Skip to content
Tech News
← Back to articles

CISA Alert: Water Sector PLC Targeting

read original more articles
Why This Matters

This alert underscores the growing cybersecurity threats to critical water infrastructure, highlighting the risks of internet-exposed PLCs which can lead to operational disruptions and public health hazards. Protecting these systems is vital for ensuring safe water supply and maintaining public trust in essential services.

Key Takeaways

Download the full brief →

Introduction

CISA issued an alert on July 30, 2026 warning that threat actors are increasingly targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector, in some cases modifying passwords to lock out operators and disconnecting devices by changing their IP addresses, resulting in boil-water notices and sustained manual operations. CISA named Rockwell Automation/Allen-Bradley, Siemens, and Schneider Electric equipment and flagged cellular modems as a common blind spot in routine attack-surface scans. This report characterizes current Censys-observed internet exposure for each named vendor: 4,148 Rockwell/Allen-Bradley EtherNet/IP hosts, 4,117 Siemens SIMATIC S7-1200 hosts, and 2,072 Schneider Electric hosts (vendor-wide, not PLC-scoped), all as of the 2026-07-30 snapshot. This is an exposure characterization only: it does not confirm that any specific host is a victim of the activity CISA describes.

Advisory Context

The following paraphrases the CISA alert as supplied by the user for this report; it was not independently re-fetched from cisa.gov in this session.

CISA is observing a significant increase in threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Observed actor behavior includes modifying PLC passwords to lock out operators and disconnecting PLCs by changing their IP addresses, producing boil-water notices and sustained manual operations at affected utilities.

Targeting affects water entities of all sizes, including organizations with mature cybersecurity processes. CISA specifically flags cellular modems installed by operators, vendors, or system integrators as a common blind spot: these connections may be undocumented and excluded from routine attack-surface scans. Owners of Rockwell Automation MicroLogix 1400 controllers are directed to Rockwell’s guidance for restoring access when a controller password is unknown.

CISA-Recommended Mitigations

... continue reading