(TLP:CLEAR) CISA Issues Alert Urging Water and Wastewater Utilities to Protect OT Against Activity Targeting PLCs
Created: Friday, July 31, 2026 - 15:18
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
Summary: Yesterday, CISA issued an alert warning of a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the water and wastewater systems sector. CISA noted attackers accessed internet-exposed PLCs, modified passwords to lock out operators, and changed device IP addresses to disconnect the controllers. This has led to boil water notices and forced utilities into sustained manual operations.
CISA notes the targeting spans water entities of all sizes, including organizations with mature cybersecurity programs. Of particular concern, the exposed assets include cellular modems installed by operators, vendors, or system integrators that may not be documented or captured in routine attack surface scans. CISA further notes internet-exposed OT carries elevated risk of defacement, unauthorized configuration changes, operational disruption, and, in severe cases, physical damage.
WaterISAC strongly urges utilities to review and follow CISA’s alert and recommendations without delay:
- Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.
- Once PLCs are disconnected from the public internet, operators should ensure a known-clean backup of the PLC image exists in case operators are locked out by a modified password.
- It may be necessary for utilities to contact their integrators for assistance and to make sure the utility maintains a backup copy in a secure location (the integrator should not be the only one with a copy of PLC code and backups).
To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:
- CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology
- United Kingdom’s National Cyber Security Center: Secure Connectivity Principles for Operational Technology
- Federal Bureau of Investigation (FBI): Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions
Analyst Note: In addition to the CISA alert, the FBI noted that across multiple victims, similar network configurations supplied by third parties may give malicious cyber actors a chance to increase their success when vulnerable network and hardware setups are shared by customers. Utilities should therefore proactively contact integrators, service providers, and other vendors supporting critical OT systems, share this alert if they are not already aware of it, and take any necessary follow-up actions.
Original Source: https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
Additional Reading:
These TLP:AMBER posts have been previously shared with members and are subject to WaterISAC’s Information Sharing Guidelines and the Confidentiality of Sensitive Information and Data Classification and Sharing in WaterISAC’s Membership Terms and Conditions
- (TLP:AMBER) Ongoing Malicious Cyber Activity at Water and Wastewater Utilities – TTPs Shared
- (TLP:AMBER) WaterISAC Notification – Minnesota Fusion Center Reports Ongoing Malicious Cyber Activity Impacting Minnesota Water Utilities
Related WaterISAC PIRs: 6-12
