CISA | Alerts
Follow
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA is warning of a rise in cyberattacks targeting programmable logic controllers (PLCs) within the Water and Wastewater Systems Sector. Threat actors are exploiting publicly exposed PLCs by changing passwords and IP addresses, leading to operational disruptions like boil water notices. These attacks affect water organizations of all sizes, even those with established cybersecurity measures. Exposed operational technology (OT) assets face increased risks of data manipulation, operational shutdowns, and even physical damage.CISA strongly advises disconnecting PLCs from the internet and utilizing VPNs or gateway devices for any necessary remote access. It is crucial to enable password protection and change all default passwords. IP allowlisting should be implemented to restrict remote access to known, trusted sources. After disconnecting, operators must ensure they have clean, verified backups of PLC configurations. For Rockwell Automation MicroLogix 1400 users, specific guidance is available to restore access lost due to password modifications.Secure remote access for OT systems can be achieved by following CISA's primary mitigations and the UK's National Cyber Security Centre's secure connectivity principles. Further assistance is available through the EPA's Cybersecurity Technical Assistance Program or a local CISA Regional Office. Cyber incidents should be reported to CISA's Operations Center or designated law enforcement agencies, providing specific details about the event.