Exposed PLCs in the Water Sector: What CISA's Alert Reveals About Internet-Facing OT
On July 30, 2026, CISA issued an alert about rising attacks on programmable logic controllers (PLCs) in the US water and wastewater sector. Attackers change passwords, locking out operators, and IP addresses, disabling devices; this led to boil-water notices and manual operations. The agency requires removing PLCs from the internet and using VPNs.
- CISA recorded a rise in attacks on PLCs in the US water sector
- Attackers change passwords and IP addresses of controllers, disabling them
- Consequences: boil-water notices and manual operation mode
- ZoomEye search found 41,601 EtherNet/IP and 37,792 Modbus devices exposed
Read next
Security