{"id":110945,"date":"2026-06-30T23:04:09","date_gmt":"2026-06-30T23:04:09","guid":{"rendered":"https:\/\/www.europesays.com\/canada\/110945\/"},"modified":"2026-06-30T23:04:09","modified_gmt":"2026-06-30T23:04:09","slug":"russian-water-system-hack-attempted-to-turn-canada-dry","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/canada\/110945\/","title":{"rendered":"Russian Water System Hack Attempted to Turn Canada Dry"},"content":{"rendered":"<p>                    Hackers Said They Gained Access to Pumps, Chlorine Dosing and Pressure Settings<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.govinfosecurity.com\/authors\/shaun-waterman-i-7453\" rel=\"nofollow noopener\" target=\"_blank\">Shaun Waterman<\/a>                                                     \u2022<br \/>\n                        June 30, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.cuinfosecurity.com\/russian-water-system-hack-attempted-to-turn-canada-dry-a-32122#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/canada\/wp-content\/uploads\/2026\/06\/russian-water-system-hack-attempted-to-turn-canada-dry-image_large-5-a-32122.jpg\" alt=\"Russian Water System Hack Attempted to Turn Canada Dry\" class=\"img-responsive \"\/><br \/>\n                Image: Shutterstock            <\/p>\n<p>Canada&#8217;s Communications Security Establishment, the Maple Leaf version of the U.S. National Security Agency, refreshed a warning to the country&#8217;s water sector, revealing for the first time that Russian hackers attacked operational technology systems at a Quebec municipality utility last year.<\/p>\n<p>See Also: <a href=\"https:\/\/www.govinfosecurity.com\/beat-breach-outsmart-attackers-secure-cloud-a-32006?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Beat the Breach: Outsmart Attackers and Secure the Cloud<\/a><\/p>\n<p>The spy agency&#8217;s latest <a href=\"https:\/\/www.cse-cst.gc.ca\/en\/accountability\/transparency\/reports\/communications-security-establishment-canada-annual-report-2025-2026\" target=\"_blank\" rel=\"nofollow noopener\">annual report<\/a>, published Monday, <a href=\"https:\/\/www.cse-cst.gc.ca\/en\/accountability\/transparency\/reports\/communications-security-establishment-canada-annual-report-2025-2026#:~:text=Spotlight%3A%20Unauthorized%20access%20to%20a%20Quebec%20water%20treatment%20plant\" target=\"_blank\" rel=\"nofollow noopener\">did not identify<\/a> the municipality, or provide any technical details of the intrusion. It did reveal that CSE found out about the hack on Oct. 7 from an online claim of responsibility made by NoName057(16), a Russian hacker group. <\/p>\n<p>CSIRTAmericas, a multi-national incident response clearing house that&#8217;s part of the Organization of American States, &#8220;relayed NoName\u2019s claim of unauthorized access to a Quebec municipality\u2019s water treatment plant,&#8221; the report states. The hackers claimed they had achieved &#8220;the ability to covertly control pumps, chlorine dosing, pressure settings and monitoring\/alerts systems.&#8221;<\/p>\n<p>The report does not make clear whether the claim of access by NoName is accurate or not, and Russian hacktivist groups often make unfounded claims about their operations. Such claims are an important part of the <a href=\"https:\/\/www.govinfosecurity.com\/russian-attacks-on-polish-water-utilities-use-fear-as-weapon-a-31681\" rel=\"nofollow noopener\" target=\"_blank\">information-warfare aspect<\/a> of their campaigns (see: <a href=\"https:\/\/www.govinfosecurity.com\/google-kremlin-expands-ai-backed-campaigns-across-europe-us-a-32120\" rel=\"nofollow noopener\" target=\"_blank\">Google: Kremlin Expands AI-Backed Campaigns Across Europe, US<\/a>).<\/p>\n<p>A CSE spokesperson, who asked for anonymity, said in a statement the agency &#8220;cannot provide further information.&#8221; The statement touted the work of CSE&#8217;s Cyber Centre with the CSIRTAmericas Network, and other international partners, saying they &#8220;work together to identify, assess and mitigate cyberthreats.&#8221;<\/p>\n<p>The failure of the utility to independently detect the attack illustrates the difficulty of adequately defending OT, given the rudimentary state of security in many OT operators.  <\/p>\n<p>NoName was identified in a U.S. <a href=\" https:\/\/ismg-cdn.nyc3.cdn.digitaloceanspaces.com\/asset_files\/external\/usa-v-dubranova-et-al-indictment-noname.pdf\" target=\"_blank\">indictment<\/a> unsealed in December as a &#8220;covert project&#8221; of Russian state security whose membership included many staff members of The Center for the Study and Network Monitoring of the Youth Environment, &#8220;an information technology organization established by order of the President of Russia in October 2018.&#8221;<\/p>\n<p>The indictment charged Ukrainian national Victoria Eduardovna Dubranova for her role in conducting cyberattacks and computer hacking intrusions against critical infrastructure organizations and other victims in Europe and beyond. She was arrested and extradited to the United States in 2025 (see: <a href=\"https:\/\/www.govinfosecurity.com\/us-warns-ongoing-pro-russia-critical-infrastructure-hacks-a-30263\" rel=\"nofollow noopener\" target=\"_blank\"> US Warns of Ongoing Pro-Russia Critical Infrastructure Hacks<\/a>).<\/p>\n<p>A takedown of NoName infrastructure <a href=\"https:\/\/www.eurojust.europa.eu\/news\/hacktivist-group-responsible-cyberattacks-critical-infrastructure-europe-taken-down\" target=\"_blank\" rel=\"nofollow noopener\">conducted by European authorities<\/a> in July 2025 didn&#8217;t stick, according to the Nordic Observatory for Digital Media and Information Disorder, an independent non-profit monitoring cyber and information warfare. The group <a href=\"https:\/\/www.nordishub.eu\/when-denmark-sweden-norway-or-finland-hold-elections-or-do-anything-that-goes-against-the-interests-of-russia-hacktivists-pester-the-nordic-countries-nordis-has-monitored-the-hackers\/\" target=\"_blank\" rel=\"nofollow noopener\">reported<\/a> that NoName ceased operations only for a few weeks. <\/p>\n<p>The U.S. Department of State <a href=\"https:\/\/rewardsforjustice.net\/rewards\/noname05716\/\" target=\"_blank\" rel=\"nofollow noopener\">offers a reward up to $10 million<\/a> for information leading to the &#8220;identification or location&#8221; of any members of the group, which it said had conducted more than 1,500 distributed denial-of-service attacks on websites of governments, news agencies, militaries, telecom providers and other critical infrastructure in Ukraine and neighboring NATO members &#8211; including Estonia, Finland, Lithuania, Norway, Poland and Sweden &#8211; as part of the Russian grey zone campaign against Ukraine&#8217;s allies.<\/p>\n<p>The CSE warned the water sector twice last year: In October about the risk to internet-exposed ICS and OT systems in critical infrastructure. And the following month about possible <a href=\"https:\/\/www.cyber.gc.ca\/en\/guidance\/cyber-threat-canadas-water-systems-assessment-mitigation\" target=\"_blank\" rel=\"nofollow noopener\">cyberthreats to water utilities<\/a> more generally.<\/p>\n","protected":false},"excerpt":{"rendered":"Hackers Said They Gained Access to Pumps, Chlorine Dosing and Pressure Settings Shaun Waterman \u2022 June 30, 2026&hellip;\n","protected":false},"author":2,"featured_media":110946,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[38729,17,38723,8083,38727,38362,8272,38715,38728,38730,38724,38716,38725,38717,38709,38726,38718,32699,38710,38713,38714,2989,38712,38711,1802,38719,38720,38721,10595,38722,1182],"class_list":["post-110945","post","type-post","status-publish","format-standard","has-post-thumbnail","category-canada","tag-business-continuity","tag-canada","tag-clinger-cohen-act","tag-congress","tag-coso","tag-cyber-security","tag-cybersecurity","tag-defense-department","tag-diacap","tag-disaster-recovery","tag-e-government-act","tag-energy-department","tag-fiscam","tag-government-accountability-office","tag-government-information-security","tag-hipaa","tag-homeland-security-department","tag-identity-theft","tag-information-security","tag-information-security-articles","tag-information-security-events","tag-information-security-news","tag-information-security-webinars","tag-information-security-white-papers","tag-legislation","tag-national-security-agency","tag-nist","tag-office-of-management-and-budget","tag-risk-management","tag-us-cert","tag-white-house"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/110945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/comments?post=110945"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/110945\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media\/110946"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media?parent=110945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/categories?post=110945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/tags?post=110945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}