AUTO-UPDATED

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

The Cybersecurity and Infrastructure Security Agency is urging water utility operators to secure internet-exposed programmable logic controllers following a wave of coordinated cyberattacks targeting Minnesota water systems.

Key Points

  • CISA issued an urgent alert on July 30 warning that threat actors are actively targeting programmable logic controllers (PLCs) within the water and wastewater sector.
  • Over 30 community water systems in Minnesota experienced operational disruptions on July 26 and 27, leading to manual control procedures and localized boil water notices.
  • Attackers are gaining access to OT systems by exploiting publicly exposed devices, modifying passwords, and altering IP addresses to lock out legitimate operators.
  • The agency specifically identified risks associated with undocumented cellular modems and controllers manufactured by Siemens, Rockwell Automation, and Schneider Electric.
  • Operators are advised to disconnect PLCs from the public internet, implement VPNs for remote access, and maintain clean, offline backups of all controller configurations.

Why it Matters

These attacks highlight a critical vulnerability in national infrastructure as threat actors increasingly target the automated systems that manage essential public water services. Securing these industrial controllers is vital to preventing service outages and ensuring the continued safety of municipal water supplies across the country.
Securityweek.com Published by Mike Lennon
Read original