CISA warns of increased attacks on control units in water and wastewater
CISA issued an alert on 30 July 2026 stating that several threat actors are attacking programmable logic controllers, known as PLCs, in the water and wastewater sector. The attackers have changed passwords so that operators were locked out of their own plants, and they have altered IP addresses so that controllers lost connectivity. The consequences have been boil water notices to residents and sustained manual operation. CISA states that the activity has affected water entities of all sizes, and that it has also reached cellular modems installed by operators, vendors or system integrators. Such modems are often missing from asset inventories and are not picked up by routine external scanning.
What happens technically
A PLC is a small industrial computer that drives pumps, valves and dosing equipment according to a fixed program. The device is built to run for years without a restart, not to withstand attack on an open network. Many models have weak authentication or none at all by default, and they ship with well known default passwords. When the device is reachable directly from the internet, no vulnerability in the ordinary sense is needed. It is enough to log in with the password that has always been there, and then change it.
The two moves CISA describes hit different parts of operations. A changed password removes the operator's ability to control the plant, without the process itself necessarily changing. A changed IP address disconnects the device from monitoring, so operators lose visibility even while the pumps keep running. The third finding is the easiest to overlook. Cellular modems tend to be installed so that a vendor can provide remote support, and they open a route into the plant that bypasses the organisation's own network. Such a connection does not appear in a scan of the organisation's own addresses, because it does not live there. CISA therefore asks organisations to validate all external connections, including undocumented cellular links, and recommends routing remote access through a VPN or gateway, replacing default passwords, allowlisting approved addresses, and keeping a known clean backup of each PLC image.
What this means for you as a water and wastewater operator
Berigo's assessment is that this case lands on you directly, and that it lands on a tender spot. Water plants are often run by small technical teams in municipalities or intermunicipal companies, where the automation is delivered and maintained by an external supplier. The consequence described is not data loss either. It is boil water notices and manual operation, meaning an incident residents notice the same day. Water supply and wastewater are among the sectors NIS2 counts as essential, and the Article 21 requirements for risk management, access control and incident handling apply just as much to a small plant with three employees.
The practical test for you is therefore preparedness and oversight, not advanced detection. Can you run the plant manually for several days, and do you have the people to do it. Is the program image of each PLC stored somewhere other than on the device itself, so you can restore the unit after a password change you did not make. In our view the heaviest work sits in the dullest item, namely producing a complete list of the routes that lead into your plant. A cellular modem installed by a system integrator five years ago appears in no budget and on no network diagram, yet it is a door.
Berigo recommends
- Take controllers and other operational technology off the internet, and route remote access through a VPN or gateway with strong authentication.
- Replace every default password, and use different passwords per plant and per device.
- Map all external connections, including cellular modems installed by suppliers, and record them in the asset inventory.
- Take a verified copy of the program image in each PLC, store it separately, and rehearse restoration.
- Rehearse manual operation across several days, and settle in advance who notifies residents.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch