CISA: Hackers Hit 100+ Water Utility Controllers Across 12 US States Using Default Passwords
CISA reported in July 2026 that malicious actors targeted over 100 internet-exposed programmable logic controllers at water and wastewater facilities across at least 12 US states. Attackers used unsophisticated methods — scanning for exposed devices, logging in with default or weak credentials, changing admin passwords, and altering IP addresses to lock out legitimate operators. The intrusions caused loss of remote monitoring capability, with some utilities forced to resort to manual valve operation and pressure readings; physical consequences included localised flooding and pressure loss. The vulnerabilities stem from legacy PLCs lacking encryption or authentication, combined with undocumented cellular modems attached directly to controllers for convenient remote access. CISA recommends eliminating direct internet exposure, enforcing strong credentials, segmenting networks, maintaining offline configuration backups, and auditing all undocumented remote connections.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in