


Perceptive Security
SOC/SIEM Consultancy

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
Published:
30 juli 2026 om 12:00:00
Alert date:
30 juli 2026 om 21:05:50
Source:
cisa.gov
Critical Infrastructure, Network Infrastructure, Mobile & IoT
CISA is observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. Threat actors have been modifying passwords to lock out operators and changing IP addresses to disconnect PLCs, resulting in boil water notices and sustained manual operations. The activity targets water entities of all sizes, including through undocumented cellular modems installed by operators or vendors. CISA urges critical infrastructure owners to disconnect PLCs from the internet immediately and route remote access through VPNs or gateway devices. Recommended mitigations include enabling password protection, changing default passwords, and allowlisting IPs for remote access. Rockwell Automation MicroLogix 1400 PLC users are directed to a specific advisory for restoring access when passwords are unknown. The alert was jointly developed with the EPA and FBI, and organizations can contact EPA's Cybersecurity Technical Assistance Program or CISA Regional Offices for support.
Technical details
Mitigation steps:
Affected products:
Rockwell Automation MicroLogix 1400
Programmable Logic Controllers (PLCs)
Related links:
https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html
https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology
https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity
https://www.epa.gov/cyberwater/forms/cybersecurity-technical-assistance-program-water-sector
https://www.cisa.gov/about/regions
https://www.cisa.gov/reporting-cyber-incident
https://www.ic3.gov/
https://www.fbi.gov/contact-us/field-offices
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
