrastructure Security Agency on Thursday advising critical infrastructure agencies to install the latest version of Windows and urging them to be on the lookout for suspicious logins to their remote access software.
Newsletter

Related Articles

0:00
0:00
Close
Russia Expels British Diplomat as UK Pushes Back Against Pressure
White House App Faces Scrutiny After Claims of Continuous User Location Tracking
BBC Faces Scrutiny Over Allegations of Paid Content Linked to Saudi Arabia
UK-France Coastal Patrol Agreement Nears Breakdown Amid Migration Pressures
UK Police Detain Pro-Palestine Activist Again Weeks After Bail Release
FTSE 100 Advances as Energy and Mining Shares Gain Amid Middle East Tensions
Eli Lilly Seeks UK Pricing Deal to Unlock Renewed Pharmaceutical Investment
Three Arrested in UK After Massive Cocaine Haul Discovered Hidden in Banana Shipment
UK Fuel Prices Poised for Further Surge Amid Global Energy Pressures
Apple Subsidiary Penalized by UK Authorities for Breach of Moscow Sanctions
Western Allies Intensify Coordinated Sanctions Strategy Against Russia
UK Lawmakers Face Criticism Over Renewed Push for Social Media Restrictions
Starmer Signals UK Crackdown on Addictive Social Media Features
Rising Costs Push One in Five UK Hospitality Businesses to the Brink of Closure
Man Arrested on Suspicion of Attempted Murder After Car Strikes Pedestrians in UK, Injuring Seven
Escalating Conflict Involving Iran Tightens Fiscal Pressures and Highlights UK Economic Vulnerabilities
UK Moves to Confront Russian ‘Shadow Fleet’ Operating in Its Waters
UK Housing Divide Deepens as Older Owners Hold Wealth While Under-30s Face Mounting Barriers
London Demonstration Calls on UK to Recognize Iranian Opposition’s Provisional Government
UK Green Party Vote on ‘Zionism is Racism’ Motion Collapses Amid Internal Disputes and Technical Failures
SNL UK Ignites Debate with Sharp Royal Satire Targeting Prince Andrew and Prince William
EU Proposes ‘Emergency Brake’ to Resolve Deadlock in UK Youth Mobility Talks
Thousands Rally in London to Oppose Rise of Far-Right Movements
Hong Kong Official Rejects Allegations of Surveillance Orders Targeting UK-Based Dissidents
PayPal Expands Cryptocurrency Services to Allow UK Users to Buy and Sell Bitcoin
UK Minister Challenges Reform Party’s ‘Pro-Family’ Agenda as Debate Intensifies
Concerns Grow Over Meningitis Risk Among UK Students Amid Warning Signs of New Outbreaks
Japanese Grand Prix 2026: Schedule, UK Start Times and Full Broadcast Details
Electric Vehicles Seen as Strategic Solution to UK Fuel Reserve Concerns
Rise of Lone-Actor Threats and Online Radicalisation Drives New Wave of Antisemitic Attacks in the UK
Canada Advances Plan to Ban Cryptocurrency Donations in Election Campaigns
UK Faces Looming Medicine Shortages as Iran Conflict Threatens Supply Chains
Deadly Meningitis Outbreak in the U.K. Highlights Urgent Need for Vaccination
Fresh Claims Emerge Over Harry and Meghan’s Australia Visit as Insider Speaks Out
NATO Assessment Indicates UK Defence Spending Has Fallen Below Alliance Average
FTSE 100 Slips as Middle East Tensions Weigh on Investor Sentiment
UK Economy Begins to Feel Early Impact of Iran Conflict as Policy Challenges Intensify
Russian National Jailed in UK After Assault Case Linked to Barron Trump’s Alert
Energy Price Surge Accelerates Shift Away from Fossil Fuels in UK Homes
UK Museums House More Than 260,000 Human Remains, New Report Reveals
Surging UK Gilt Yields Reflect Inflation Pressures and Fiscal Uncertainty
UK Issues Updated Guidance on Children’s Screen Time with Focus on Balance and Wellbeing
UK Migration Figures Show Shifting Trends Across Asylum, Visas and Channel Crossings
UK Watchdog Launches Probe into Five Firms Over Alleged Fake Reviews and Ratings
Jaguar Land Rover Halts Production at UK Plant Amid Supplier Disruption
UK Police Reverse Position, Confirm Arrests Will Resume for Palestine Action Protests
UK Small Businesses Face Europe’s Steepest Cost Pressures, New Survey Reveals
US Envoy Urges UK to Proceed with King’s Visit Amid Diplomatic Sensitivities
FTSE 100 Drops Over One Percent as Middle East Tensions Weigh on Markets
UK CO2 Plant Set to Reopen as Authorities Move to Safeguard Supplies Amid Middle East Tensions
×