SHIELD: ACTIVE // NETWORK SECURE

FBI and CISA Warn of Escalating Cyberattacks Targeting Water System PLCs

Security Advisory: Escalating Cyberattacks Targeting Water System PLCs

Executive Summary

On July 31, 2026, a joint security advisory was issued by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) regarding a significant escalation in cyberattacks against United States drinking water and wastewater treatment facilities. These attacks specifically target internet-exposed Programmable Logic Controllers (PLCs), which are essential for automating physical processes such as chemical dosing and water pumping. Adversaries have successfully modified device passwords and IP addresses, resulting in operator lockouts, communication failures with monitoring networks, and the imposition of boil-water advisories due to forced manual emergency operations.

Technical Analysis of Industrial Control Vulnerabilities

PLCs and Human-Machine Interfaces (HMIs) function as the primary interface between digital commands and physical industrial actions. When these devices are exposed to the public internet without proper network segmentation or virtual private network (VPN) protections, they become vulnerable to automated scanning and exploitation by state-sponsored and criminal threat actors.

Attack Vector and Port Analysis

The current campaign utilizes remote exploitation of industrial protocols that lack sufficient authentication. The following table outlines the primary protocols and ports identified in these activities:

Protocol Type

Common Target Ports

Exploitation Method

Modbus

TCP Port 502

Direct remote command execution via unauthenticated scripts.

EtherNet/IP

Port 44818

Automated scanning and connection to exposed OT interfaces.

Proprietary Interfaces

Various Vendor Web Ports

Exploitation of default credentials or weak authentication tokens.

Execution Mechanics

1. Access and Credential Takeover: Threat actors utilize default vendor credentials or exploit weak tokens to gain administrative access to the PLC interface. They subsequently overwrite passwords to prevent legitimate access by municipal operators.

2. Network Isolation: By reconfiguring static IP addresses and subnet settings, attackers sever the connection between the PLC and Supervisory Control and Data Acquisition (SCADA) consoles. This effectively blinds operators to real-time system telemetry.

3. Process Manipulation: Attackers adjust operational thresholds, disrupting automated filtration and treatment. Recent incidents have necessitated the shutdown of automated systems and the transition to manual operation to maintain safety.

Mitigation and Defense Directives

The vulnerability of water and wastewater systems (WWS) is often exacerbated by legacy equipment and constrained security budgets. CISA and the FBI recommend the following immediate actions for utility providers:

Primary Defensive Actions

* Internet Decoupling: Immediately audit networks to identify and remove all PLCs, HMIs, and SCADA interfaces from the public internet. All Operational Technology (OT) assets must be secured behind firewalls.

* Remote Access Security: Enforce multi-factor authentication (MFA) for all remote pathways into the OT environment. Use hardware-authenticated VPNs or dedicated industrial jump boxes for management sessions.

* Credential and Configuration Hardening: Replace all default vendor passwords with unique, complex passphrases. Ensure that offline, out-of-band backups of PLC firmware and logic code are maintained for recovery during lockout events.

* Network Segmentation: Implement the Purdue Model to strictly divide Information Technology (IT) and OT networks. Deploy OT-specific intrusion detection systems (IDS) to identify unauthorized protocol commands or configuration changes.

Operational status should be monitored by Person to ensure all directives are implemented by Date.

Category: Cyber Security Intelligence