CISA has warned that cyber threat actors are increasingly targeting internet-exposed programmable logic controllers in U.S. water and wastewater systems, changing passwords to lock out operators and altering IP addresses to disconnect equipment. The activity has already contributed to boil-water notices and sustained manual operations, according to a July 30 alert issued with input from the Environmental Protection Agency and FBI.
The immediate directive is blunt: remove PLCs and other operational technology from direct internet exposure. CISA says remote operational access should terminate at a VPN or gateway device rather than at the controller itself.

An operator monitors a water treatment plant as warning and cybersecurity icons link industrial controls to the cloud.The overlooked connection may be a cellular modem​

The alert applies to water organizations of every size, including operators with established cybersecurity programs. CISA specifically cautions that externally reachable OT may include cellular modems installed by internal teams, vendors, or system integrators—connections that may not appear in routine asset inventories or perimeter scans.
That matters because an exposed PLC is not merely another unmanaged endpoint. It can be directly tied to pumps, treatment processes, alarms, and telemetry. CISA says attackers have used exposed controllers to change configurations, disrupt operations, and potentially create conditions for physical damage.
For Windows administrators supporting utility environments, this is a reminder that ordinary IT visibility is not enough. A Windows-based engineering workstation, remote-access server, or vendor support laptop may be well managed while a controller’s cellular path remains reachable from the public internet.

Restore access only after preserving a clean recovery path​

CISA recommends that operators first disconnect PLCs from the internet, then verify they have a known-clean backup of the PLC image. That sequence is important: if an attacker has changed a controller password, operators may need a trusted image to restore normal access and configuration.
The agency also calls for password protection, replacement of default credentials, and IP allowlisting so that remote access is limited to known engineering laptops or other critical OT assets. These are basic controls, but the warning illustrates why they must be applied to the controller and its remote-access path—not just to surrounding Windows infrastructure.
Owners and integrators using Rockwell Automation MicroLogix 1400 controllers have a specific recovery concern. CISA points them to Rockwell Automation guidance for restoring controller access when the password is unknown, reflecting the password-lockout behavior observed in this activity.

Remote access is the exposure point to audit now​

Utilities should treat this as an urgent external-attack-surface review rather than a routine quarterly control check. The priority is to identify every path that could reach a PLC: fixed public IP addresses, cellular gateways, vendor-managed remote tools, legacy NAT rules, and temporarily deployed troubleshooting equipment.
CISA’s advice is not to abandon remote operations, but to put a security boundary in front of them. A VPN or properly controlled gateway, combined with tightly restricted source IPs and tested recovery backups, gives operators a way to retain remote engineering access without publishing the controller itself to the internet.
The practical next step is simple but time-sensitive: inventory every internet-facing OT connection, disconnect direct PLC exposure, and confirm that recovery images and access procedures work before an attacker turns a configuration change into an operational outage.

References​

  1. Primary source: CISA
    Published: 2026-07-30T12:00:00+00:00