Updated September 2026. Cyber attacks on critical infrastructure target the technologies, networks, and facilities that keep fuel flowing, water clean, food processed, patients treated, and goods moving. When those systems fail—even briefly—the impact shows up at gas stations, pharmacies, ports, and hospital wards, not just on a SOC dashboard.
The threat is not theoretical. Since 2021, ransomware crews and nation-state operators have repeatedly hit energy, water, food, healthcare, and transportation. Some incidents were IT ransomware that forced operators to shut OT as a precaution. Others reached programmable logic controllers (PLCs) and industrial protocols directly. The common thread: weak remote access, flat networks, and internet-exposed operational technology (OT) turn local compromises into national headaches.
This article walks through eight well-documented cases from 2021 through 2025, then covers what defenders and policymakers are doing in 2026—and what operators should prioritize now.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why critical infrastructure stays fragile
Most critical systems mix decades-old industrial controls with newer IT, cloud, and remote-access tooling. That mix improves efficiency and remote support—and expands the attack surface.
- Legacy OT often cannot run modern endpoint agents or patch on IT cadences.
- Remote access (VPN, Citrix, TeamViewer, vendor jump boxes) is frequently the first foothold.
- IT/OT convergence means a billing or corporate malware event can force operators to isolate production networks—or worse, give adversaries a path toward control systems.
- Default credentials and internet-facing HMIs/PLCs remain a recurring theme in water and industrial incidents.
CISA, sector agencies, and allies have warned for years that water/wastewater, pipelines, healthcare clearinghouses, and ports are attractive targets precisely because downtime is expensive and politically visible.
Eight major cyber attacks on critical infrastructure (2021–2025)
1. Oldsmar, Florida water treatment plant (February 2021) — Water
What happened: On February 5, 2021, an intruder remotely accessed the City of Oldsmar’s water-treatment SCADA environment (reported via TeamViewer) and briefly raised the sodium hydroxide (lye) setpoint from about 100 ppm to 11,100 ppm. A plant operator watched the change happen live and reversed it. Drinking water was not contaminated.
Impact: No public health harm, but a clear demonstration that remote-desktop access into treatment controls can become a life-safety issue within minutes.
Lesson: Shared passwords, internet-exposed operator workstations, missing firewalls, and outdated OS builds on SCADA PCs are not “small town” problems—they are systemic OT hygiene failures. Monitor setpoints, require MFA for remote access, and keep engineering tools off the public internet.
2. Colonial Pipeline (May 2021) — Energy / pipelines
What happened: On May 7, 2021, DarkSide ransomware hit Colonial Pipeline’s corporate IT environment. Operators shut down roughly 5,500 miles of refined-products pipeline as a precaution while investigating and recovering. Colonial later confirmed a ransom payment of about $4.4 million for a decryptor; pipeline operations restarted around May 12.
Impact: Fuel distribution disruptions and panic buying across parts of the U.S. East Coast. The event became a kitchen-table cybersecurity moment and accelerated federal attention on pipeline OT security (including TSA security directives) and CISA’s broader critical-infrastructure posture.
Lesson: You do not need malware in the PLC to halt a pipeline. Compromised IT billing/operations systems—and the decision to isolate OT—can still create real-world shortages. Segment IT from OT, rehearse OT islanding, and treat identity and remote access as safety-critical controls.
3. JBS Foods (May–June 2021) — Food and agriculture
What happened: In late May 2021, REvil ransomware disrupted JBS, one of the world’s largest meat processors. U.S. plants were temporarily halted; operations in other countries were also affected. JBS later said it paid about $11 million to resolve the incident after restoring systems.
Impact: Short production outages and public concern about meat supply. The case showed how a concentrated agribusiness processor can become a single point of friction for national food logistics.
Lesson: Food and agriculture are critical infrastructure. Ransomware playbooks that ignore plant-floor recovery, cold-chain logistics, and subsidiary interconnectivity leave gaps. Backup integrity and cross-site containment matter as much as endpoint tools.
4. Industroyer2 against Ukrainian energy (April 2022) — Energy / OT-ICS
What happened: In April 2022, Sandworm operators attempted to disrupt a Ukrainian energy provider using Industroyer2—malware designed to issue IEC-104 commands against high-voltage substations—alongside destructive wipers intended to hinder recovery. Defenders detected and stopped the operation before a large blackout.
Impact: No mass outage from this attempt, but a high-confidence example of purpose-built ICS attack tooling in wartime, building on earlier Industroyer/CrashOverride lineage.
Lesson: Nation-state actors invest in protocol-aware OT malware and combine it with IT destruction. Protocol monitoring, engineering-workstation hardening, and recovery plans that assume wiped Windows environments are part of modern energy defense—not niche ICS research topics.
5. DP World Australia ports (November 2023) — Transportation / ports
What happened: On November 10, 2023, DP World Australia detected unauthorized access to its Australian corporate network and disconnected systems from the internet to contain the incident. Landside operations at terminals in Melbourne, Sydney, Brisbane, and Fremantle stopped. The company resumed port operations on November 13 and reported clearing a backlog of about 30,137 containers by November 20. DP World stated it found no ransomware deployment or ransom demand, but confirmed limited employee data exfiltration.
Impact: Multi-day disruption to roughly 40% of Australia’s container freight movement—enough to stress national supply chains even without encryption malware.
Lesson: Containment choices (pulling the plug) can be correct and still costly. Port operators need resilient landside systems, tested manual workarounds, and crisis coordination with government and shippers. “No ransomware” does not mean “no critical-infrastructure impact.”
6. CyberAv3ngers / Unitronics PLCs (November 2023–January 2024) — Water / OT
What happened: IRGC-affiliated actors using the CyberAv3ngers persona compromised internet-facing Unitronics Vision Series PLCs that used default or no passwords. CISA’s joint advisory (AA23-335A, updated December 2024) assessed at least 75 compromised devices in the U.S., including at least 34 in the Water and Wastewater Systems sector. A widely reported U.S. case involved a Municipal Water Authority of Aliquippa (Pennsylvania) booster-station PLC defaced in November 2023; operators switched to manual control and reported no impact on water quality or delivery.
Impact: Localized OT disruption and a sector-wide scramble to find and lock down exposed PLCs. The campaign underlined how commodity industrial HMIs become geopolitical targets when left on the public internet.
Lesson: Never expose PLCs/HMIs directly to the internet. Change default passwords, place devices behind VPN/firewall with MFA where possible, inventory internet-reachable assets, and treat “secure by default” vendor gaps as an enterprise risk.
7. Change Healthcare (February 2024) — Healthcare
What happened: On February 21, 2024, UnitedHealth Group disclosed a cyberattack on subsidiary Change Healthcare. Public testimony and reporting described ALPHV/BlackCat affiliates using stolen credentials against a Citrix remote-access portal that lacked multifactor authentication, dwelling for days before deploying ransomware. Change took major platforms offline; pharmacies, providers, and hospitals faced weeks of claims, eligibility, and payment disruption. Sector groups described it as among the most disruptive cyber events in U.S. healthcare history.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Impact: Nationwide friction in prescriptions, prior authorizations, and provider cash flow—evidence that a concentrated clearinghouse is critical infrastructure even when it is not a hospital bedside system.
Lesson: MFA on every remote-access path is non-negotiable. Third-party concentration risk belongs in board-level resilience planning. Healthcare organizations need contingency workflows for claims and Rx when a major intermediary fails.
8. Poland energy-sector incidents (December 29, 2025) — Energy / OT
What happened: On December 29, 2025, coordinated cyberattacks hit Poland’s energy sector, including numerous renewable facilities and combined heat and power (CHP) plants, as documented by CERT Polska. A follow-up analysis described a smaller CHP plant where attackers reached OT via a misconfigured private APN path and abused a WAGO PFC200 controller, briefly interrupting a steam turbine and process-water treatment. Operators limited customer impact; heat and electricity supplies to end users were preserved.
Impact: Short operational interruptions and a fresh warning about cellular/APN-connected industrial devices—attack paths that sit outside classic “IT firewall” mental models.
Lesson: Treat private APNs and cellular OT links as hostile networks unless tightly segmented and monitored. Default credentials on edge controllers remain an open door in 2025–2026, not a 2010s problem.
What is being done in 2026
Public- and private-sector defenses have matured since Colonial and JBS, even as attackers keep adapting.
- NIST Cybersecurity Framework (CSF) 2.0 (finalized February 2024) adds a sixth function, Govern, putting leadership, risk appetite, roles, and policy on equal footing with Identify/Protect/Detect/Respond/Recover.
- CISA Cross-Sector Cybersecurity Performance Goals (CPGs) 2.0 (December 2025) align prioritized, practical controls to CSF 2.0—including governance, managed-service-provider risk, least privilege, and incident communications—aimed especially at small and mid-size operators.
- CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022) directs CISA to require covered entities to report covered cyber incidents and ransomware payments. As of 2026, CISA continues work on the final rule (rulemaking timelines have slipped). Until the rule takes effect, voluntary reporting to CISA/FBI remains important; covered entities should watch CISA’s CIRCIA page for effective dates. The statute’s intent centers on rapid reporting (commonly discussed as roughly 72 hours for covered incidents and 24 hours for ransom payments once regulations apply).
- Sector-specific pressure continues: TSA pipeline security directives after Colonial, EPA/CISA focus on water OT exposure, and healthcare performance goals after Change Healthcare.
- International cooperation (JCDC-style collaboration, allied joint advisories such as AA23-335A) shortens the time between first victim and widespread warning.
Frameworks do not patch PLCs by themselves. They do give boards and plant managers a shared language for funding MFA, segmentation, and incident drills before the next headline.
What operators should do now
Practical priorities that map to the incidents above:
- Kill default and shared passwords on HMIs, PLCs, remote-access tools, and vendor accounts. Rotate credentials after staff or integrator changes.
- Enforce phishing-resistant MFA on every remote path into IT and OT (VPN, Citrix, cloud admin, jump hosts). Change Healthcare’s Citrix foothold is the cautionary tale.
- Remove OT from the public internet. If remote engineering is required, put it behind VPN/firewall with allowlists and logging—not a raw PLC port.
- Segment IT and OT (Purdue-style zones, proxies, tightly controlled historians). Rehearse operating in island mode when IT is on fire.
- Patch and inventory internet-exposed services aggressively; use free cyber hygiene scans where available. Know every cellular/APN-connected controller.
- Back up PLC logic and configurations offline, and test restores. Keep cold-standby hardware where downtime equals public-safety risk.
- Monitor for abnormal OT behavior—setpoint changes, unexpected engineering protocols, logins from odd places—not only antivirus alerts.
- Plan for third-party concentration risk (clearinghouses, port terminals, cloud SaaS). Manual or alternate workflows matter when a vendor goes dark.
- Report early to CISA, FBI, and sector ISACs. CIRCIA will formalize more of this; sharing IOCs still helps the next operator today.
- Use CSF 2.0 Govern + CISA CPGs as the board checklist: owners, risk decisions, and funding—not just a binder of policies.
For broader context on attack patterns, see our overview of types of cyber attacks and practical notes on ransomware.
Bottom line
From Oldsmar’s water plant to Colonial’s pipeline, Change Healthcare’s claims network, and 2025 energy OT incidents in Poland, the pattern is consistent: adversaries go where downtime hurts, and they often start with weak identity and exposed remote access—not exotic zero-days. Defenders who treat MFA, OT internet exposure, IT/OT segmentation, and governance as safety controls—not IT nice-to-haves—are far better positioned for 2026 and beyond.
Sources
- CISA — The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done Over the Past Two Years
- Idaho National Laboratory CyOTE — Case Study: DarkSide Ransomware Attack on Colonial Pipeline
- Reuters — Hackers try to contaminate Florida town’s water supply through computer breach (Oldsmar)
- CNN Business / public reporting — JBS Foods ransomware (May–June 2021); see also CBS News coverage of the reported $11 million payment
- ESET WeLiveSecurity — Industroyer2: Industroyer reloaded
- DP World Australia — Media Statement: Update on Cybersecurity Incident (28 November 2023)
- CISA — AA23-335A: IRGC-Affiliated Cyber Actors Exploit PLCs… (Unitronics / CyberAv3ngers)
- CBS Pittsburgh — Municipal Water Authority of Aliquippa Unitronics incident reporting (November 2023)
- American Hospital Association — Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness
- Cybersecurity Dive — coverage of UnitedHealth testimony on Change Healthcare Citrix access without MFA
- CISA — #StopRansomware: ALPHV Blackcat (AA23-353A)
- CERT Polska — Energy Sector Incident Report – 29 December 2025; Follow-Up Report
- NIST — Cybersecurity Framework 2.0
- CISA — Cross-Sector Cybersecurity Performance Goals
- CISA — CIRCIA
FAQ
Which sectors count as critical infrastructure?
Energy, water, transportation, healthcare, communications, financial services, and government systems — plus the IT/OT vendors that keep them running.
Why do ransomware crews target OT environments?
Downtime is existential for operators, so payment pressure is high. Flat networks and aging HMIs still show up in post-incident reports.
Is air-gapping still realistic?
True air gaps are rare. Assume remote access, vendors, and update channels exist — then monitor and constrain them.
What should defenders do after a sector advisory?
Map the advisory to your assets within 24 hours, patch or compensate, and verify detection coverage. Frameworks help prioritize; the brief flags what just became urgent.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
How to Pass CompTIA CySA+ in 2026 (CS0-004 Study Guide)
CompTIA CySA+ V4 (CS0-004) study guide for 2026: domains, V3 retirement timeline, a practical lab-first plan, and how CySA+ fits with Security+...
Are Your AI-Powered Security Tools Vulnerable to Adversarial Inputs?
AI security tools can miss threats when attackers craft adversarial inputs. Here’s how malware, phishing, and behavior models get fooled — and...
The 5-Minute Cyber Brief: September 18, 2026
Friday clock stories: Cisco ISE root bypass due Saturday, Acronis hosting LPE, MikroTik MikroTrick, Check Point management root.
Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.