Skip to main content
Threat IntelligenceEmerging Threats

CISA Warns of Targeted Cyberattacks on US Water Utilities

Water treatment plant control room with industrial systems and equipment.

"CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."

CISA's urgent warning and recommended mitigations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert after a wave of attacks that targeted internet-exposed programmable logic controllers (PLCs) in the water and wastewater sector. CISA described the threat activity as including attackers changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and taking other actions that disrupted operations. The agency explicitly recommended removing publicly exposed PLCs and other OT from direct internet exposure. Where removal is not possible, CISA advised using a VPN connection or gateway devices for secure access, changing default passwords, and limiting access through an IP address allow-list. For operators of Rockwell Automation MicroLogix 1400 PLCs, CISA pointed to vendor guidance for recovering access if passwords have been changed.

Minnesota disruptions prompted an incident response

The alert follows a coordinated set of intrusions that disrupted more than 30 community water systems in Minnesota. According to state authorities, the attacks began last Sunday and continued through Monday. Multiple municipalities reported equipment malfunctions; some utilities were forced to switch to manual operations temporarily. Minnesota IT Services (MNIT) activated the state's cybersecurity incident response plan, shared threat intelligence collected from affected systems, and provided guidance and best practices to help impacted utilities restore normal operations.

Observed tactics: exposed PLCs, password changes, and undocumented cellular modems

CISA's bulletin highlights how internet-facing OT is vulnerable to a range of outcomes: defacement, configuration changes, operational disruption, and even physical damage. The agency warned that exposed OT can include undocumented cellular modems installed by operators, vendors, or system integrators — a common blind spot that can create unexpected public internet access paths to critical equipment. The combination of exposed PLCs and poorly controlled remote-access mechanisms enabled attackers to lock out operators and interrupt normal control functions in affected water systems.

Scope of internet exposure, according to Censys

Security search company Censys quantified internet exposure across major automation vendors. Their analysis estimates more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, roughly 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts reachable from the public internet. Censys cautioned that the map of reachable devices shows devices accessible via the internet, not systems that are necessarily being targeted or already compromised. The company also noted that many MicroLogix 1400 controllers appear to be running end-of-sale (EoS) firmware versions and supplied an expanded set of indicators of compromise (IoCs) and threat-hunting guidance. Nearly half of the exposed Rockwell devices were reported as reachable via Verizon Business, AT&T, T‑Mobile, Comcast, Charter, and Starlink networks, underscoring the role of cellular and consumer-provider links in the exposure picture.

What this means for technologists, water utilities, and vendors

  • Technologists and security teams: The immediate tasks are to inventory internet-facing PLCs and OT, remove direct exposure where possible, and apply CISA's mitigations — VPNs or gateways, password changes, and IP allow-lists. Censys-provided IoCs and hunting guidance were released as practical inputs for detection and response work.
  • Water utilities and municipal operators: Even organizations "of all sizes" and those with mature cybersecurity programs were noted as targets. Utilities that reported equipment malfunctions had to fall back to manual operations, highlighting operational continuity considerations when control systems are disrupted.
  • Vendors and system integrators: The bulletin names undocumented cellular modems and installed remote-access components as frequent blind spots. Vendors tied to Rockwell MicroLogix 1400 controllers were specifically pointed to recovery guidance for compromised password scenarios.

The incident places a narrow, practical demand on owners and operators: find internet-exposed PLCs now and remove or secure them. CISA's call to action and the Censys exposure figures together frame the problem as both immediate and measurable — whether that measurement is the count of devices reachable from the public internet or the count of communities already disrupted. The next concrete steps are those the agencies and vendors have laid out: inventory, isolate, recover, and hunt using shared IoCs. The question left by these facts is simple and urgent: will owners prioritize removal of internet-facing PLCs before more communities face operational disruptions?

Source: BleepingComputer — CISA warns of cyberattacks disrupting U.S. water utilities