VYPR
advisoryPublished Jul 31, 2026· 1 source

CISA Issues Urgent Warning to Water Utilities: Disconnect Internet-Exposed PLCs

CISA has issued an urgent warning to water and wastewater organizations to immediately remove internet-exposed programmable logic controllers (PLCs) from public access due to rising cyberattacks.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to water and wastewater organizations, directing them to immediately disconnect internet-exposed programmable logic controllers (PLCs) from public access. This directive comes in response to a concerning increase in cyberattacks targeting these critical industrial devices, which are essential for managing water treatment, pumping, chemical dosing, and wastewater management processes.

Threat actors are actively exploiting the public accessibility of these PLCs to alter configurations, change passwords, and disrupt vital operations. CISA reports that these attacks have affected water entities of all sizes, including those with existing cybersecurity measures in place. In several recent incidents, attackers have successfully modified PLC passwords, effectively locking out authorized operators, and have even changed device IP addresses, severing remote management capabilities. These malicious actions have led to significant operational disruptions, including the issuance of boil water advisories and prolonged reliance on manual system operation.

CISA emphasizes that the public exposure of these operational technology (OT) assets may not always be obvious. Some PLCs might be connected via cellular modems installed by vendors, integrators, or operators, making them invisible to standard external attack-surface scans or asset inventories. This lack of visibility can leave organizations unaware that critical equipment is accessible online, creating a hidden vulnerability.

To mitigate these risks, CISA strongly advises owners, operators, and system integrators to disconnect PLCs from the internet without delay. The agency recommends that remote access should never connect directly to a PLC. Instead, organizations should implement secure virtual private network (VPN) connections or utilize gateway devices that enforce robust authentication, monitoring, and access control measures. Furthermore, enforcing strong password policies by replacing default credentials with unique, strong passwords for each device is crucial.

Water utilities are also urged to restrict remote connectivity through IP allowlisting, ensuring that access is granted only from approved engineering laptops and other authorized OT systems. After securing devices against external exposure, it is imperative for organizations to maintain clean, verified backups of PLC images and configurations. These backups are vital for restoring access and returning equipment to a safe, known state in the event of a password change or configuration modification by an attacker.

CISA specifically highlighted guidance for operators of Rockwell Automation MicroLogix 1400 PLCs, directing them to consult Rockwell Automation's resources for restoring access when controller passwords are lost. This alert underscores the escalating threat landscape for OT systems within the water sector, where vulnerabilities can range from simple defacement to severe service outages and potential physical damage.

Utilities are encouraged to conduct thorough reviews of all external connections, including any undocumented vendor-installed cellular equipment, to ensure no critical PLC is directly exposed to the public internet. CISA also points to its operational technology mitigation guidance and the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for additional support. Organizations detecting malicious activity are urged to report it to CISA, the FBI, or the Internet Crime Complaint Center.

Synthesized by Vypr AI