CYBERSECURITYTRACKER
TRACKING7,218 stories in this site build1,512 vulnerability news stories in this site build
Permanent story citation

The water sector just got it’s wake-up call. Again.

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3969

As cited

Copy frozen at (site build).

ot ics

The water sector just got it’s wake-up call. Again.

Since July 27, the FBI and EPA alerted utilities in at least seven states to cyberattacks targeting internet-exposed programmable logic controllers (PLCs) that operate water treatment equipment. The attacks, which required no sophisticated techniques, caused operational disruptions including pressure loss, flooding, and forced manual control in some systems. Water utilities remain vulnerable due to legacy equipment, limited cybersecurity budgets, voluntary compliance rules, and basic security gaps like default passwords and internet-exposed controllers.

Why it matters: Water utility operators and chief information security officers must act immediately to remove PLCs from internet exposure, enforce strong authentication, segment control system networks, and practice manual operations, as attackers are expanding from past incidents to coordinated multi-state disruptions that can interrupt water service to communities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary