According to available reporting, Chosen Brick malware is now circulating against Windows systems at U.S. water utilities, part of a broader campaign that includes previously documented incidents. In July 2024, over 100 U.S. water utilities across 12 states experienced cyberattacks; CISA did not formally attribute those incidents at the time. August 2024 saw a suspected Iran-linked attack disable a UK power plant. More recently, U.S. agencies have warned of attackers using AI-generated scripts to target Siemens S7 programmable logic controllers (PLCs) in water, energy, and manufacturing infrastructure.
Why this matters: Water utilities operate critical infrastructure that directly affects public health and supply chains. Siemens S7 PLCs control physical processes—pressure, flow, chemical dosing—in treatment and distribution. Data-stealing malware creates two distinct risks: immediate reconnaissance for follow-on destructive attacks, and theft of operational intelligence that could inform future targeting. The combination of malware distribution via Telegram and targeting of both general Windows systems and specialized industrial control systems suggests attackers are building operational visibility across multiple layers of utility networks.
The pattern is significant. Escalation from reconnaissance (data theft) to destructive action (network shutdown, process manipulation) typically occurs in phases. The July 2024 utility attacks, the August 2024 UK power plant incident, and now Chosen Brick distribution represent data points across a 14-month window, not isolated events.
What to watch: Monitor your utility's communications for any notice of compromise or forensic activity. If you rely on a municipal water system, maintain a baseline supply of stored water (CDC recommends 1 gallon per person per day for 3 days minimum). For operators and network administrators at critical infrastructure, segregate OT (operational technology) networks from IT systems aggressively; assume that Windows system compromise may grant attackers reconnaissance access to adjacent systems. Verify that your facility has tested manual, non-networked overrides for critical processes.




