VYPR
advisoryPublished Jul 31, 2026· Updated Aug 7, 2026· 4 sources

CISA Issues Urgent Warning to Water Utilities: Disconnect Internet-Exposed PLCs

CISA has issued an urgent warning to water and wastewater organizations to immediately remove internet-exposed programmable logic controllers (PLCs) from public access due to rising cyberattacks.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to water and wastewater organizations, directing them to immediately disconnect internet-exposed programmable logic controllers (PLCs) from public access. This directive comes in response to a concerning increase in cyberattacks targeting these critical industrial devices, which are essential for managing water treatment, pumping, chemical dosing, and wastewater management processes.

Threat actors are actively exploiting the public accessibility of these PLCs to alter configurations, change passwords, and disrupt vital operations. CISA reports that these attacks have affected water entities of all sizes, including those with existing cybersecurity measures in place. In several recent incidents, attackers have successfully modified PLC passwords, effectively locking out authorized operators, and have even changed device IP addresses, severing remote management capabilities. These malicious actions have led to significant operational disruptions, including the issuance of boil water advisories and prolonged reliance on manual system operation.

CISA emphasizes that the public exposure of these operational technology (OT) assets may not always be obvious. Some PLCs might be connected via cellular modems installed by vendors, integrators, or operators, making them invisible to standard external attack-surface scans or asset inventories. This lack of visibility can leave organizations unaware that critical equipment is accessible online, creating a hidden vulnerability.

To mitigate these risks, CISA strongly advises owners, operators, and system integrators to disconnect PLCs from the internet without delay. The agency recommends that remote access should never connect directly to a PLC. Instead, organizations should implement secure virtual private network (VPN) connections or utilize gateway devices that enforce robust authentication, monitoring, and access control measures. Furthermore, enforcing strong password policies by replacing default credentials with unique, strong passwords for each device is crucial.

Water utilities are also urged to restrict remote connectivity through IP allowlisting, ensuring that access is granted only from approved engineering laptops and other authorized OT systems. After securing devices against external exposure, it is imperative for organizations to maintain clean, verified backups of PLC images and configurations. These backups are vital for restoring access and returning equipment to a safe, known state in the event of a password change or configuration modification by an attacker.

CISA specifically highlighted guidance for operators of Rockwell Automation MicroLogix 1400 PLCs, directing them to consult Rockwell Automation's resources for restoring access when controller passwords are lost. This alert underscores the escalating threat landscape for OT systems within the water sector, where vulnerabilities can range from simple defacement to severe service outages and potential physical damage.

Utilities are encouraged to conduct thorough reviews of all external connections, including any undocumented vendor-installed cellular equipment, to ensure no critical PLC is directly exposed to the public internet. CISA also points to its operational technology mitigation guidance and the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for additional support. Organizations detecting malicious activity are urged to report it to CISA, the FBI, or the Internet Crime Complaint Center.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public alert warning of a significant increase in malicious activity targeting water utilities, advising facilities to immediately remove publicly exposed Programmable Logic Controllers (PLCs) and other Operational Technology (OT) from the internet. This advisory follows investigations into recent incidents in Minnesota, where over 30 community water systems were affected by a coordinated cyberattack beginning July 26, with threat actors modifying passwords and disconnecting PLCs. While the CISA alert does not mention Iran, multiple news outlets report that state and federal investigators are probing a potential link to Iran-linked hackers, citing a memo from the WaterISAC that tied the attacks to the nation-state.

A recent scan by Forescout's Vedere Labs has identified over 4,000 Rockwell Automation and Allen-Bradley industrial controllers exposed online, with 22 of these devices located in U.S. water systems that have recently been targeted by cyberattacks. While the FBI and EPA have warned of attacks impacting utilities in at least 12 states, Forescout's research suggests the current activity is more indicative of opportunistic, at-scale exploitation of known vulnerabilities rather than a sophisticated, targeted campaign. The scan also noted that 19 of the 22 exposed hosts in affected cities appear vulnerable to CVE-2017-16740, a remote code execution flaw from 2017, though it remains unconfirmed if Modbus TCP was enabled on these specific devices.

Retired General Paul Nakasone, former NSA chief, echoed CISA's warning by stating that programmable logic controllers (PLCs) in US water systems should not be connected to the internet, especially following suspected Iranian cyberattacks. He emphasized the need for higher cybersecurity standards and greater collaboration, pointing to initiatives like DEF CON Franklin as examples of effective partnerships in securing critical infrastructure.

Synthesized by Vypr AI