highOther

Increased Targeting of Exposed PLCs in Water and Wastewater Systems Sector

First seen Jul 31, 2026 · Updated Jul 31, 2026

OTICSPLCcritical-infrastructurewater-sectorinternet-exposed-devicesdefault-credentialsCISA-alert

CISA reports a significant increase in threat actors targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector, including devices connected via undocumented cellular modems. Attackers have locked out legitimate operators by changing passwords and altering IP configurations, resulting in boil water notices and forced manual operations at affected utilities.

Technical Analysis

Threat actors are scanning for and directly accessing internet-facing PLCs and OT devices, often reached through undocumented cellular modems installed by vendors or integrators outside normal attack surface monitoring. Observed tactics include modifying default or weak passwords to lock out legitimate operators and altering device IP addressing to sever remote management access, disrupting control loops for water treatment processes. Rockwell Automation MicroLogix 1400 PLCs are specifically called out as affected, with vendor guidance issued for password-recovery scenarios (advisory SD1790). This activity does not exploit a specific CVE but leverages insecure architecture: direct internet exposure, lack of VPN/gateway segmentation, and unmanaged remote access points. There is no direct AI agent system impact from this alert, as it targets OT/ICS field devices rather than IT infrastructure, APIs, or software supply chains used by agentic systems.

Affected Systems

Internet-exposed programmable logic controllers (PLCs) in Water and Wastewater Systems Sector; specifically Rockwell Automation MicroLogix 1400 PLCs; OT devices reachable via undocumented/unmanaged cellular modems installed by operators, vendors, or system integrators

Indicators of Compromise

  • No specific file hashes, IPs, or domains provided in this alert. Indicators of compromise are behavioral: unauthorized password changes on PLCs, unexpected PLC IP address changes, loss of operator access to control systems, unexplained boil water notices or manual operation switchovers.

Remediation Steps

  1. 1

    Disconnect PLCs from the Internet

    Remove direct internet exposure for all PLCs; route any necessary remote access through a VPN or dedicated secure gateway device rather than direct PLC connectivity.

  2. 2

    Enforce Strong Authentication

    Enable password protection on all PLCs and OT devices, replace default/vendor-set credentials with strong unique passwords, and rotate credentials regularly.

  3. 3

    Implement IP Allowlisting

    Restrict remote access to PLCs to a defined allowlist of known engineering laptops and trusted OT assets only.

  4. 4

    Audit Undocumented Remote Access Paths

    Inventory and assess all cellular modems and remote access points installed by operators, vendors, or integrators that may not be captured in standard attack surface scans.

  5. 5

    Maintain Clean Configuration Backups

    Keep verified clean backups of PLC images/configurations to enable rapid recovery if operators are locked out due to unauthorized password changes.

  6. 6

    Apply Vendor-Specific Guidance

    For Rockwell Automation MicroLogix 1400 PLC owners, follow Rockwell's advisory SD1790 for restoring access when passwords are unknown.

  7. 7

    Report Incidents

    Report any suspected compromise to CISA's 24/7 Operations Center, the EPA's Cybersecurity Technical Assistance Program for the Water Sector, or FBI IC3.

Industries Most Exposed

Water and Wastewater SystemsCritical InfrastructureUtilitiesIndustrial Control Systems/OT operators

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.