CISA Warns of Rising Cyberattacks on Internet-Exposed Water Sector PLCs
The U.S. Cybersecurity and Infrastructure Security Agency issued an alert on July 30, 2026, warning of a significant rise in cyberattacks targeting programmable logic controllers in the water and wastewater sector. Threat actors have been altering device passwords to lock out operators and changing IP addresses to disconnect equipment, resulting in boil water notices and forced manual operations. CISA urges critical infrastructure operators of all sizes to immediately disconnect PLCs from the public internet and route any remote access through VPNs or secure gateway devices. The agency also recommends enabling password protection, allowlisting known IP addresses, and maintaining clean backups of PLC images in case of lockout. Internet scan data collected in September 2026 found over 41,000 EtherNet/IP assets and nearly 38,000 Modbus assets publicly reachable, illustrating the broad exposure surface CISA's guidance aims to address.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in