The hard failure here is loss of operator control, not just a noisy intrusion. Once someone can reach a PLC’s management plane, they can change passwords and IP settings, cut operators off, and leave the site running only in manual mode.
CISA says it is seeing a significant increase in attacks on internet-exposed PLCs in water and wastewater systems. The agency says the activity has already caused boil water notices and sustained manual operations, and that the exposed paths can include cellular modems installed by operators, vendors, or system integrators that never made it into routine inventory.
That means perimeter scans that only look for obvious internet-facing devices miss the real trust path. If the control plane is reachable, the attacker can rewrite who is trusted to manage the plant, and the lockout can persist even after the initial access point is found.
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
CISA warns of cyberattacks disrupting U.S. water utilities
Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.