posted in Technology

CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

www.privacyguides.org/news/2026/07/31/cisa-releases-guidance-urging-water-treatment-facilities-to-disconnect-equipment-from-the-internet/
Privacy GuidesCISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the InternetCISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

Replying to @⁨new_otters_raft@piefed.ca⁩

The hacks target internet-facing programmable logic controllers (PLCs)

Why the fuck
is your PLC
facing the fucking internet!

Jesus Zombie Christ an a pogo stick. Has no one been paying attention for the last two decades? Seriously, we learned this sort of lesson in Two Thousand and fucking Three. Your critical assets do not get public IP addresses.

en.wikipedia.orgSQL Slammer - Wikipedia

Replying to @⁨sylver_dragon@lemmy.world⁩

It usually happens in 2 steps.

First step is that everything gets connected to the LAN and you can only access the PLC network from within the building’s network. Then some time later, management finds out that keeping someone on-call to go out costs a fortune, so they request that access be made so they can make the change from anywhere.

The IT team argues security, but no new hardware can be provisioned and a developing a new process is too hard. Then the magical phrase is uttered: “Just make it work”. So IT punches a hole in the firewall, adds a NAT rule, and job done.

Replying to @⁨sylver_dragon@lemmy.world⁩

“Well, we just bought this new monitoring platform from my cousin’s company and they need access to it. No, their platform doesn’t support any real secure protocols and won’t route over a VPN, it needs to be on the same subnet as the devices. Ok, then just open all ports to the network so they can connect. No, they don’t know what port or protocol, it also runs out of my cousin’s house so it’s on a dynamic IP so you can’t create some type of access rule for it. Just put an any/any rule in and it’s good. What do you mean we already have a monitoring platform? Well, this one is better!”

Replying to @⁨blargh513@sh.itjust.works⁩

“No, their platform doesn’t support any real secure protocols and won’t route over a VPN, it needs to be on the same subnet as the devices. […]”

They won’t know that much. They don’t understand that their job isn’t running a water department, it’s running the computers that maintain the water department and that includes security. For someone familiar with computer security it’s easy to recognize negligence, but until the law sees it as criminal negligence nothing’s going to change.

Small town municipal water departments aren’t going to be able to afford the guy holding the shield against international state actors.