Targeting the taps: Why foreign hackers are striking Quebec’s water plants | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Listen to this article

Estimated 4 minutes

The audio version of this article is generated by AI-based technology. Mispronunciations can occur. We are working with our partners to continually review and improve the results.

For the mayor of Saint-Noël – a municipality of fewer than 400 residents in Quebec’s Bas-Saint-Laurent region – watching a video of hackers playing around with the computer system of the local drinking water treatment station was surprising at first –  then angering. 

“For Saint-Noël to get hacked by people in Russia, it’s funny, and it’s not,” said Gilbert Marquis.

The video was posted on July 24 on the Telegram account of a group called Z-Pentest Alliance. In it, upbeat music plays over the screen recording of a computer interface, the French inscription at the top reading “St-Noel drinking water.” A cursor is seen adjusting chlorine dosage settings.

The mayor insists that water quality wasn’t affected. 

“Fortunately, the plant went into safe mode, on standby. So, the drinking water wasn’t contaminated,” Marquis said. 

He added that the hackers didn’t gain access to citizens’ sensitive information because the facility’s network isn’t connected to anything else.

After several similar attacks in the United States, the country’s Cybersecurity and Infrastructure Security Agency issued an advisory in 2025, warning that pro-Russia hacktivists were conducting opportunistic attacks on critical infrastructure in the U.S and globally, listing Z-Pentest Alliance and NoName057(16) as some of the groups with suspected links to Russia’s military intelligence agency.

WATCH | Small Quebec municipality targeted in cyberattack:

Why would Russian hackers target a water treatment plant in eastern Quebec?

The water treatment plant is located in Saint-Noël, a small municipality of fewer than 400 residents in eastern Quebec. Its mayor, Gilbert Marquis, says the hackers didn’t access any sensitive information and the water remains potable.

A Canadian federal agency also documented a hacking incident in another Quebec water treatment plant last year, without disclosing an exact location. According to the report, NoName claimed to be behind the attack.

The  Canadian Centre for Cyber Security explained, in a recent report, that water systems are almost certainly a strategic target for state-sponsored actors to demonstrate force through disruptive cyberthreats.

Targeting “low-hanging fruit” to gather Canadian intel

While problems at the plant in Saint-Noël were detected and addressed immediately by a municipal employee, it was cybersecurity expert Steve Waterhouse, who flagged the issue was linked to a cyberattack. 

Waterhouse has served as an information security officer at the Department of National Defence and as assistant deputy minister at Quebec’s Cybersecurity Ministry. He currently provides cybersecurity guidance to small and medium-sized businesses.

“In my practice, I go about and look at international events, especially those that are affecting Canada and Quebec,” he says. “This one popped up immediately.” 

Waterhouse says he reached out to the authorities, including government agencies and police, after discovering two messages posted by the Russian group.

He says one of the posts indicated that hackers had also breached an oil and gas facility elsewhere in the country, saying they were on a mission to work against Canada.

Certified cybersecurity and privacy expert Claudiu Popa says there are multiple reasons for international groups to target municipal-level governments, which can have weaker cybersecurity.

For one, it can be about self-promotion: if they plan to sell their services to foreign governments – it’s a way for them to show that they can hack into state systems.

“In other cases, it’s just for information gathering. This is a great way to gather up intel at the municipal level so that they can apply those lessons learned at the provincial or even the federal level,” Popa said.

Both Popa and Waterhouse believe the federal government should standardize and implement cybersecurity protocols across all levels of government.

“Otherwise hackers will continue to choose the low-hanging fruit and harm those communities potentially (…) or introduce the threat of terrorism which is obviously very, very significant here in our country,” Popa says.

CBC reached out to Public Safety Canada for comment but did not get a response by deadline.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW