CISA Warns of Escalating Attacks on Water Sector PLCs, Urges Immediate Disconnection
The Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a critical alert regarding a surge in cyberattacks targeting Programmable Logic Controllers (**PLCs**) within the Water and Wastewater Systems (**WWS**) Sector. Threat actors are exploiting publicly exposed operational technology (**OT**) to modify passwords, disconnect devices, and trigger operational disruptions, including 'boil water' notices. CISA is urging immediate action to secure these vital systems.
### Critical Infrastructure Under Threat
**CISA** is observing a significant increase in cyber threat actors targeting **PLCs** in the **WWS** Sector. These attacks are not merely disruptive; they have tangible consequences, leading to 'boil water' notices and forcing facilities into sustained manual operations.
### Modus Operandi of Attackers
Attackers are exploiting publicly exposed **PLCs** and other **OT** assets. Their methods include modifying passwords to lock out operators and disconnecting **PLCs** by altering their IP addresses. This highlights a critical vulnerability in systems directly accessible from the internet.
### Widespread Impact and Undocumented Exposures
These threat actors are targeting water entities of all sizes, emphasizing that no organization is immune. Even facilities with mature cybersecurity programs are at risk, particularly from undocumented external connections like cellular modems installed by operators, vendors, or system integrators. These often bypass routine attack surface scans, creating stealthy entry points.
### Immediate Mitigation Recommendations
**CISA** strongly recommends the following critical mitigations:
* **Disconnect PLCs from the Internet:** Remote access for operational purposes should be routed through a Virtual Private Network (**VPN**) or a dedicated gateway device, never directly to the **PLC**.
* **Enable Password Protection:** Implement strong password policies and immediately change all default passwords.
* **IP Whitelisting:** Restrict remote access to **PLCs** only from known engineering laptops or other critical **OT** assets through IP allowlisting.
### Post-Disconnection Steps and Vendor Guidance
After disconnecting **PLCs** from the internet, operators must ensure they possess a verified clean backup of the **PLC** image. This is crucial for recovery in scenarios where passwords may have been compromised or modified.
Owners, operators, and integrators of **Rockwell Automation MicroLogix 1400 PLCs** should consult **Rockwell Automation's** [IMPORTANT NOTICE: Restoring Access to a MicroLogixβ’ 1400 Controller When the Password Is Unknown](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html) for specific guidance.
### Resources for Secure Remote Access
For guidance on securely enabling remote access to **OT** systems, **CISA** recommends the following resources:
* **CISA**: [Primary Mitigations to Reduce Cyber Threats to Operational Technology](https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology)
* **United Kingdom's National Cyber Security Center**: [Secure Connectivity Principles for Operational Technology](https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity)
* **Federal Bureau of Investigation (FBI)**: [Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions](https://www.ic3.gov/PSA/2026/PSA260730.pdf)
### Reporting Incidents and Seeking Support
For additional support, organizations can contact the **Environmental Protection Agencyβs** [Cybersecurity Technical Assistance Program for the Water Sector](https://www.epa.gov/cyberwater/forms/cybersecurity-technical-assistance-program-water-sector) or their [CISA Regional Office](https://www.cisa.gov/about/regions).
To report a cyber incident, contact **CISAβs** 24/7 Operations Center at [email protected] or call 1-844-Say-CISA (1-844-729-2472). Further details are available at [Reporting a Cyber Incident](https://www.cisa.gov/reporting-cyber-incident). Alternatively, incidents can be reported to the **FBIβs Internet Crime Complaint Center (**IC3**)** or your [local FBI field office](https://www.fbi.gov/contact-us/field-offices).
When reporting, include the date, time, and location of the incident, type of activity, number of people affected, equipment used, and contact information for the submitting organization.
### Acknowledgements
This alert was developed with contributions from the **Environmental Protection Agency** and the **Federal Bureau of Investigation**.