In response to the growing threat by pro-Russia hacktivists, on May 1, 2023, CISA and other national agency partners issued an Alert to operators of industrial control systems and small-scale operational technology systems in North America and Europe on mitigation techniques for cyber operations to prevent a compromise of industrial control systems, including “Water and Wastewater Systems, Dams, Energy, and Food and Agriculture Sectors.”

The Alert, entitled “Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity”, outlines the ongoing threat posed by pro-Russia hacktivists concentrating remote control over industrial control systems, including successful attacks against several U.S.-based wastewater systems, which caused disruption in the systems, including “causing water pumps and blower equipment to exceed their normal operating parameters,…altered settings, turned off alarm mechanisms, and changed administrative passwords to lock out the WWS operators.”

The Alert provides mitigations to prevent and respond to the ongoing threat that industrial control operators may wish to review.

A Tampa, Florida area water facility was recently hacked using a popular remote-access software tool.  The unidentified hacker also used the software to connect to an on-site computer and then used that computer to access the facility’s control panel.  Once there, the hacker programmed a 100x-increase in the levels of sodium hydroxide (lye) to be added to the water supply.  While small amounts of lye are used to control the acidity of water, at these massively-increased levels, lye is corrosive. Drinking the water could be like drinking liquid drain cleaner.

There are many valuable and legitimate uses of remote-access software. This software allows a user to take full control of another computer as if they were sitting in front of it. The particular brand of remote-access software involved in this incident is popular with consumers and businesses and has more than 200 million users globally. It can be used by individuals to remotely access and troubleshoot their family members’ computer issues.  However, there are now questions about whether remote-access software is appropriate to monitor and change controls at critical infrastructure facilities.

There are alternative approaches. Some critical infrastructure facilities permit remote-access software, but only to monitor the facility systems.  Any changes must be completed on site from computers not connected to external systems or software.  Some in the critical infrastructure industry recommend requiring a secure VPN to remotely access the internal network.  After using the VPN, any additional access by the remote user would be done via a secured login with mandatory, multi-factor authentication.  Some recommend a second secure login inside the network that controls the critical infrastructure.

Industry members are quick to point out that critical infrastructure systems often have multiple safeguards to prevent extreme manipulation of the systems.  For example, many water treatment facilities have physical size restriction limits on the quantities of chemicals that can be introduced into the system over any given period. This type of safeguard could restrict the speed and/or amount of chemicals that would actually be pumped into a system, even if programmed to do so. But if a hacker can remotely access the system controls to program changes in quantity, could they possibly program other changes, such as changes to these safeguards?

In the case of the Florida water facility, any possible crisis was averted because an attentive employee saw the controls being changed, and notified the company, which notified the police. The increases in sodium hydroxide were quickly reversed.

The incident remains under investigation by the FBI and Secret Service, as well as local law enforcement officials.

See: https://www.tampabay.com/news/pinellas/2021/02/08/someone-tried-to-poison-oldsmars-water-supply-during-hack-sheriff-says/

Last week, the Australian Department of Defence announced that it will begin research and development for the use of swarms of tiny autonomous underwater vehicles (AUV) (i.e., underwater drones) to detect and clear naval mines. This research and development project will cost approximately $15 million and span over five years in partnership with Australia’s Trusted Autonomous Systems Defence Cooperative Research Centre and Thales Australia.

The goal of the project will be to assess researchers’ design, development and testing of various teams of micro AUV swarms as well as autonomous surface vessels (AUS) in order to develop new systems of defense. Teams of AUV and AUS could survey an area before manned vessels are deployed. This type of undertaking will include the ability to autonomously collect environmental data in order to conduct mine countermeasure missions. It relies heavily on artificial intelligence, big data and connectivity.

This type of investment and involvement with underwater and surface drones will surely continue to grow across the globe. In January 2020, the U.S. Navy partnered with L3Harris Technologies to test underwater drones for undersea missions. Just last month, L3 Harris Technologies received a contract from the U.S. Navy as part of a $281 million program for medium unmanned surface vehicles.

The U.S. Navy is moving fast to acquire a new unmanned surface vehicle (USV) and hopes to award a contract for the USV by the end of 2019. Over the next two months, the Navy plans to issue a request for proposals for a new, medium-sized USV, up to 50 meters long. The Navy seeks a USV that can function as a sensor and communication relay as part of a family of unmanned surface systems being developed by the Navy. Additionally, the USV will be able to carry a payload similar to that of a 40-foot shipping container, return to port, and be capable of refueling at sea. The USV will also be able to autonomously operate at a cruising speed of about 16 knots, with a minimum range of 4,500 nautical miles, operated through a government-provided communication relay system.

In addition to these USVs, the Navy plans to invest to improve the technology on its unmanned underwater vehicles as well. The Navy also plans to add 100 personnel to its explosive ordnance disposal (EOD) force so it can have a greater presence around the globe. These two additions to its fleet will allow the Navy to search bodies of water for potential dangers and neutralize threats much faster.

The Navy has eight (8) unmanned systems platoons now and will grow to 16 in the next three years. Unlike other parts of the EOD community, the men and women in the unmanned systems platoons are not EOD techs, but rather pull from a range of fleet ratings.

The Navy’s goal is to enable the unmanned vehicle to make decisions while it’s in the water, and reach a level of trust in the vehicle to make the right decisions. If the vehicle sees an object of interest, it can decide to take more passes at it so the Navy can better understand what’s there, which in turn will save team members the time of having to send out a second mission. We will provide updates on other maritime unmanned vehicle projects as the Navy invests more efforts in this area.

Cybersecurity specialists at BAE Systems and Symantec announced last week new evidence suggesting that the criminals behind the notorious 2014 attack on Sony Corp. are also responsible for recent cyber-attacks involving 104 organizations in 31 countries. Researchers and investigators have long attributed the 2014 Sony attack, which crippled computer systems and revealed internal emails, to the North Korea-linked group known as “Lazarus.” Malware recently discovered running on the computers of a Polish bank suggest that the Lazarus group is now targeting global financial institutions using a sophisticated “watering hole” technique. Continue Reading Sony Cyber-Attackers Lurking at Financial Supervisor “Watering Hole” Target Banks and Others

I apologize that this post is not light reading. It’s critically important to know what the threats are so you can avoid becoming a victim.

Although disconcerting, it is crucial to know what has happened in the first half of this year. TechCrunch recently issued a report outlining the worst breaches of 2026—so far:

  • DOGE’s massive swipe of Social Security data (I’ve discussed this  in numerous posts)
  • Hackers increased targeting of water systems and energy grids (discussed here)
  • Iranian government hackers attacking Stryker with a destructive device hack (ditto)
  • ShinyHunters’ disruptive hacking campaign against Instructure, among other targets (ShinyHunters has been a frequent subject of our posts)
  • The supply chain under attack, targeting open-source projects and big tech companies
  • FBI’s surveillance system breach, sparking a “major cyber incident“
  • Hasbro’s hack leading to weeks of downtime
  • Exposure of millions of passports and driver licenses

What can we learn from these trends?

According to TechCrunch, “the attacks are getting bolder, more destructive, and harder to contain.” The trends confirm that as technology advances, so must defenses equally. Cybersecurity measures must be sophisticated enough to block attackers so they will move on to the next victim. A mature cybersecurity posture, both personally and professionally, must be a priority to prevent becoming victimized. In a world of geopolitical discontent, cyber attackers serve as warriors for nation states, and at the same time, our own government is failing to protect our data and our warriors’ data. Unfortunately, the Cybersecurity and Infrastructure Security Agency’s funding has been decimated, so we are left to our own devices (pardon the pun).

We need to take greater responsibility for protecting our own information while demanding stronger safeguards from our government, especially for the sensitive data of current and veteran military personnel. Additionally, private companies must also do more to prevent exposure. Robust cybersecurity programs across individuals, government, and the private sector are essential. This is no longer a future concern; it is reality. Without collective action, the second half of 2026 will bring more of the same.

The Cybersecurity & Infrastructure Security Agency, the Federal Bureau of Investigation, and the National Security Agency recently issued two joint alerts to critical infrastructure entities—one addressing BlackMatter Ransomware, and the second specifically to U.S. water and wastewater systems.

BlackMatter Ransomware Alert 

On October 18, 2021, CISA/FBI/NSA issued an alert providing information to critical infrastructure entities on BlackMatter ransomware. According to the Alert, BlackMatter ransomware has been targeting critical infrastructure entities since July of 2021, “including two U.S. Food and Agriculture Sector organizations.” BlackMatter uses “embedded, previously compromised credentials…” to “leverage the Lightweight Directory Access Protocol (LDAP) and Server Message Block (SMB) protocol to access the Active Directory (AD) to discover all hosts on the network. BlackMatter then remotely encrypts the hosts and shared drives as they are found.”

The Alert outlines the technical details of BlackMatter ransomware, as well as mitigations available to organizations “to reduce the risk of compromise by BlackMatter ransomware” which include implementing backup and restoration policies and procedures, using strong, unique passwords, using multi-factor authentication, and implementing network segmentation and traversal monitoring.

Ongoing Cyber Threats to U.S. Water and Wastewater Systems Alert 

Originally released on October 14, 2021, and updated on October 25, CISA/FBI/NSA issued an alert to U.S. Water and Wastewater Systems “to highlight ongoing malicious cyber-activity—by both known and unknown actors—targeting the information technology (IT) and operational technology (OT) networks, systems and devices of U.S. Water and Wastewater Systems (WWS) Sector facilities.”

According to the Alert “This activity—which includes attempts to compromise system integrity via unauthorized access—threatens the ability of WWS facilities to provide clean, potable water to, and effectively manage the wastewater of, their communities.”

The Alert outlines the technical details and an overview of the threat, and lists mitigations to apply, including not clicking on suspicious links, secure and monitor remote desktop protocol, use strong passwords, and use multi-factor authentication.

In an excellent blog post, “Avoiding AI Pitfalls in 2026: Lessons Learned from Top 2025 Incidents,” ISACA’s Mary Carmichael summarizes lessons learned from top incidents in 2025 using MIT’s AI Incident Database and risk domains. According to Carmichael, an analysis of the incidents showed recurring patterns across different risk domains, including privacy, security, reliability, and human impact, pointing out that most problems were predictable and avoidable.

Carmichael notes that her blog post “reviews where those patterns appeared and what needs to change in 2026 so organizations can use AI with greater confidence and control.”

Consider reading the article, but in a nutshell, her lessons are:

  1. Treat AI systems like core infrastructure—enforce MFA, unique administrative accounts, privileged access reviews, and security testing, particularly where personal information is included.
  2. To combat discrimination and toxicity, facial recognition technology can be used to support investigations but should not be “the deciding evidence.” Require corroborating evidence, publish error rates by race and other characteristics, and log every use.
  3. Deepfakes are on the rise: “Organizations should monitor for misuse of their brands and leaders. This includes playbooks for rapid takedowns with platforms and training employees and the public to ‘pause and verify’ through secondary channels before responding.”
  4. Attackers are using AI models for cyber-espionage. “Assume attackers have an AI copilot. Treat coding and agent-style models as high-risk identities, with least-privilege access, rate limits, logging, monitoring, and guardrails. Any AI that can run code should be governed like a powerful engineer account, not a harmless chatbot.”
  5. Chatbots and AI companion apps have engaged in harmful conversations. Build AI products with safety-by-design: “clinical input, escalation paths, age-appropriate controls, strong limits and routes to human help. If it cannot support these safeguards, it should not be marketed as an emotional support tool for young people.”
  6. AI providers are alleged to be adding air pollution, noise, and industrial traffic to neighborhoods. Due diligence, including information on “energy mix, emissions and water use” should be collected “so AI procurement aligns with climate and sustainability goals.”
  7. AI tools are confident, but often incorrect. Hallucinations are frequent and pose safety risks. “Design every high-impact AI system with the assumption it will sometimes be confidently wrong. Build governance around that assumption with logging, version control, validation checks and clear escalation so an accountable human can catch and override outputs.”

Carmichael outlines strategic goals to consider in 2026 to leverage the lessons learned in 2025. Her final thought, near and dear to my heart, is that having an AI governance program will give organizations a competitive advantage in 2026. “Organizations that maintain visibility, clear ownership and rapid intervention will reduce harm and earn trust. With the right oversight, AI can create value without compromising safety, trust or integrity.” I couldn’t have said it better. If you have not developed and established an AI governance program yet, Q1 in 2026 is a perfect time to get started.

On July 24, 2025, the White House released the “White House AI Action Plan,” which includes over 90 policy actions focused on accelerating innovation, building AI infrastructure, and increasing international diplomacy around artificial intelligence (AI). The Plan focuses on removing regulatory barriers and requires that systems are free from ideological bias and “woke” policies.

The Plan outlines three pillars as its foundation:

  • Accelerate AI Innovation—Focuses on removing federal regulations that hinder AI development and includes seeking private sector input.
  • Build American AI Infrastructure—Focuses on streamlining permits for data centers and semiconductor manufacturing to support AI growth.
  • Leading in International Diplomacy—Focuses on promoting the export of American AI technologies and establishing global standards.

Several things of note in each pillar may give data privacy and security professionals pause, as well environmentalists. Because I fall into both categories, I wanted to point out the following:

Pillar I: Accelerate AI Innovation

  • In order to accelerate AI innovation, the current administration intends to “work with all federal agencies to identify, revise or repeal regulations, rules, memoranda, administrative orders, guidance, documents, policy statements, and interagency agreements that unnecessarily hinder AI development of deployment.”

This can be interpreted as repealing or terminating any guidelines put in place to minimize the risk of using AI tools, such as bias, hallucinations, and data leakage. Unfettered development of AI tools with no guardrails increases the already known risks of AI tool usage and allows developers to ignore the risks and mitigate against them when developing products.

  • In addition, the Office of Management and Budget will “work with Federal agencies that have AI-related discretionary funding programs to ensure, consistent with applicable law, that they consider a state’s AI regulatory climate when making funding decisions and limit funding if the state’s AI regulatory regimes may hinder the effectiveness of that funding or award.”

This can be interpreted that if a state determines that it is in its residents’ best interest to regulate the development and use of AI tools in its state, that the federal government can limit funding to the state to deter it from enacting consumer protection legislation. This is essentially a run around of the proposed moratorium on state AI regulation that has overwhelmingly failed in the past. This could have a chilling effect on appropriate regulation of AI tools by the states, since there appears there will be no regulation during this administration.

  • A mandate to “revise the NIST AI Risk Management Framework to eliminate references to misinformation, Diversity, Equity, and Inclusion, and climate change.” The concern here is obvious—ignoring DEI and climate change, well-documented risks and concerns, perpetuates bias. Completely ignoring well-documented science on how the development of data centers and AI tools affects the climate poses significant risks.
  • A requirement that the government only contracts with frontier large language model (LLM) developers who ensure that their systems are objective and free from top-down ideological bias. Whose “ideological bias” is mentioned here?

There is a clear message that the Republican ideological bias will be accepted, but any others will be rejected. Wouldn’t it be better to keep politics out of the AI systems that are being developed for use over generations? Will only right-leaning AI developers’ systems be approved to use, so only a portion of the truth is used to train the models? Doesn’t this make the models so biased as to not be worthwhile? This is a very concerning policy statement.

Pillar II: Build American AI Infrastructure

Pillar Two outlines how AI infrastructure can be developed. Some concerns mentioned in the Action Plan:

  • Streamline permitting processes for Data Centers, Semiconductor Manufacturing Facilities, and Energy Infrastructure.
  • Explore the need for a nationwide Clean Water Act Section 404 permit for data centers, and, if adopted, ensure that this permit does not require a Pre-Construction Notification.
  • Expedite environmental permitting by streamlining or reducing regulations promulgated under the Clean Air Act, the Clean Water Act, the Comprehensive Environmental Response, Compensation, and Liability Act, and other relevant related laws.
  • Make federal lands available for data center construction and the construction of power generation infrastructure for those data centers by directing agencies with significant land portfolios to identify sites suited to large-scale development. (Hopefully, not any of our national forests or parks).

There has to be a balance between allowing the free market to innovate and regulating to protect national interests. Congress has passed numerous laws over decades designed to ensure that our environment is protected, mostly because of past experience of dumping harmful toxins that affected individuals’ drinking water and manufacturing products that contribute to air and water pollution, affecting our natural wildlife.

The concerning tone here appears to attempt to short-cut the processes in place that are designed to protect our environment. We have seen in the past what happens when companies operate in unregulated industries—lead pigment, lead in water pipes, tobacco, asbestos, oil and gas spills, social media, OxyContin, and the list goes on. The impact of manufacturing data centers on our environment should not be ignored or cut short. This will impact our environment for generations and these laws have been put in place to ensure the process is followed correctly.

Don’t get me wrong: the Action Plan is not all bad. There are solid policy recommendations on cybersecurity, information sharing, and work force training. It is just too bad that it allows the development of AI tools with no regulation or guidelines, especially when we know that there are inherent risks. It’s like letting the tobacco, lead pigment, and asbestos industries manufacture away, even after there was clear evidence of the products’ hazards. The Plan could have been instrumental in shaping AI regulation for the future, so we do not end up in the same place as we did with other hazardous products. For me, it’s a bit of déjà vu, which is disappointing.

That said, on June 23, 2025, the day before the White House unveiled its plan, more than 90 organizations launched a competing “People’s AI Action Plan,” characterizing the Trump administration’s approach as “a massive handout to the tech industry” that prioritizes corporate interests over public welfare. The coalition includes labor unions, environmental justice groups, and consumer protection nonprofits.

The coalition’s concerns include: “the environmental impact of data centers, potential job displacement, and the lack of meaningful safety standards.” The short AI Action Plan is easily digestible. I urge you to read it and provide comment.

The City of Tulsa, Oklahoma, announced on May 9, 2021, that it had been hit with a ransomware attack, but the Mayor is resolute in not paying the demanded ransom. Although “all of our computer systems—with a few exceptions—are down right now,” the Mayor has stated that he will “not pay a nickel” to the attackers.

Although emergency services like fire, rescue and police are fully functional, unfortunately, the attack has caused serious disruption to the city, including the police department, which is unable to offload data from body cameras. In addition, residents are unable to pay some bills, such as water bills. While the city is restoring the system, residents will get a brief hiatus from paying bills where systems have been disrupted until five days after systems are restored.

Although IT staff are working around the clock, the Mayor said the systems will be restored in phases, and some systems may not be fully restored within a month.