Hackers lock water utilities out of internet-facing PLCs

CISA is warning water and wastewater utilities that attackers are actively going after the programmable logic controllers, or PLCs, that run their treatment processes, and in some cases locking operators out of their own equipment. In an alert published July 30, 2026, the agency said it is observing a significant increase in threat actors targeting PLCs in the Water and Wastewater Systems sector, and urged owners, operators and integrators to pull publicly exposed controllers off the internet as soon as possible.

The consequences are not theoretical. According to CISA's alert, which the Environmental Protection Agency and the FBI contributed to, threat actors have modified PLC passwords to lock out operators and changed the devices' IP addresses to disconnect them. That activity has resulted in boil water notices and sustained manual operations.

Who is affected

CISA says the targeting spans water entities of all sizes, not only small rural systems with thin IT budgets. Even organizations with mature cybersecurity processes are told to validate their external connections, because the exposure often comes from cellular modems installed by operators, vendors or system integrators that were never documented and do not show up in routine attack surface scans.

Beyond lockouts, CISA warns that OT assets reachable from the internet carry raised risk of defacement, configuration changes, operational disruption and, in severe cases, physical damage.

The alert does not attribute the activity to any named group or country. Internet-exposed water sector PLCs have drawn this kind of attention before, though: IntelFusions has previously covered the CyberAv3ngers campaign against Unitronics controllers in the water, energy and healthcare sectors. Industrial malware activity overall has been trending toward a three-year low, which makes a concentrated push against one sector stand out.

What you should do

CISA's guidance is mostly about removing exposure rather than patching anything:

Owners, operators and integrators running Rockwell Automation MicroLogix 1400 PLCs are pointed to Rockwell's notice on restoring access to a MicroLogix 1400 controller when the password is unknown, which addresses this specific activity. CISA also references its own primary mitigations for reducing cyber threats to operational technology, and the UK National Cyber Security Centre's secure connectivity principles for OT.

Utilities in the United States can contact the EPA's Cybersecurity Technical Assistance Program for the Water Sector or their CISA regional office for help. Incidents can be reported to CISA's 24/7 operations center or to the FBI's Internet Crime Complaint Center.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions