CISA has issued an urgent warning regarding threat actors targeting internet-exposed programmable logic controllers in the water sector, leading to operational disruptions and mandatory boil-water notices nationwide.
Key Points
- Threat actors are locking out operators by changing passwords and disconnecting devices by modifying IP addresses on critical water infrastructure.
- CISA identified Rockwell Automation, Siemens, and Schneider Electric equipment as primary targets for these malicious cyber activities.
- Cellular modems are frequently overlooked in security scans, creating significant blind spots for critical infrastructure operators and system integrators.
- Censys data from July 30, 2026, reveals over 10,000 internet-exposed hosts across the three identified vendors globally.
- Recommended mitigations include removing PLCs from the public internet and routing all remote access through secure VPNs or gateway devices.