Skip to content
Data Breach

CISA Urges Water Utilities to Remove PLCs From the Public Internet Immediately

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to water and wastewater organizations due to a rise in cyberattacks targeting internet-exposed programmable logic controllers (PLCs). PLCs are industrial devices that control critical physical processes such as...

· Jul 31, 2026 · 3 min read · 👁 1 views
CISA Urges Water Utilities to Remove PLCs From the Public Internet Immediately

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to water and wastewater organizations due to a rise in cyberattacks targeting internet-exposed programmable logic controllers (PLCs).

PLCs are industrial devices that control critical physical processes such as water treatment, pumping, chemical dosing, and wastewater management.

When these systems are accessible from the internet, attackers can attempt to alter their configurations, disrupt operations, or lock authorized personnel out of essential equipment.

CISA reported that threat actors have targeted water entities of all sizes, including those with established cybersecurity programs. In recent incidents, attackers have modified PLC passwords to prevent operators from accessing the devices.

They have also changed device IP addresses, effectively disconnecting PLCs from their managing organizations. These actions have led to operational disruptions, including boil water advisories and prolonged manual operation of water systems.

Although manual control can help maintain service during an incident, it increases pressure on staff. It may pose safety and reliability risks if disruptions persist.

CISA Urges Water Utilities

The agency warned that public exposure to vulnerabilities is not always obvious. Some operational technology assets may be connected via cellular modems installed by equipment vendors, integrators, or operators.

These connections might not appear in standard external attack-surface scans or asset inventories, leaving organizations unaware that a PLC is accessible online. CISA urges owners, operators, and system integrators to disconnect PLCs from the internet immediately.

Remote access should not connect directly to a PLC; instead, organizations should use a properly secured virtual private network (VPN) or a gateway device that provides authentication, monitoring, and access control.

Water utilities should also enforce password protection by replacing default credentials and using unique, strong passwords for each device.

Organizations should restrict remote connectivity through IP allowlisting, permitting access only from approved engineering laptops and other authorized operational technology systems.

After removing external exposure, utilities should ensure they have a clean backup of the PLC image and configuration. This is crucial in case an attacker changes a password or modifies device settings. A verified backup can help operators restore access and return equipment to a safe, known state.

CISA specifically advised operators of Rockwell Automation MicroLogix 1400 PLCs to consult Rockwell Automation guidance on restoring access when the controller password is unknown.

This alert underscores the growing threat to operational technology in the water sector. Internet-exposed operational technology devices face risks ranging from website-style defacement and unauthorized configuration changes to service outages and potential physical damage.

Utilities should examine all external connections, including any undocumented vendor-installed cellular equipment, to ensure no critical PLC is directly exposed to the public internet.

CISA recommends following its operational technology mitigation guidance. At the same time, the Environmental Protection Agency’s Cybersecurity Technical Assistance Program can offer additional support for the water sector. Organizations that detect malicious activity should report it to CISA, the FBI, or the Internet Crime Complaint Center.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you