CISA warns water utilities to remove internet-exposed PLCs after disruptive attacks

CISA warns water utilities to remove internet-exposed PLCs after disruptive attacks

CISA warns water utilities to remove internet-exposed PLCs after attacks caused lockouts, disruptions and manual operations.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Aug 02, 2026

CISA has issued a new warning to water and wastewater operators after observing a significant increase in threat activity against internet-exposed programmable logic controllers, or PLCs. The July 30 alert says attackers have been targeting operational technology used in water systems and urges owners, operators and integrators to remove PLCs and other OT assets from direct public internet exposure as soon as possible.

The agency says the activity is not limited to small or poorly resourced utilities. Organizations of different sizes, including some with mature cybersecurity programs, may be exposed when controllers, cellular modems or vendor-installed remote access paths sit outside the normal IT inventory. In affected environments, attackers have changed passwords to lock operators out and modified IP addresses to disconnect PLCs from the internet, causing operational disruptions that included boil-water notices and sustained manual operations.

Why the warning matters

PLCs are not ordinary office endpoints. In water facilities they can be tied to pumps, valves, telemetry, alarms and treatment processes. A controller that is reachable from the public internet can therefore turn a basic credential or configuration failure into a disruption in physical operations. CISA also cautions that undocumented cellular modems installed by operators, vendors or system integrators can create hidden exposure even when the main network appears locked down.

The immediate mitigation is straightforward but operationally sensitive: remove PLCs and other OT devices from direct internet access. Where remote access is required, CISA recommends routing it through a VPN or secure gateway device, changing default passwords, using strong password protection, limiting access to approved IP addresses and keeping known-clean backups of PLC images. The agency separately points Rockwell Automation MicroLogix 1400 owners to vendor recovery guidance if a controller password has already been changed.

What operators should audit now

  • Public IP addresses, cellular gateways and modem links that can reach controllers.
  • Vendor-maintained remote access tools and temporary troubleshooting connections.
  • Default credentials, weak passwords and missing IP allow-lists on OT paths.
  • Availability of clean controller images and tested recovery procedures.

BleepingComputer reported on July 31 that the warning followed disruptions at more than 30 Minnesota community water systems, with some utilities moving to manual operations while responders investigated. CISA's broader message is that utilities should treat remote OT exposure as an urgent attack-surface problem, not merely a compliance checklist item. For water operators, preserving safe operations may now depend as much on finding forgotten internet paths as on patching visible systems.

Sources

Cover photo by Tom Fisk on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...