Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Water plants told to unplug controllers

3 min read
16:08UTC

CISA's 30 July alert says intruders reaching internet-exposed controllers at water and wastewater plants have already caused boil water notices and forced operators to run plant by hand. Its instruction is to disconnect the controllers, not to patch them.

TechnologyAssessed
Key takeaway

Check the vendor's commissioning paperwork; scanning your own address space won't find modems on networks you never registered.

CISA published an alert on 30 July reporting a significant increase in threat actors reaching internet-exposed programmable logic controllers at Water and Wastewater Systems facilities of every size 1. A programmable logic controller, or PLC, is the small industrial computer that opens a valve, starts a pump or holds a chlorine dose steady. Attackers have changed the passwords on these devices to lock operators out of their own plant, and altered the network addresses the devices answer on. In CISA's words, the activity "has resulted in boil water notices and sustained manual operations" 2.

Read that plainly and it describes staff standing at a pump doing by hand what the controller used to do, and households told to boil what comes out of the tap. CISA names no utility and identifies no attacker, so the harm arrives as a sector-wide statement that nobody outside the agency can trace to an incident, a date or a town.

The instruction to operators is to take the controllers off the public internet. Patching does not appear. Controllers of this generation carry no cryptographic identity for the engineer connecting to them, so there is no authentication design to repair and no update that would make an exposed device safe to leave exposed; the fix available is architectural, which is why it reads as an instruction to unplug.

The blind spot the alert singles out defeats the usual assurance. Vendors and integrators fit cellular modems during commissioning, the modem never reaches the asset register, and a scan of the utility's own address space comes back clean while the controller sits reachable on somebody else's. For a small utility, disconnection also removes the remote monitoring adopted precisely because it cannot staff a control room overnight, which turns a security instruction into an operating cost. ENISA, the European Union Agency for Cybersecurity, put EU drinking water and wastewater into its NIS360 risk zone for the first time on 28 May ; the American version of that warning arrives written in boil water notices rather than risk scores.

Deep Analysis

In plain English

A programmable logic controller, or PLC, is a small industrial computer that opens and closes valves, runs pumps and manages other physical equipment at a water treatment plant. CISA says hackers are getting into these controllers over the internet at facilities of every size, in some cases changing the passwords so the people who run the plant get locked out, and changing the controller's network address so staff can't even find it to fix it. CISA's advice is blunt: disconnect these controllers from the internet rather than wait for a software fix, because this isn't a single bug you can patch, it's a connectivity problem. The alert confirms this has already caused boil-water notices, meaning residents in affected areas were told to boil tap water before drinking it, and forced some plants to run by hand rather than through automated controls.

Deep Analysis
Root Causes

CISA names the mechanism explicitly: vendors and integrators fit cellular modems onto PLCs during commissioning for remote diagnostics, and those modems don't appear on the asset-register scans utilities run to find internet exposure. The vendor installs the blind spot at commissioning, before any later misconfiguration has a chance to.

ENISA's NIS360 found a third of EU water utilities had never conducted a risk assessment at all; CISA's alert covers utilities 'of all sizes,' including some with mature cybersecurity processes, meaning the exposure survives even where an assessment has been done. Undocumented commissioning-time connectivity defeats both an absent assessment and a completed one.

What could happen next?
  • Risk

    Utilities that treat this as CISA's problem to patch, rather than their own asset-inventory gap, will remain exposed even after this specific campaign ends, because undocumented modems are a commissioning-process failure, not a single flaw.

  • Precedent

    CISA's disconnect-don't-patch instruction may become the template response for OT alerts where the failure is architectural rather than a single CVE.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Water plants told to unplug controllers
A federal agency has stated public-health harm from cyber intrusion as accomplished fact, sector-wide, without naming a single utility or attacker.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.