CISA warns water utility companies to disconnect internet-exposed controls after hacks
Connecting PLCs to the internet is like paving the way for hackers.

Image by Shutterstock
- CISA urged utilities to remove programmable logic controllers from the internet after hackers locked out operators and forced manual operations.
- Controllers managing water quality, chemical treatment, and pumps are vulnerable to hackers who can change configurations and disrupt operations.
- Pro-Iranian group CyberAv3ngers targeted water and wastewater companies in what officials called one of the largest attacks on state infrastructure.
- CISA recommends routing remote connections through VPNs instead of directly to controllers, and blocking all non-whitelisted IP addresses
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The US Cybersecurity and Infrastructure Security Agency (CISA) is pressing water and wastewater companies to take measures to better protect their facilities.
America’s cybersecurity agency is urging owners and operators of critical infrastructure companies to remove all publicly exposed programmable logic controllers (PLCs) and other operational technology (OT) from the internet as soon as possible.
“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations,” CISA says in a recently published cybersecurity advisory.
Water utilities use PLCs to manage and monitor drinking water quality and wastewater treatment, including switching pumps at a pumping station on and off, filling tanks and reservoirs, adding chemicals, collecting data for monitoring reports, and responding to emergency situations.
PLCs connected to the internet that are protected by weak or default passwords pose a threat to the quality of drinking water for local communities and their inhabitants, including an increased risk of hacking, configuration changes to key systems, operational disruptions, and even physical damage.
Because of these risks, CISA is recommending owners and operators of utility companies to disconnect their PLCs from the internet.
“Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC,”the security agency warns.
In addition, password protection should be enabled, and default passwords should be changed immediately.
Lastly, only whitelisted IP addresses should be granted remote access to PLCs and other operational technology.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Last week, pro-Iranian hacktivist group the CyberAv3ngers targeted more than 30 water and wastewater companies in Minnesota in a coordinated cyberattack. Officials described the events as one of the largest attacks on Minnesota’s water infrastructure in history.
Minnesota IT Services (MNIT) is currently working closely with the Minnesota Department of Public Safety, the FBI, and other state and federal authorities to “support affected communities and strengthen the security of the state’s critical infrastructure.”