Security
Hackers target internet-exposed PLCs at water utilities, triggering boil-water notices: CISA
2026-07-31
Cyber threat actors are increasingly targeting internet-exposed programmable logic controllers (PLCs) used by water and wastewater utilities, locking operators out of industrial control systems and disrupting operations, according to a new alert from the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CISA said attackers have been changing passwords on exposed PLCs to deny operators access and modifying device IP addresses to disconnect controllers from operational networks. The attacks have already resulted in boil-water notices and forced affected utilities to operate manually while restoring systems.
The agency said water utilities of all sizes are being targeted, including organisations with mature cybersecurity programmes. In several cases, attackers gained access through internet-connected operational technology (OT) assets, including cellular modems installed by operators, vendors or system integrators that were not documented or included in routine attack surface assessments.
According to CISA, publicly accessible PLCs face an elevated risk of unauthorised configuration changes, operational disruptions, system defacement and, in severe cases, physical damage to industrial equipment.
The advisory underscores the continued exposure of critical infrastructure to attacks against operational technology, particularly in sectors where legacy industrial control systems remain directly accessible from the internet.
To reduce risk, CISA urged operators to remove PLCs and other OT assets from direct internet exposure, instead routing remote access through virtual private networks (VPNs) or secure gateway devices. The agency also recommended replacing default passwords, enabling strong authentication, restricting remote access to trusted engineering systems through IP allowlists, and maintaining verified offline backups of PLC configurations to support recovery if devices are compromised.
CISA issued additional guidance for organisations using Rockwell Automation MicroLogix 1400 controllers, noting that operators should ensure they can restore access if passwords are changed during an attack.
The agency also encouraged water utilities to review all external connections to operational technology environments, including undocumented remote-access devices that may have been installed by third-party vendors or maintenance contractors.
The alert reflects growing concern over attacks targeting industrial control systems supporting critical infrastructure. In recent years, water utilities have become increasingly attractive targets for cybercriminals and state-linked threat actors because internet-connected industrial controllers often provide a direct path to operational disruption. The latest incidents suggest attackers are moving beyond reconnaissance to actively manipulating control systems capable of affecting essential public services.
CISA said attackers have been changing passwords on exposed PLCs to deny operators access and modifying device IP addresses to disconnect controllers from operational networks. The attacks have already resulted in boil-water notices and forced affected utilities to operate manually while restoring systems.
The agency said water utilities of all sizes are being targeted, including organisations with mature cybersecurity programmes. In several cases, attackers gained access through internet-connected operational technology (OT) assets, including cellular modems installed by operators, vendors or system integrators that were not documented or included in routine attack surface assessments.
According to CISA, publicly accessible PLCs face an elevated risk of unauthorised configuration changes, operational disruptions, system defacement and, in severe cases, physical damage to industrial equipment.
The advisory underscores the continued exposure of critical infrastructure to attacks against operational technology, particularly in sectors where legacy industrial control systems remain directly accessible from the internet.
To reduce risk, CISA urged operators to remove PLCs and other OT assets from direct internet exposure, instead routing remote access through virtual private networks (VPNs) or secure gateway devices. The agency also recommended replacing default passwords, enabling strong authentication, restricting remote access to trusted engineering systems through IP allowlists, and maintaining verified offline backups of PLC configurations to support recovery if devices are compromised.
CISA issued additional guidance for organisations using Rockwell Automation MicroLogix 1400 controllers, noting that operators should ensure they can restore access if passwords are changed during an attack.
The agency also encouraged water utilities to review all external connections to operational technology environments, including undocumented remote-access devices that may have been installed by third-party vendors or maintenance contractors.
The alert reflects growing concern over attacks targeting industrial control systems supporting critical infrastructure. In recent years, water utilities have become increasingly attractive targets for cybercriminals and state-linked threat actors because internet-connected industrial controllers often provide a direct path to operational disruption. The latest incidents suggest attackers are moving beyond reconnaissance to actively manipulating control systems capable of affecting essential public services.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




