Particle.news

Federal Alert: Hackers Target Internet‑Exposed PLCs, Disrupt U.S. Water Controls

Agencies warn operator lockouts caused by changed PLC passwords along with altered IP settings can force manual operations, raising safety, systemic risk.

Overview

  • A coordinated intrusion that hit more than 30 Minnesota community water systems on July 26–27 prompted CISA to issue an urgent July 30 alert about rising attacks on internet‑exposed programmable logic controllers.
  • Investigators say attackers are logging into publicly reachable PLC management interfaces, changing device passwords to lock out operators and altering PLC IP settings to sever remote monitoring and control.
  • CISA, the FBI, and the EPA urge immediate steps: remove PLCs from direct internet access, broker remote access through VPNs or jump hosts, enforce unique strong passwords, and implement IP allowlisting.
  • Internet scans from Censys show thousands of potentially exposed devices across major vendors, and agencies warn undocumented cellular modems and end‑of‑sale firmware are common blind spots that increase attack surface.
  • State and federal investigations are active with no formal attribution, utilities report mostly restored service using manual controls, and agencies warn hardening OT will drive audits, recovery costs, and ongoing scrutiny of small utilities.