Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New SSH Bot Profiles Linux Systems Before Deploying Crypto Miner
July 31, 2026
DeepSeek-Powered Hermes Agent Autonomous Cyberattacks Target Exposed Servers
July 31, 2026
ShutterGap Flaw Exposes AWS Resources Between Security Scans
July 31, 2026
Home/CyberSecurity News/CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet
CyberSecurity News

CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet

Key Takeaways The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to water and wastewater utilities. The warning addresses a surge in cyberattacks specifically...

David kimber
David kimber
July 31, 2026 4 Min Read
4 0

Key Takeaways

  • The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to water and wastewater utilities.
  • The warning addresses a surge in cyberattacks specifically targeting Programmable Logic Controllers (PLCs) that are directly exposed to the public internet.
  • Attackers have been observed altering PLC configurations, changing passwords, and modifying IP addresses, leading to operational disruptions and manual system overrides.
  • CISA strongly advises immediate disconnection of internet-exposed PLCs and the implementation of secure remote access solutions like VPNs.

CISA Sounds Alarm on Exposed PLCs in Water Sector

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert to organizations within the water and wastewater sectors, highlighting a significant increase in cyberattacks. These incidents specifically target Programmable Logic Controllers (PLCs) that are directly accessible from the public internet, posing substantial risks to critical infrastructure operations.

Table Of Content

  • Key Takeaways
  • CISA Sounds Alarm on Exposed PLCs in Water Sector
  • Undocumented Exposure and Mitigation Strategies
  • What You Should Do

PLCs are foundational industrial control devices responsible for automating vital physical processes, including water purification, pumping stations, chemical treatment, and wastewater management. Direct internet exposure of these systems creates a severe vulnerability, allowing malicious actors to potentially manipulate configurations, disrupt essential services, or lock out authorized personnel from crucial equipment.

CISA’s reporting indicates that threat actors are indiscriminately targeting water entities, regardless of their size or the maturity of their existing cybersecurity frameworks. Recent attacks have involved threat actors altering PLC passwords, effectively preventing operators from accessing and controlling their own devices. Furthermore, attackers have been observed changing device IP addresses, severing the connection between PLCs and their managing organizations. These actions have resulted in significant operational disruptions, including the issuance of boil water advisories and prolonged periods where water systems must be managed manually.

While manual control can serve as a temporary measure to maintain service during an incident, it places considerable strain on staff. Moreover, sustained disruptions under manual operation can introduce safety hazards and compromise the long-term reliability of water infrastructure.

Undocumented Exposure and Mitigation Strategies

CISA emphasized that the public exposure of these critical operational technology (OT) assets is not always immediately apparent. Many OT systems may be connected to the internet via cellular modems installed by equipment vendors, system integrators, or even operators themselves. These types of connections often bypass standard external attack-surface scans or asset inventories, leaving organizations unaware that a vital PLC is directly exposed online. For this reason, CISA urges asset owners, operators, and system integrators to immediately disconnect any PLCs found to be directly accessible from the internet.

The agency advises against direct internet connectivity for remote access to PLCs. Instead, organizations should implement properly secured virtual private networks (VPNs) or utilize gateway devices that offer robust authentication, comprehensive monitoring, and stringent access control mechanisms. Water utilities are also advised to enforce strong password policies, mandating the replacement of all default credentials with unique, complex passwords for each individual device.

To further bolster security, organizations should implement IP allowlisting for remote connectivity, restricting access exclusively to approved engineering laptops and other authorized operational technology systems. Following the removal of external exposure, it is critical for utilities to ensure they possess clean, verified backups of PLC images and configurations. This measure is paramount for restoring access and returning equipment to a secure, known operational state in the event of password changes or configuration modifications by an attacker.

CISA specifically directed operators of Rockwell Automation MicroLogix 1400 PLCs to consult official Rockwell Automation guidance for procedures on restoring access when the controller password is unknown. This alert highlights the escalating threat landscape facing operational technology within the water sector, where internet-exposed devices are vulnerable to a spectrum of attacks, from website defacement and unauthorized configuration changes to service outages and potential physical damage.

Utilities must conduct thorough examinations of all external connections, including any undocumented cellular equipment installed by vendors, to confirm that no critical PLC is directly exposed to the public internet. CISA further recommends adherence to its comprehensive operational technology mitigation guidance. Additionally, the Environmental Protection Agency’s Cybersecurity Technical Assistance Program offers specialized support for the water sector. Organizations that detect any malicious activity are urged to report it promptly to CISA, the FBI, or the Internet Crime Complaint Center (IC3).

What You Should Do

  • Immediately Disconnect Exposed PLCs: Identify and remove any PLCs directly accessible from the public internet.
  • Implement Secure Remote Access: Utilize VPNs or secure gateway devices with strong authentication, monitoring, and access controls for all remote PLC access.
  • Enforce Strong Password Policies: Replace all default credentials and use unique, complex passwords for every PLC and associated device.
  • Restrict Remote Connectivity: Implement IP allowlisting to permit remote access only from authorized engineering workstations and OT systems.
  • Maintain Verified Backups: Create and regularly verify clean backups of all PLC images and configurations to facilitate rapid recovery from attacks.
  • Audit External Connections: Conduct a comprehensive audit of all external connections, including vendor-installed cellular modems, to ensure no critical OT assets are inadvertently exposed.
  • Report Incidents: Report any detected malicious activity to CISA, the FBI, or the Internet Crime Complaint Center (IC3).

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecuritySecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

PHP Patches Critical SQL Injection, Memory Corruption Flaws

Next Post

Astaroth Malware Spreads via WhatsApp to Steal Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet
July 31, 2026
PHP Patches Critical SQL Injection, Memory Corruption Flaws
July 31, 2026
Gentlemen Ransomware Terminates 180 Security Processes Before Encryption
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us