CISA published an alert on 30 July reporting a significant increase in threat actors reaching internet-exposed programmable logic controllers at Water and Wastewater Systems facilities of every size 1. A programmable logic controller, or PLC, is the small industrial computer that opens a valve, starts a pump or holds a chlorine dose steady. Attackers have changed the passwords on these devices to lock operators out of their own plant, and altered the network addresses the devices answer on. In CISA's words, the activity "has resulted in boil water notices and sustained manual operations" 2.
Read that plainly and it describes staff standing at a pump doing by hand what the controller used to do, and households told to boil what comes out of the tap. CISA names no utility and identifies no attacker, so the harm arrives as a sector-wide statement that nobody outside the agency can trace to an incident, a date or a town.
The instruction to operators is to take the controllers off the public internet. Patching does not appear. Controllers of this generation carry no cryptographic identity for the engineer connecting to them, so there is no authentication design to repair and no update that would make an exposed device safe to leave exposed; the fix available is architectural, which is why it reads as an instruction to unplug.
The blind spot the alert singles out defeats the usual assurance. Vendors and integrators fit cellular modems during commissioning, the modem never reaches the asset register, and a scan of the utility's own address space comes back clean while the controller sits reachable on somebody else's. For a small utility, disconnection also removes the remote monitoring adopted precisely because it cannot staff a control room overnight, which turns a security instruction into an operating cost. ENISA, the European Union Agency for Cybersecurity, put EU drinking water and wastewater into its NIS360 risk zone for the first time on 28 May ; the American version of that warning arrives written in boil water notices rather than risk scores.
