Pages

Thursday, August 6, 2026

Federal agencies warn U.S. organizations about cyber attacks on water sector

The Water Quality Control Division is partnering with the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency to issue this urgent warning.

The Cybersecurity and Infrastructure Security Agency and partners are issuing an urgent warning regarding a sharp increase in cyber attacks targeting programmable logic controllers (PLCs) in water and wastewater systems. Attackers are exploiting internet-exposed equipment to change passwords and alter system settings, sometimes triggering boil-water notices.

Water and wastewater suppliers should take the following actions immediately:

  • Disconnect PLCs from the internet. Remote access for operational purposes should go through a VPN (virtual private network) or gateway device, not directly to the PLC.
  • Enable password protection and change default passwords.
  • Establish a protocol so that only specific, approved computers can access the PLCs. To do this, work with IT to set up Allowlist IPs = every computer has an ID number (an IP address). "Allowlisting" means making an exclusive list of the ID numbers you trust.
  • Review CISA’s Known Exploited Vulnerabilities (KEV) list and Industrial Control Systems (ICS) Advisories and take action to address any potential vulnerabilities.

How can cybercriminals use a PLC? 

  • Locking out operators: Hackers change the PLC's internal passwords and IP addresses. This locks the real workers out and leaves them blind to what is happening.
  • Flooding: Attackers can force valves to stay open or pumps to run non-stop, causing sewage or water tanks to overflow and flood the facility.
  • Water pressure loss: Forcing water pumps to shut down drops pressure in pipes, which can compromise water quality and require cities to issue emergency boil-water notices.
  • Chemical manipulation: Attackers can alter chemical dosing rules and make the water unsafe to drink.
  • Falsifying information: Sophisticated hackers can feed fake "normal" data to the SCADA screens. While the computer screen shows everything is fine, the physical PLC is actively damaging the equipment on the floor.

What can systems do to protect themselves? 

After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password.

Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity.

To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:

For additional support, contact the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for the Water Sector or your CISA Regional Office.

What should I do if my system is affected? 

Regulatory requirements: 

  1. Contact the department for any type of cybersecurity event including any tampering to computers, operating technology, or cyber assets. Notify the department as soon as possible, but no later than 10 a.m. of the calendar day following any cybersecurity event (see Regulation 11 for details).
  2. Provide written notice within five calendar days to the department explaining the circumstances of the occurrence and setting forth the action(s) taken to ensure the ability of the system to maintain critical operations and to prevent any recurrence. The Tampering Threat and Incident Report Form described below will satisfy this requirement.

Highly recommended: