FILTERING BY: CLEAR FILTER

CISA Directive: Decommissioning Internet-Exposed PLCs in Water Utility Sector

Between July 26 and 27, 2026, a coordinated cyberattack targeted the operational technology (OT) of over 30 community water systems in Minnesota, including Plymouth, South St. Paul, Maple Plain, and Braham. The threat actor exploited publicly accessible Programmable Logic Controllers (PLCs) to gain unauthorized access to control networks. While water safety remained uncompromised, the event exposed systemic failures in OT perimeter security and network segmentation. In response, CISA has issued an urgent directive for water utilities to identify and decommission all internet-exposed PLCs and SCADA interfaces to mitigate the risk of large-scale critical infrastructure exploitation.


LINK COPIED TO CLIPBOARD