The water sector just got it’s wake-up call. Again.

The FBI and EPA warned that cyberattacks against internet-facing PLCs have hit water and wastewater utilities in at least seven states, causing operational disruptions like pressure loss, flooding, and manual fallback. The attacks relied on exposed, outdated controllers and weak access controls, highlighting the need for utilities to remove PLCs from the public internet, strengthen passwords, and monitor OT environments continuously. #FBI #EPA #PLC #Aliquippa

Keypoints

  • Water and wastewater utilities in at least seven states were targeted through internet-facing PLCs.
  • Some attacks caused pressure loss, flooding, and forced systems into manual control.
  • Attackers used exposed controllers, weak credentials, and outdated devices with no recent security patches.
  • Utilities should secure remote access, change default passwords, and restrict device-to-device communication.
  • Continuous monitoring and a complete asset inventory are essential to detect and stop intrusions quickly.

Read More: https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/