- Sources: CISA advisories index, BleepingComputer
- Summary: The CISA alerts index lists an alert dated 2026-07-30 titled CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs. No per-alert permalink resolved in this run, so the alert title and its date were read from the index. The reported activity is attackers changing PLC passwords to lock operators out and altering IP addresses to disconnect devices, and Minnesota IT Services activated the state incident response plan for what it described as a coordinated attack on operational technology at more than 30 community water systems, with some utilities switching to manual operation. CISA's instruction is to remove publicly exposed PLCs and other operational technology from the internet, and otherwise to reach them through a VPN or gateway, change default passwords, and restrict access to an IP allow-list. Censys quantifies the exposure at more than 4,100 internet-reachable Rockwell Automation and Allen-Bradley hosts, about 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts, and reports that nearly half the exposed Rockwell devices are reachable over consumer and carrier networks, which matches the alert's warning about undocumented cellular modems installed by operators, vendors, or integrators. No affected versions apply, because the alert describes password changes and IP reassignment against exposed controllers rather than exploitation of a versioned software defect. Reachable is not the same as targeted or compromised.
- Why it matters: The prescribed controls are inventory and network placement rather than a patch, so the work falls on whoever owns the remote-access path to the controller.
- Follow-up: Track whether CISA publishes a per-alert page with indicators, and whether the Minnesota incident is attributed.
send feedback on this story