Internet-Exposed PLCs Fuel Multistate Water Attacks

CISA and the FBI said a campaign targeting internet-exposed programmable logic controllers (PLCs) in U.S. water and wastewater systems has spread across at least a dozen states, with Minnesota first to confirm more than 30 affected systems. New Jersey and Alabama were the latest states to report incidents, joining Georgia, Michigan, and South Dakota. The attacks use the PLCs’ own management functions to change passwords or IP addresses. That can lock operators out and make a controller look disconnected even when no malware is involved, which leaves visibility and control disrupted and forces some sites onto manual workarounds. The exposure sits on the public-facing management plane, not one vendor’s bug list. For any utility or integrator with controllers reachable from the internet, the blast radius is the device fleet itself: if one controller can be reached and reconfigured, the operational loss can spread beyond a single site.

Part of the PlainSec briefing for 2026-08-10

Every edition of this story: Internet-Exposed PLCs Fuel Multistate Water Attacks

Sources