VORANT. Threat Intelligence Sign in Get the full feed

CISA warns of PLC attacks on water utilities

high vulnerability infrastructure

CISA reports a surge in attacks against internet-exposed PLCs in the water sector, with actors locking out operators and disrupting service.

CISA has issued an alert describing a marked increase in threat activity targeting programmable logic controllers (PLCs) within the Water and Wastewater Systems Sector. Attackers are gaining access to publicly exposed PLCs and OT devices—including undocumented cellular modems installed by vendors or integrators—then changing default or existing passwords to lock out legitimate operators and altering IP configurations to sever remote connectivity. This activity has already caused boil water notices and forced some utilities into sustained manual operations, indicating real operational impact rather than opportunistic defacement alone.

The advisory notes that targeting is indiscriminate across utility size and maturity, meaning even organizations with established cybersecurity programs may be exposed via undocumented remote-access hardware that falls outside routine attack surface scans. CISA specifically references Rockwell Automation MicroLogix 1400 controllers, pointing operators to vendor guidance for recovering access when passwords have been changed by an unauthorized party.

Mitigation guidance focuses on immediately removing PLCs from direct internet exposure, routing remote access through VPNs or gateway devices, enforcing password protection, and allowlisting IPs to known engineering assets. CISA also recommends maintaining clean PLC image backups in case of lockout. No specific threat actor, malware, or CVE has been attributed to this activity; the alert is a sector-wide warning based on observed operational patterns rather than a single confirmed intrusion set.

Source reporting: https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free