CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet

The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a rack-mounted network security appliance in a dim data center aisle, status LEDs glowing amber and re
Share

Key points

  • CISA says hackers are actively breaking into internet-exposed programmable logic controllers, the small industrial computers that run pumps and valves at US water and wastewater utilities.
  • Attackers have changed passwords and IP addresses on the devices, locking out staff and forcing some plants to run by hand.
  • At least one incident tied to this activity has led to a boil-water notice for local residents.
  • Rockwell Automation MicroLogix 1400 controllers are among the affected devices, and Rockwell has published guidance for owners locked out by an unknown password.
  • CISA wants every water utility to pull these controllers off the public internet immediately and require a VPN, a private encrypted tunnel, for any remote access.

The US Cybersecurity and Infrastructure Security Agency is telling water utilities to yank their control systems off the public internet, because attackers are actively hunting them down and locking operators out.

CISA's warning focuses on programmable logic controllers: the small, rugged computers that open valves and run pumps inside a treatment plant. They're the brains that keep tap water safe. Attackers are finding these devices exposed on the open internet, changing their passwords so plant staff can't log back in, and in some cases switching the device's network address so it drops off the utility's own systems.

The result has been ugly. Some utilities have had to switch to manual operations, meaning staff physically walking the plant to keep things running. At least one incident led to a boil-water notice, the standard public health warning when drinking water may not be safe.

Who is being targeted?

Every size of water utility, from small rural systems to large municipal operators. CISA is blunt that mature security programs aren't automatically safe here, because the risky devices are often ones nobody remembered were online.

A common culprit is a cellular modem, a small box that gives a remote pump station a wireless internet link, installed years ago by a vendor or contractor and never logged in the utility's asset list. If it's not on the list, it doesn't get scanned, and it doesn't get fixed.

How are the hackers getting in?

Mostly through the front door. These controllers are sitting on the public internet with weak or default passwords, and attackers are simply logging in.

This isn't an exotic zero-day, meaning a secret software flaw the vendor doesn't know about. It's closer to leaving the keys in the ignition. We've been tracking Rockwell Automation's exposure across five water-utility stories since 30 July 2026, and this advisory is the most operationally direct warning yet. CISA specifically calls out Rockwell Automation MicroLogix 1400 controllers, pointing owners to Rockwell's notice on restoring access when the password is unknown if they've already been locked out.

What CISA wants utilities to do

Pull the controllers off the internet. Remote access, when needed, should run through a VPN or a gateway device that sits in front of the controller and checks who is knocking.

Action Why it matters
Disconnect PLCs from the public internet Removes the direct path attackers are using today
Change default passwords, turn on password protection Stops trivial guessing and known factory credentials
Restrict remote access to specific approved IP addresses Blocks random scanners on the internet
Keep a clean backup of the controller's configuration Lets operators recover fast if they get locked out

The US Environmental Protection Agency and the FBI contributed to the alert. Utilities that spot suspicious activity are asked to contact CISA's 24/7 Operations Center or the FBI's Internet Crime Complaint Center.

Should people worry about their tap water?

Not in a panic sense. Water utilities have physical safeguards and manual overrides that don't depend on a single controller behaving, which is why the visible impact so far has been operational headaches and precautionary boil-water notices rather than mass illness.

But the pattern matters. If you get a boil-water notice from your local utility, follow it: boil tap water for one full minute before drinking or cooking, until the utility says it's clear. The fact that the attack is this simple, just logging in with a default password, is exactly what should concern anyone responsible for these systems.

© 2026 Threat Vectr