CyberzSOC

Publication detail
← Back to advisories & guidance

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs ↗ source

July 30, 2026 CISA Alert
Co-sealed by: CISA, EPA, FBI

Summary

These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC. Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.