The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in water and wastewater systems across the country.
CISA issued the alert following a pattern of attacks on critical infrastructure that manages essential water services. The attacks focus on PLCs—industrial control systems that regulate water treatment, distribution, and wastewater management operations.
Programmable logic controllers exposed to the internet represent a primary vulnerability. Attackers exploit these access points to potentially disrupt water service delivery, compromise water quality monitoring, or cause operational shutdowns.
The agency did not disclose the specific number of affected utilities or attacks detected. However, the warning indicates the threat level warrants immediate attention from water system operators nationwide.
CISA recommends water utilities implement several defensive measures: immediately audit all internet-connected PLCs and industrial control systems, restrict network access to essential personnel only, deploy network monitoring to detect suspicious activity, and apply available security patches and firmware updates.
The agency also advises utilities to segment their operational technology networks from IT systems, establish secure remote access protocols, and develop incident response plans specific to cyberattacks on water infrastructure.
Water utilities fall under critical infrastructure protection frameworks due to their essential role in public health and safety. Disruptions to these systems can affect millions of people and potentially create public health emergencies.
The alert reflects broader concerns about the vulnerability of U.S. critical infrastructure to state-sponsored and criminal cyber actors. Previous incidents have demonstrated that attackers target industrial control systems managing power grids, pipelines, and other essential services.
Utility operators are urged to contact CISA's 24/7 operations center for technical assistance and threat intelligence related to their specific systems. The agency also maintains a repository of indicators of compromise and attack patterns that utilities can use to strengthen their defenses.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.
Healthcare software company Unlimited Technology Systems disclosed a data breach affecting 3.8 million individuals. The breach occurred in October 2025.