CISA Warns of Escalating Cyberattacks on U.S. Water Utilities' PLCs
The U.S. **Cybersecurity and Infrastructure Security Agency (CISA)** has issued an urgent alert regarding a sharp increase in cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) within the water and wastewater systems (WWS) sector. This comes after disruptions affected over 30 community water systems in Minnesota, highlighting critical vulnerabilities in operational technology (OT) infrastructure.

**CISA** is sounding the alarm over a concerning surge in attacks aimed at internet-exposed **PLCs** in the U.S. water and wastewater systems sector. The agency's alert follows recent incidents where hackers disrupted more than 30 community water systems in Minnesota, commencing last Sunday and continuing into Monday.
These attacks involved threat actors targeting exposed **PLCs**, altering passwords to lock out operators, modifying IP addresses to disconnect devices, and performing other actions that caused operational disruptions.
### Urgent Call to Action for Critical Infrastructure
**CISA** strongly urges critical infrastructure owners, operators, and integrators to remove publicly exposed **PLCs** and other operational technology (OT) from direct internet access as swiftly as possible. This recommendation extends to organizations of all sizes within the WWS sector, including those with established cybersecurity programs.
### Undocumented Modems: A Persistent Blind Spot
One significant vulnerability highlighted in the bulletin is the presence of exposed OT, which often includes undocumented cellular modems installed by operators, vendors, or system integrators. These internet-facing assets are susceptible to a range of threats, from defacement and configuration changes to operational disruptions and even potential physical damage.
To mitigate these risks, **CISA** recommends immediate removal of these assets from direct internet exposure. Where direct removal isn't feasible, secure access via **VPN** connections or gateway devices is advised. Furthermore, changing default passwords and implementing **IP address allow-listing** are crucial steps.
For owners of **Rockwell Automation MicroLogix 1400 PLCs**, **CISA** points to vendor guidance for recovering access if passwords have been compromised.
### Quantifying Internet Exposure
Cybersecurity search company **Censys** has provided a blog post quantifying this internet exposure. Their analysis estimates over 4,100 internet-exposed **Rockwell Automation/Allen-Bradley** hosts, 4,100 **Siemens** hosts, and more than 2,000 **Schneider Electric** hosts currently accessible online.

It's important to clarify that this map illustrates devices reachable over the public internet, not necessarily those actively targeted or compromised.
**Censys** also noted that many of the **MicroLogix 1400** controllers mentioned by **CISA** appear to be running End-of-Sale (EoS) firmware versions, further exacerbating their vulnerability.
The issue of undocumented cellular modems remains a significant blind spot, with **Censys** reporting that nearly half of the exposed **Rockwell** devices are reachable via major networks like **Verizon Business**, **AT&T**, **T-Mobile**, **Comcast**, **Charter**, and **Starlink**.

**Censys**'s report also includes an expanded set of Indicators of Compromise (**IoCs**) and threat-hunting guidance to assist organizations in detection and response.
### Minnesota Incidents Trigger State Response
Earlier this week, **Minnesota IT Services (MNIT)** activated the state's cybersecurity incident response plan in response to what was described as a "coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems." The incidents led to equipment malfunctions, forcing some utilities to temporarily switch to manual operations.
**MNIT** has since shared threat intelligence from the affected systems and offered guidance and best practices to help impacted utilities restore normal operations.