Water Utility Cyberattacks: PLCs Emerge as Hackers' Main Entry Point

Water Utility Cyberattacks: PLCs Emerge as Hackers' Main Entry Point

Water Utility Cyberattacks: PLCs Emerge as Hackers' Main Entry Point

For decades, water and wastewater utilities treated their programmable logic controllers (PLCs) as dependable, low-maintenance workhorses that simply ran the plant. That assumption is now the single largest cybersecurity liability in critical infrastructure. In a report published September 30, 2026, industry security officials detailed a bruising summer of

3 min readContent reviewed

Detail

in which internet-exposed PLCs served as the primary intrusion vector , a warning that should push every operator to audit exactly how their control systems touch the public internet.

Physical reliability and cyber resilience have converged. A PLC engineered before the internet era is now a frontline attack surface, while uptime , not patching , has traditionally been the operator's priority. That gap between operational legacy and modern threats is the defining industrial risk of 2026.

Tom Dobbins, executive director of the Water Information Sharing and Analysis Center (WaterISAC), told CyberScoop that PLCs are “obviously” a vulnerability point and have been the “main point of entry” for hackers across the sector.

“A lot of the equipment was developed pre-cyber threats and activities,” Dobbins said. “The equipment, it’s still valuable, it still is operational, so there’s not a huge reason or incentive for utilities to upgrade it.”

That economic logic , working hardware, constrained budgets, and no visible failure , is precisely what keeps vulnerable controllers in service nationwide. Compounding the problem, older-generation systems often remain directly reachable from the internet, a condition security officials say must be eliminated outright.

The threat is not theoretical. A July 2026 joint advisory from the FBI and EPA warned that malicious actors were targeting internet-facing OT devices, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs. After gaining remote access, attackers changed IP addresses and passwords, producing a loss of monitoring and control functionality.

On July 30, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) escalated its own alert, urging owners and operators to remove publicly exposed PLCs and other OT from the internet “as soon as possible.” CISA noted the campaign included cellular modems installed by operators, vendors, or integrators that may not appear in routine attack-surface scans.

Sourcing help

Send the BOM for one quote covering active stock, EOL stock and cross-references.

Need a quote for this part?

Send us the part number or article link — we will confirm price, availability and lead time.

WhatsApp us

Related Articles

Torna al blog