- CISA and the FBI have confirmed that Volt Typhoon, a Chinese state-sponsored threat group, maintains persistent, pre-positioned access inside U.S. energy, water, communications, and transportation IT networks right now, not as a hypothetical future risk.
- CISA's own guidance names MFA, alongside patching, logging, and retiring end-of-life systems, as one of the four fundamentals utilities are most commonly missing.
- More than 30 Minnesota water systems were hit in a coordinated 2026 attack rooted in default factory credentials and un-revoked former-employee access, the same failure pattern EPA found in over 70% of the drinking water systems it inspected.
- Continuous, presence-aware authentication closes the credential-based entry point at the IT and workstation layer, the layer CISA's own mitigation guidance targets, without claiming to secure OT or SCADA devices directly.
Yes, per CISA, the FBI, and the 2026 ODNI Annual Threat Assessment, all of which confirm that Volt Typhoon maintains active, persistent access inside U.S. critical infrastructure IT networks today. The group's goal is pre-positioning for potential future disruption, and CISA's own advisory names basic cyber hygiene, patching, MFA, logging, and end-of-life system management, as the mitigation utilities most commonly get wrong.
This piece covers what is confirmed about the threat, a live 2026 example, and where authentication actually fits in the response.
What CISA and the FBI Have Confirmed About Volt Typhoon
Volt Typhoon is a real, ongoing, government-confirmed threat, not an invented urgency angle, and CISA names it specifically in energy, water and wastewater, communications, and transportation sectors.
CISA and the FBI describe Volt Typhoon as a Chinese state-sponsored, PLA/MSS-affiliated advanced persistent threat group that maintains persistent, pre-positioned access inside U.S. critical infrastructure IT networks to enable lateral movement into operational technology assets for potential future disruption (CISA advisory AA24-038A). This activity is confirmed still active as of the 2026 ODNI Annual Threat Assessment.
CISA's own stated top mitigation against it is patching, MFA, logging, and retiring end-of-life systems, which puts phishing-resistant, continuous-session MFA directly inside CISA's own recommended response, not adjacent to it.
A Live 2026 Example: The Minnesota Water Attacks
More than 30 Minnesota community water systems were hit in a coordinated July 2026 attack, and the confirmed root cause was unchanged default factory credentials and inconsistent revocation of former-employee access, not a novel exploit.
The intrusions used internet-exposed Rockwell Automation MicroLogix programmable logic controllers reachable directly from the internet; no novel exploit or custom malware was involved. Once in, the actors remotely changed the PLCs' own IP addresses and passwords, locking operators out and blinding them to what the controllers were monitoring or driving. At least seven states reported affected utilities to the FBI, officials noted no ransom demand and described the apparent intent as disruption rather than financial gain, and drinking water itself was never compromised or contaminated in any affected city.
To be precise about scope: as reported, this specific incident looks like direct PLC-level compromise, the PLC itself was internet-facing and its own credentials were changed, not an IT-network credential compromise that then moved laterally into OT. Official mitigation guidance from CISA and Minnesota IT Services repeatedly cited across coverage: disconnect OT from the public internet where possible, replace all default credentials, enforce MFA network-wide, and separate corporate and business networks from OT.
The EPA Finding That Makes This a Sector-Wide Problem
EPA's own enforcement alert found that more than 70% of the drinking water systems it inspected since September 2023 violate basic cybersecurity requirements, citing unchanged default passwords, shared logins, and un-revoked former-employee access by name.
Community water systems serving more than 3,300 people must certify a Risk and Resilience Assessment to EPA under the Safe Drinking Water Act Section 1433, and that assessment is required by statute to address the security of electronic and automated systems. EPA's enforcement alert, issued May 2024 and updated July 2025, states it will pursue increased inspections and, where warranted, civil and criminal enforcement, including for false certifications.
This EPA finding is a separate, independently sourced fact from the Minnesota root-cause reporting above; both point to the same underlying credential-hygiene failure across the sector, but they should be cited to their own sources rather than conflated into a single claim.
Why This Is a Workstation-Layer Problem
Volt Typhoon's playbook and the credential failures EPA found both target the IT and workstation layer, exactly where continuous, presence-aware authentication removes the credential these attacks depend on.
To be precise about scope: Proximia secures Windows-based IT workstations. It does not secure OT, ICS, or SCADA devices directly, and it does not replace the network segmentation NERC CIP-005-7 separately requires. Within that scope, biometric plus XiFi Card authentication replaces password-based login for shared control-room and operations-center workstations, and Continuous Session Protection locks the session the moment an operator steps away, closing the unattended-shared-terminal gap that a network perimeter or SIEM alone does not address.
Because there is no password or one-time code, the credential-harvesting and phishing techniques Volt Typhoon and similar actors rely on for initial IT-network access lose their target at the workstation layer. For electric utilities specifically, NERC CIP-005-7 Requirement R2.2 makes MFA mandatory for interactive remote access to High and Medium Impact BES Cyber Systems; the accurate claim is that Proximia supports the MFA requirement within NERC CIP-005-7, not a flat "NERC CIP compliant" claim. Immutable, per-session audit logs support the access-control evidence NERC CIP audits require, generated as a byproduct of normal operation.
What This Means for Utility IT Teams Now
With CISA naming MFA as one of four fundamentals against a confirmed, active nation-state threat, and EPA already citing credential hygiene failures in the majority of systems it inspects, this is a current risk conversation for utility IT teams, not a future one.
For a typically lean utility IT team, closing this gap means fewer password-reset help desk tickets and continuous, auditable session-level evidence for compliance reviews, generated as a byproduct of normal operation rather than a separate exercise. No active Proximia customer deployment exists in this vertical yet; this is offered as current, verified threat and regulatory context for a conversation utility security teams are already having, not as a claim of field-proven results specific to utilities.
Ready to Close the Gap?
See how Proximia supports the MFA requirement within NERC CIP-005-7 and removes the default-credential failure pattern CISA and EPA keep finding. Schedule a demo at proximia.com/contact.
Frequently Asked Questions
Does Proximia secure our OT or SCADA systems?
No. Proximia secures Windows-based IT workstations only. It does not replace OT or ICS-specific defenses, and it does not replace the network segmentation NERC CIP-005-7 separately requires.
Would this have stopped the Minnesota water attacks?
As reported, those attacks targeted internet-exposed PLCs directly using default credentials, a different layer than the IT workstation authentication Proximia secures. The relevance here is closing the same category of credential-hygiene failure at the IT layer before it can become a foothold, not a claim about that specific incident.
Can this work in a control room where downtime is not tolerable?
It deploys per workstation without requiring a broader infrastructure change, though this has not yet been independently validated in a control-room environment specifically, since no active utility customer deployment exists at this time.
Does deploying this make us NERC CIP compliant?
It supports the MFA requirement specifically within NERC CIP-005-7 Requirement R2.2. Overall NERC CIP compliance is assessed across many requirements at the utility level, not certified at the vendor level.
What about utilities outside electric, like water or gas?
Water utilities fall under a different framework, the Safe Drinking Water Act Section 1433 and America's Water Infrastructure Act Section 2013, rather than NERC CIP. The underlying credential-hygiene problem EPA has documented applies across subsectors even though the specific regulatory driver differs.




