HeadlinesBriefing favicon HeadlinesBriefing.com

CISA Alerts On Water Sector PLC Targeting

Hacker News •
×

On July 30, 2026, CISA warned that threat actors are increasingly targeting internet‑exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector. Actuators are being locked out by changing passwords and disconnected by altering IP addresses, prompting boil‑water notices and prolonged manual operations.

The alert names Rockwell Automation/Allen‑Bradley, Siemens, and Schneider Electric equipment and flags cellular modems as a blind spot. Censys observed 4,148 Rockwell/Allen‑Bradley Ether Net/IP hosts, 4,117 Siemens SIMATIC S7‑1200 hosts, and 2,072 Schneider Electric hosts (vendor‑wide, not PLC‑scoped) as of the snapshot date. This is an exposure characterization only; it does not confirm any specific host is compromised.

CISA urges owners, operators, and integrators to remove publicly exposed PLCs, use VPN gateways, enable password protection, and allowlist IPs for remote access. Rockwell’s guidance for restoring access to Micro Logix 1400 controllers is available for password‑unknown cases.

Geographically, the United States accounts for 71% of Rockwell exposures, Canada 11.5%, and combined cellular carriers cover 59% of all exposed hosts. Siemens exposure concentrates in southern and central Europe, while Schneider Electric hosts are split between Turkey and Australia.