Unpatched PLCs and Weak Credentials Put US Water Utilities at Risk
Attackers exploited internet-facing programmable logic controllers (PLCs) across water utilities in at least seven US states, leveraging unpatched devices and weak or default credentials — no sophisticated techniques required. The root failures were foundational: critical operational technology (OT) was left exposed to the public internet without hardening, patching, or strong authentication. These oversights resulted in real-world physical consequences, including pressure loss and flooding, demonstrating that cyber vulnerabilities in critical infrastructure translate directly into public safety risks. The fact that a joint FBI/EPA alert was necessary underscores how persistently the water sector lags behind on basic cyber hygiene. This is not a novel threat — it is a recurring, preventable one.
Tactical Insight
Immediate Actions
- Audit all internet-facing OT/ICS devices (PLCs, HMIs, SCADA) and remove or firewall any that do not require direct internet exposure.
- Immediately change all default and weak credentials on PLCs and related control systems to strong, unique passwords.
- Apply all available patches and firmware updates to operational technology devices, prioritizing internet-facing assets.
Long-Term Improvements
- Implement network segmentation to isolate OT/ICS environments from both the public internet and corporate IT networks using DMZs and industrial firewalls.
- Establish a formal vulnerability management program specifically covering OT/ICS assets, including a maintained inventory of all field devices and their patch status.
- Enforce multi-factor authentication (MFA) for all remote access to control systems and operational networks.
Detection & Response Measures
- Deploy continuous monitoring and anomaly detection on OT networks to identify unauthorized access or unusual command sequences in real time.
- Develop and regularly exercise an OT-specific incident response plan that includes coordination procedures with the FBI, EPA, and CISA.
- Implement logging on all PLCs and network devices with centralized log aggregation to support forensic investigation after any incident.