top of page
perceptive_background_267k.jpg

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

Published:

30 juli 2026 om 12:00:00

Alert date:

30 juli 2026 om 21:05:50

Source:

cisa.gov

Click to open the original link from this advisory

Critical Infrastructure, Network Infrastructure, Mobile & IoT

CISA is observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. Threat actors have been modifying passwords to lock out operators and changing IP addresses to disconnect PLCs, resulting in boil water notices and sustained manual operations. The activity targets water entities of all sizes, including through undocumented cellular modems installed by operators or vendors. CISA urges critical infrastructure owners to disconnect PLCs from the internet immediately and route remote access through VPNs or gateway devices. Recommended mitigations include enabling password protection, changing default passwords, and allowlisting IPs for remote access. Rockwell Automation MicroLogix 1400 PLC users are directed to a specific advisory for restoring access when passwords are unknown. The alert was jointly developed with the EPA and FBI, and organizations can contact EPA's Cybersecurity Technical Assistance Program or CISA Regional Offices for support.

Technical details

Mitigation steps:

Affected products:

Rockwell Automation MicroLogix 1400
Programmable Logic Controllers (PLCs)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page