CISA Warns Water Utilities: Remove Exposed PLCs From Public Internet
Key Takeaways The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to water and wastewater utilities. The warning addresses a surge in cyberattacks specifically...
Key Takeaways
- The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory to water and wastewater utilities.
- The warning addresses a surge in cyberattacks specifically targeting Programmable Logic Controllers (PLCs) that are directly exposed to the public internet.
- Attackers have been observed altering PLC configurations, changing passwords, and modifying IP addresses, leading to operational disruptions and manual system overrides.
- CISA strongly advises immediate disconnection of internet-exposed PLCs and the implementation of secure remote access solutions like VPNs.
CISA Sounds Alarm on Exposed PLCs in Water Sector
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert to organizations within the water and wastewater sectors, highlighting a significant increase in cyberattacks. These incidents specifically target Programmable Logic Controllers (PLCs) that are directly accessible from the public internet, posing substantial risks to critical infrastructure operations.
Table Of Content
PLCs are foundational industrial control devices responsible for automating vital physical processes, including water purification, pumping stations, chemical treatment, and wastewater management. Direct internet exposure of these systems creates a severe vulnerability, allowing malicious actors to potentially manipulate configurations, disrupt essential services, or lock out authorized personnel from crucial equipment.
CISA’s reporting indicates that threat actors are indiscriminately targeting water entities, regardless of their size or the maturity of their existing cybersecurity frameworks. Recent attacks have involved threat actors altering PLC passwords, effectively preventing operators from accessing and controlling their own devices. Furthermore, attackers have been observed changing device IP addresses, severing the connection between PLCs and their managing organizations. These actions have resulted in significant operational disruptions, including the issuance of boil water advisories and prolonged periods where water systems must be managed manually.
While manual control can serve as a temporary measure to maintain service during an incident, it places considerable strain on staff. Moreover, sustained disruptions under manual operation can introduce safety hazards and compromise the long-term reliability of water infrastructure.
Undocumented Exposure and Mitigation Strategies
CISA emphasized that the public exposure of these critical operational technology (OT) assets is not always immediately apparent. Many OT systems may be connected to the internet via cellular modems installed by equipment vendors, system integrators, or even operators themselves. These types of connections often bypass standard external attack-surface scans or asset inventories, leaving organizations unaware that a vital PLC is directly exposed online. For this reason, CISA urges asset owners, operators, and system integrators to immediately disconnect any PLCs found to be directly accessible from the internet.
The agency advises against direct internet connectivity for remote access to PLCs. Instead, organizations should implement properly secured virtual private networks (VPNs) or utilize gateway devices that offer robust authentication, comprehensive monitoring, and stringent access control mechanisms. Water utilities are also advised to enforce strong password policies, mandating the replacement of all default credentials with unique, complex passwords for each individual device.
To further bolster security, organizations should implement IP allowlisting for remote connectivity, restricting access exclusively to approved engineering laptops and other authorized operational technology systems. Following the removal of external exposure, it is critical for utilities to ensure they possess clean, verified backups of PLC images and configurations. This measure is paramount for restoring access and returning equipment to a secure, known operational state in the event of password changes or configuration modifications by an attacker.
CISA specifically directed operators of Rockwell Automation MicroLogix 1400 PLCs to consult official Rockwell Automation guidance for procedures on restoring access when the controller password is unknown. This alert highlights the escalating threat landscape facing operational technology within the water sector, where internet-exposed devices are vulnerable to a spectrum of attacks, from website defacement and unauthorized configuration changes to service outages and potential physical damage.
Utilities must conduct thorough examinations of all external connections, including any undocumented cellular equipment installed by vendors, to confirm that no critical PLC is directly exposed to the public internet. CISA further recommends adherence to its comprehensive operational technology mitigation guidance. Additionally, the Environmental Protection Agency’s Cybersecurity Technical Assistance Program offers specialized support for the water sector. Organizations that detect any malicious activity are urged to report it promptly to CISA, the FBI, or the Internet Crime Complaint Center (IC3).
What You Should Do
- Immediately Disconnect Exposed PLCs: Identify and remove any PLCs directly accessible from the public internet.
- Implement Secure Remote Access: Utilize VPNs or secure gateway devices with strong authentication, monitoring, and access controls for all remote PLC access.
- Enforce Strong Password Policies: Replace all default credentials and use unique, complex passwords for every PLC and associated device.
- Restrict Remote Connectivity: Implement IP allowlisting to permit remote access only from authorized engineering workstations and OT systems.
- Maintain Verified Backups: Create and regularly verify clean backups of all PLC images and configurations to facilitate rapid recovery from attacks.
- Audit External Connections: Conduct a comprehensive audit of all external connections, including vendor-installed cellular modems, to ensure no critical OT assets are inadvertently exposed.
- Report Incidents: Report any detected malicious activity to CISA, the FBI, or the Internet Crime Complaint Center (IC3).
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.