GBHackers

CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a significant rise in cyber threat activity targeting internet-exposed programmable logic controllers (PLCs).

Released on July 30, 2026, the advisory urges critical infrastructure owners, operators, and system integrators to immediately identify and remove PLCs and other operational technology (OT) assets that are directly accessible from the public internet.

CISA Urges Water Utilities to Remove Publicly Exposed

CISA reported that threat actors have been actively targeting exposed PLC devices by changing administrator passwords, locking authorized personnel out of industrial control systems, and altering IP address settings to disconnect controllers from operational networks.

This activity has already caused real impacts on affected organizations, resulting in boil water notices and the necessity for ongoing manual operations.

PLCs are crucial components in water treatment and distribution environments, automating functions such as pump control, chemical dosing, pressure management, and filtration. Unauthorized changes to these systems can disrupt service delivery and create potential safety risks.

The agency cautioned that water utilities of all sizes are being targeted, including those with established cybersecurity programs. CISA specifically highlighted the risks posed by undocumented cellular modems installed by operators, vendors, or integrators.

These connections may not be included in regular asset inventories or routine external attack-surface scans, creating unmonitored access points to sensitive OT environments.

Publicly exposed OT equipment is at higher risk for defacement, configuration manipulation, operational outages, and potentially serious physical equipment damage.

To reduce exposure, CISA recommends that organizations disconnect PLCs from the internet and refrain from allowing direct remote access to controllers.

If remote administration is necessary for operational reasons, utilities should route access through a properly secured virtual private network (VPN) or gateway device instead of connecting directly to PLC interfaces.

The agency also advises operators to enable password protections, replace default credentials, and implement IP allowlisting to restrict remote access to known engineering workstations and other approved OT assets.

Additionally, utilities should maintain a known clean backup image of each PLC after disconnecting it from the internet. This precaution can help restore operations if attackers change credentials or modify configuration settings.

CISA indicated that owners, operators, and integrators using Rockwell Automation MicroLogix 1400 PLCs should consult Rockwell Automation’s guidance for restoring controller access when the password is unknown.

This alert reinforces a long-standing principle of OT security: industrial control systems should not be exposed directly to the public internet.

CISA recommends reviewing its “Primary Mitigations to Reduce Cyber Threats to Operational Technology” guidance and the UK National Cyber Security Center’s secure connectivity principles as additional resources.

Water-sector organizations can also seek assistance through the Environmental Protection Agency’s Cybersecurity Technical Assistance Program or contact their regional CISA office.

If organizations experience suspicious activity, they should preserve relevant details, including the time of the incident, affected equipment, type of activity, operational impact, and a designated point of contact before reporting the incident to CISA, the FBI, or IC3.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.



Source link