Water Sector PLCs Under Active Attack, CISA Orders Immediate Disconnect
The persistent gap isn't internet exposure, it's the undocumented cellular modems vendors install that bypass asset management entirely.
TL;DR
CISA reports threat actors are systematically compromising internet-exposed PLCs at water and wastewater utilities of all sizes, modifying passwords and IP configurations to lock out operators and force manual operations. The activity has already triggered boil-water notices. CISA's central demand: disconnect exposed PLCs from the internet immediately. Even organizations with mature cybersecurity programs are warned to hunt for undocumented cellular modems installed by vendors or system integrators, devices that won't appear in routine attack-surface scans and can nullify the best perimeter defenses.

CISA's alert this week lands differently than the 2023 Unitronics advisory. The earlier warning named a specific vendor and a default password: Unitronics Vision Series, "1111." This one doesn't. The threat actors aren't exploiting a single CVE, they're exploiting the condition of being reachable. They change the password, change the IP, and the operator walks into a locked-out PLC and a treatment process running blind. That's the bluntness of the alert, and it's worth sitting with: CISA is telling every water utility in the country to pull internet-facing PLCs offline, full stop.
The operational consequences of ignoring this aren't theoretical. Boil-water notices are already in effect at affected systems. Manual operations (meaning someone physically driving to pump stations and turning valves) are sustained, not temporary. For smaller utilities that run lean staffing, manual operations are a crisis, not a workaround.
The undocumented-modem gap
The most consequential paragraph in the alert is the one about cellular modems. CISA warns that even "mature" organizations need to validate external connections because vendors and integrators install cellular modems that aren't documented and don't appear in routine attack-surface scans. This is the practitioner problem. A utility can have every perimeter control right, every asset-management workflow running, and still be blind to a modem a system integrator plugged in three years ago during commissioning and never told anyone about.
That gap isn't a failure of policy. It's a structural mismatch: OT asset management is designed around what the owner installed and knows about. Vendor-installed remote-access hardware sits outside that inventory by default. The CISA alert essentially tells every water-sector operator to go physically look at their PLC cabinets and trace every cable.
The continuity with IRGC activity, and what's different
The water sector has been here before. In November 2023, IRGC-affiliated actors using the "CyberAv3ngers" persona compromised Unitronics PLCs at multiple U.S. water facilities through default passwords and internet exposure. That advisory was updated in December 2024 with expanded TTPs and mitigation guidance. The current alert doesn't attribute activity to a specific actor, but the targeting pattern (internet-exposed PLCs in water systems, password modification, lockout) mirrors what the joint advisory described.
What's different now is the scale and the operational impact. The 2023 activity was documented at a handful of facilities. CISA's current alert describes "a significant increase" in targeting, affecting entities of all sizes, with confirmed boil-water notices. The agency isn't naming a number of compromised systems, but the alert's urgency ("as soon as possible," not "review and implement at your earliest convenience") suggests they're seeing something that isn't contained.
What the practitioner does Monday
The immediate action is binary: find every internet-facing PLC and disconnect it. Remote access must route through a VPN or gateway device, not directly to the PLC. After disconnection, verify a known-clean backup of the PLC logic and configuration exists, if a threat actor has already changed the password, the backup is the only recovery path short of vendor intervention.
The harder Monday task is the modem hunt. Walk the physical PLC cabinets. Identify every cellular modem, trace its ownership (vendor? integrator? internal?), and either document it or remove it. For organizations using Rockwell Automation MicroLogix 1400 PLCs, Rockwell has published separate password-recovery guidance that CISA explicitly references.
The EPA's Cybersecurity Technical Assistance Program for the Water Sector is available for utilities that need help scoping the exposure. CISA regional offices can provide additional support, and incidents should be reported to CISA's 24/7 Operations Center or the FBI's IC3.
Published ·Deep Fathom