U.S. water utility cyberattacks are becoming a massive operational technology security risk in 2026. CISA and the FBI have warned that malicious cyber actors are aggressively targeting internet-exposed programmable logic controllers, commonly known as PLCs, used by water and wastewater systems across the country.
According to the agencies, attackers have modified PLC passwords, locked legitimate operators out of their systems and changed device IP addresses. These actions can disrupt monitoring and operational workflows inside critical water infrastructure, leading to severe U.S. water utility cyberattacks.
The warning is important for every municipal utility, managed service provider and security team responsible for industrial control systems in the United States.
How U.S. Water Utility Cyberattacks Target Systems
Threat actors targeted PLCs that were directly accessible from the public internet. In several cases described by U.S. authorities, attackers were able to change device credentials and network settings.
Changing a PLC password can prevent authorized operators from accessing the device. Changing its IP address can also make the system difficult to locate or communicate with through normal control tools, a common tactic seen in U.S. water utility cyberattacks.
These actions may not immediately destroy equipment, but they can create operational disruption and delay an organization’s ability to respond to abnormal activity. As we’ve documented in our guide to Ransomware Critical Infrastructure Defense, such disruptions are often precursors to larger extortion attempts.
Why Are Exposed PLCs So Dangerous?
A PLC is an industrial computer that controls or monitors physical processes. In water and wastewater facilities, PLCs may be involved in pumping, pressure management, chemical treatment, alarms and other operational functions.
Unlike a normal office workstation, a compromised PLC can affect a real-world process. That is why internet exposure creates a higher risk than a standard unauthorized login.
- Operators may lose access to a critical device.
- Monitoring data may become unreliable or unavailable.
- Network configurations may be changed without authorization.
- Manual operations may be required while systems are investigated.
- Incident response may take longer if asset inventories are incomplete.
Which U.S. Organizations Are Most at Risk?
The warning is especially relevant to small and midsize water utilities that may have limited security staff and older industrial equipment. However, larger organizations should not assume that their systems are automatically protected from U.S. water utility cyberattacks.
Security teams should prioritize an immediate review if their environment includes:
- Internet-facing PLCs or remote terminal units.
- Remote access tools used by vendors or maintenance teams.
- Default or shared credentials on industrial devices.
- Legacy systems that cannot support modern authentication.
- Cloud dashboards connected directly to operational networks.
- Third-party access that has not been reviewed recently.
Immediate Security Steps for Water Utility IT Teams
1. Remove Direct Internet Exposure
Review all publicly reachable PLCs, HMIs, remote terminal units and other OT devices. Devices that do not need direct internet access should be removed from public exposure as soon as operationally possible to prevent U.S. water utility cyberattacks.
Use network segmentation, private connectivity and controlled remote-access gateways (ideally following a strict Zero Trust Architecture) instead of exposing industrial devices directly to the internet.
2. Change Default and Shared Credentials
Replace default passwords immediately. Every device and administrator account should use a unique credential. Shared passwords make it difficult to identify who accessed a system and increase the impact of a credential leak.
3. Audit Remote Access
Review every vendor, contractor and employee account that can reach the OT environment. Remove inactive accounts and restrict access to the systems required for a specific job.
Remote access should be time-limited where possible, monitored continuously and protected with multi-factor authentication.
4. Verify PLC Network Settings
Compare current PLC IP addresses, configurations and passwords with approved records. Unexpected changes should be treated as a potential security incident, not as a routine configuration issue.
5. Separate IT and OT Networks
Operational technology should not be placed on the same unrestricted network as normal office devices. Segmentation can limit how far an attacker moves after compromising an employee account or IT workstation.
6. Monitor Authentication and Configuration Changes
Enable logging for administrator logins, password changes, IP address modifications and remote sessions. Alert security staff when these actions occur outside an approved maintenance window. Due to the involvement of state-sponsored groups in these attacks, proactive Nation-State APT Threat Monitoring is highly recommended to stop U.S. water utility cyberattacks.
7. Prepare Manual Operating Procedures
Every water utility should know how to continue essential operations if a PLC or monitoring system becomes unavailable. Manual procedures should be documented, tested and accessible to plant operators.
Why IT and OT Teams Must Work Together
Traditional IT teams usually focus on endpoints, identity systems and cloud applications. OT teams focus on plant operations, safety and system availability. Both perspectives are necessary during a PLC security incident.
An IT team may identify a suspicious login, while an operator notices that a pump, sensor or dashboard is behaving unexpectedly. If these signals are not shared quickly, an attacker may remain active longer.
What to Do If Suspicious PLC Activity Is Detected
- Record the time and nature of the abnormal activity.
- Notify the incident response and OT operations teams.
- Do not make unnecessary configuration changes that could destroy evidence.
- Restrict unauthorized remote access using an approved response procedure.
- Verify device credentials, IP addresses and configuration files.
- Preserve relevant logs and access records.
- Follow current reporting guidance from CISA, the FBI and applicable state authorities.
- Restore systems only after their integrity has been validated.
The Bigger Lesson for Critical Infrastructure
The latest warning shows that attackers do not always need sophisticated malware to create disruption. An exposed device, weak credentials or poorly controlled remote access may be enough.
Water utilities should treat every internet-facing OT device as a high-priority asset. Asset inventory, network segmentation, strong authentication and tested recovery procedures are not optional extras for critical infrastructure security.
Conclusion
CISA and FBI warnings about exposed PLCs should be treated as an immediate action item by U.S. water and wastewater organizations. The first steps are straightforward: identify publicly reachable OT devices, remove unnecessary exposure, change default credentials, review remote access and monitor configuration changes.
Frequently Asked Questions
What is a PLC?
A programmable logic controller, or PLC, is an industrial computer used to monitor and control physical processes. Water facilities may use PLCs for pumping, treatment, alarms and other operational functions.
Why are internet-exposed PLCs a security risk?
Publicly reachable PLCs can be discovered and targeted by attackers. If access controls are weak, attackers may change credentials, network settings or operational configurations.
Official Government Sources
For official incident response guidance, please refer to the federal resources below:




