CISA Warns Hackers Are Breaking Into Water Plant Controllers Left Exposed on the Internet

The US cyber agency says attackers are locking operators out of the small industrial computers that run water systems, forcing boil-water notices and manual operations.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a rack-mounted network security appliance in a dim data center aisle, status LEDs glowing amber and re
Share

Key points

  • CISA says hackers are actively breaking into internet-exposed programmable logic controllers, the small industrial computers that run pumps and valves, at US water and wastewater utilities.
  • Attackers have changed passwords and IP addresses on the devices, locking out staff and forcing some plants to run by hand.
  • At least one incident tied to this activity has led to a boil-water notice for local residents.
  • Rockwell Automation MicroLogix 1400 controllers are among the affected devices, and Rockwell has published guidance for owners locked out by an unknown password.
  • CISA wants every water utility to pull these controllers off the public internet immediately and require a VPN, a private encrypted tunnel, for any remote access.

The US Cybersecurity and Infrastructure Security Agency is telling water utilities to yank their control systems off the public internet, now, because attackers are actively hunting them down and locking operators out.

The warning, published by CISA Cybersecurity Advisories, focuses on programmable logic controllers. Those are the small, rugged computers that open valves, run pumps and mix chemicals inside a treatment plant. In plain terms: they are the brains that keep tap water safe.

CISA says attackers are finding these devices exposed on the open internet, changing their passwords so plant staff cannot log back in, and in some cases switching the device's network address so it drops off the utility's own systems.

The result has been ugly. Some utilities have had to switch to manual operations, meaning staff physically walking the plant to keep things running. At least one incident led to a boil-water notice for residents, the standard public health warning when drinking water may not be safe.

Who is being targeted?

Every size of water utility, from small rural systems to large municipal operators. CISA is blunt that mature security programs are not automatically safe here, because the risky devices are often ones nobody remembered were online.

A common culprit is a cellular modem, a small box that gives a remote pump station a wireless internet link, installed years ago by a vendor or contractor and never logged in the utility's asset list. If it is not on the list, it does not get scanned, and it does not get fixed.

How are the hackers getting in?

Mostly through the front door. These controllers are sitting on the public internet with weak or default passwords, and attackers are simply logging in.

This is not an exotic zero-day, meaning a secret software flaw the vendor does not know about. It is closer to leaving the keys in the ignition. CISA specifically calls out Rockwell Automation MicroLogix 1400 controllers, and points owners to Rockwell's notice on restoring access when the password is unknown if they have already been locked out.

What CISA wants utilities to do

Pull the controllers off the internet. Remote access, when needed, should run through a VPN or a gateway device that sits in front of the controller and checks who is knocking.

Action Why it matters
Disconnect PLCs from the public internet Removes the direct path attackers are using today
Change default passwords, turn on password protection Stops trivial guessing and known factory credentials
Restrict remote access to specific approved IP addresses Blocks random scanners on the internet
Keep a clean backup of the controller's configuration Lets operators recover fast if they get locked out

The US Environmental Protection Agency and the FBI contributed to the alert, and utilities that spot suspicious activity are asked to contact CISA's 24/7 Operations Center or the FBI's Internet Crime Complaint Center.

Should people worry about their tap water?

Not in a panic sense, no. Water utilities have physical safeguards, chemical monitoring and manual overrides that do not depend on a single controller behaving. That is why the visible impact so far has been operational headaches and precautionary boil-water notices, not mass illness.

But the pattern matters. If you get a boil-water notice from your local utility, follow it: boil tap water for a full minute before drinking, cooking or brushing teeth, until the utility says it is clear.

© 2026 Threat Vectr