Independent Reviews
Back to VPN Security News
CybersecurityPublished 1 Aug 20266 min read3 sources

CISA Water-Utility Warning: Why Exposed PLCs Should Not Sit on the Internet

CISA says attackers are increasingly targeting water and wastewater PLCs, changing passwords, disconnecting devices and forcing some operators into boil-water notices or manual operations.

Quick takeaways

  • CISA says it is seeing a significant increase in threat activity against programmable logic controllers in the water and wastewater sector.
  • The practical fix is not a consumer VPN subscription; it is removing PLCs from direct internet exposure and brokering remote access through monitored gateways, firewalls or site-to-site VPN controls.
  • For households, the story is a reminder to treat public-infrastructure alerts calmly: follow local utility notices, keep emergency contact details current and be wary of fake water-bill or boil-notice messages.

What happened?

CISA issued a 30 July alert warning that cyber threat actors are increasingly targeting programmable logic controllers, or PLCs, in the water and wastewater systems sector. The agency says attackers have targeted exposed operational-technology assets, changed PLC passwords to lock out operators and changed IP addresses to disconnect devices.

CISA says the activity has already led to operational consequences, including boil-water notices and sustained manual operations. It also warns that water entities of all sizes are being targeted, including organisations with mature cybersecurity processes that may still have undocumented cellular modems or vendor-installed remote connections outside normal inventories.

Why it matters

This is not just another office-IT breach. PLCs help control pumps, treatment equipment and other physical processes. If an attacker can reach those systems directly from the internet, a password change or configuration tweak can become an operational disruption for the people who rely on that utility.

The consumer lesson is also practical: critical infrastructure incidents can trigger confusing local notices, emergency communications and scam opportunities. Attackers often piggyback on real disruption with fake payment links, fake support numbers or urgent messages that try to harvest account details.

What utilities and vendors should do now

CISA's headline advice is direct: remove publicly exposed PLCs and other OT assets from the internet as soon as possible. Remote operational access should not connect straight to a PLC. It should be mediated through a gateway, firewall, proxy, VPN or similar controlled access layer with logging and strong authentication.

Operators should also change default passwords, use strong unique credentials, allowlist known engineering laptops and critical OT assets, verify external connections including cellular modems, and keep known-clean PLC backups in case a password change locks staff out. CISA's related advisory also points to secure gateways, MFA-capable controls and monitored access paths for remote work.

Where a VPN helps — and where it does not

A VPN can help in the enterprise or utility sense when it is part of a managed remote-access design: for example, a site-to-site VPN, private APN, ZTNA gateway or admin VPN that prevents direct PLC exposure and adds authentication, monitoring and access rules in front of fragile OT equipment.

A personal VPN used by a household cannot protect a town's water PLCs, undo a utility cyberattack or verify whether a boil-water notice is real. For ordinary readers, the right response is to follow official local utility and public-health channels, avoid links in unexpected texts, and keep a basic emergency-water plan for outages or notices.

VPN Rocks view

This story shows why VPN advice needs context. For a travelling user on hotel Wi-Fi, a personal VPN protects traffic from the local network. For a water operator, a VPN or gateway is a way to reduce exposed management paths. Those are related ideas, but they are not interchangeable.

If you run a small industrial, facilities or building-management environment, use this alert as a reason to inventory anything reachable from the internet, especially forgotten cellular modems and vendor-maintained remote access. The boring controls — no direct exposure, strong authentication, allowlists, logs and backups — are exactly what CISA is pushing.

Sources and further reading

VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.

Useful next steps