Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Water plants told to unplug controllers

3 min read
12:09UTC

CISA's 30 July alert says intruders reaching internet-exposed controllers at water and wastewater plants have already caused boil water notices and forced operators to run plant by hand. Its instruction is to disconnect the controllers, not to patch them.

TechnologyAssessed
Key takeaway

Check the vendor's commissioning paperwork; scanning your own address space won't find modems on networks you never registered.

CISA published an alert on 30 July reporting a significant increase in threat actors reaching internet-exposed programmable logic controllers at Water and Wastewater Systems facilities of every size 1. A programmable logic controller, or PLC, is the small industrial computer that opens a valve, starts a pump or holds a chlorine dose steady. Attackers have changed the passwords on these devices to lock operators out of their own plant, and altered the network addresses the devices answer on. In CISA's words, the activity "has resulted in boil water notices and sustained manual operations" 2.

Read that plainly and it describes staff standing at a pump doing by hand what the controller used to do, and households told to boil what comes out of the tap. CISA names no utility and identifies no attacker, so the harm arrives as a sector-wide statement that nobody outside the agency can trace to an incident, a date or a town.

The instruction to operators is to take the controllers off the public internet. Patching does not appear. Controllers of this generation carry no cryptographic identity for the engineer connecting to them, so there is no authentication design to repair and no update that would make an exposed device safe to leave exposed; the fix available is architectural, which is why it reads as an instruction to unplug.

The blind spot the alert singles out defeats the usual assurance. Vendors and integrators fit cellular modems during commissioning, the modem never reaches the asset register, and a scan of the utility's own address space comes back clean while the controller sits reachable on somebody else's. For a small utility, disconnection also removes the remote monitoring adopted precisely because it cannot staff a control room overnight, which turns a security instruction into an operating cost. ENISA, the European Union Agency for Cybersecurity, put EU drinking water and wastewater into its NIS360 risk zone for the first time on 28 May ; the American version of that warning arrives written in boil water notices rather than risk scores.

Deep Analysis

In plain English

A programmable logic controller, or PLC, is a small industrial computer that opens and closes valves, runs pumps and manages other physical equipment at a water treatment plant. CISA says hackers are getting into these controllers over the internet at facilities of every size, in some cases changing the passwords so the people who run the plant get locked out, and changing the controller's network address so staff can't even find it to fix it. CISA's advice is blunt: disconnect these controllers from the internet rather than wait for a software fix, because this isn't a single bug you can patch, it's a connectivity problem. The alert confirms this has already caused boil-water notices, meaning residents in affected areas were told to boil tap water before drinking it, and forced some plants to run by hand rather than through automated controls.

Deep Analysis
Root Causes

CISA names the mechanism explicitly: vendors and integrators fit cellular modems onto PLCs during commissioning for remote diagnostics, and those modems don't appear on the asset-register scans utilities run to find internet exposure. The vendor installs the blind spot at commissioning, before any later misconfiguration has a chance to.

ENISA's NIS360 found a third of EU water utilities had never conducted a risk assessment at all; CISA's alert covers utilities 'of all sizes,' including some with mature cybersecurity processes, meaning the exposure survives even where an assessment has been done. Undocumented commissioning-time connectivity defeats both an absent assessment and a completed one.

What could happen next?
  • Risk

    Utilities that treat this as CISA's problem to patch, rather than their own asset-inventory gap, will remain exposed even after this specific campaign ends, because undocumented modems are a commissioning-process failure, not a single flaw.

  • Precedent

    CISA's disconnect-don't-patch instruction may become the template response for OT alerts where the failure is architectural rather than a single CVE.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

CISA· 3 Aug 2026
Read original
Causes and effects
This Event
Water plants told to unplug controllers
A federal agency has stated public-health harm from cyber intrusion as accomplished fact, sector-wide, without naming a single utility or attacker.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.