Skip to content
HN On Hacker News ↗

CISA Alert: Water Sector PLC Targeting

▲ 93 points 76 comments by speckx 3w ago HN discussion ↗

Pangram verdict · v3.3

We believe that this text is a mix of AI and human-written content.

80 %

AI likelihood · overall

AI
13% human-written 87% AI-generated
SEGMENTS · HUMAN 1 of 4
SEGMENTS · AI 2 of 4
WORD COUNT 602
PEAK AI % 89% · §1
Analyzed
Aug 1
backend: pangram/v3.3
Segments scanned
4 windows
avg 151 words each
Distribution
13 / 87%
human / AI fraction
Verdict
AI
Pangram v3.3

Article text · 602 words · 4 segments analyzed

Human AI-generated
§1 AI · 89%

Download the full brief → Introduction CISA issued an alert on July 30, 2026 warning that threat actors are increasingly targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) sector, in some cases modifying passwords to lock out operators and disconnecting devices by changing their IP addresses, resulting in boil-water notices and sustained manual operations. CISA named Rockwell Automation/Allen-Bradley, Siemens, and Schneider Electric equipment and flagged cellular modems as a common blind spot in routine attack-surface scans. This report characterizes current Censys-observed internet exposure for each named vendor: 4,148 Rockwell/Allen-Bradley EtherNet/IP hosts, 4,117 Siemens SIMATIC S7-1200 hosts, and 2,072 Schneider Electric hosts (vendor-wide, not PLC-scoped), all as of the 2026-07-30 snapshot. This is an exposure characterization only: it does not confirm that any specific host is a victim of the activity CISA describes. Advisory Context The following paraphrases the CISA alert as supplied by the user for this report; it was not independently re-fetched from cisa.gov in this session. CISA is observing a significant increase in threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Observed actor behavior includes modifying PLC passwords to lock out operators and disconnecting PLCs by changing their IP addresses, producing boil-water notices and sustained manual operations at affected utilities. Targeting affects water entities of all sizes, including organizations with mature cybersecurity processes. CISA specifically flags cellular modems installed by operators, vendors, or system integrators as a common blind spot: these connections may be undocumented and excluded from routine attack-surface scans. Owners of Rockwell Automation MicroLogix 1400 controllers are directed to Rockwell’s guidance for restoring access when a controller password is unknown. CISA-Recommended Mitigations Disconnect the PLC from the internet; route remote access through a VPN or gateway device, not directly to the PLC. Enable password protection and change default passwords. Allowlist IPs to permit remote access only from known engineering laptops or other critical OT assets. This report addresses the exposure-characterization question only — current internet-facing host counts, geography, and network concentration for the three named vendors — and does not assess the mitigations above, IOC infrastructure, or attribution. Rockwell/Allen-Bradley Ethernet/IP Censys ARC identified 4,148 Internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley. The United States remains dominant at 71.0% (2,945 hosts), with Canada a clear second at 11.5% (476 hosts). Geographic Distribution Rockwell/Allen-Bradley EtherNet/IP exposure by country (Censys, 2026-07-30) Network/ASN Distribution Rockwell/Allen-Bradley EtherNet/IP exposure by network/ASN (Censys, 2026-07-30). Combined cellular carriers (Verizon Business, AT&T Mobility, T-Mobile USA) account for 59.0% of all exposed hosts. Siemens Simatic S7-1200 Censys ARC identified 4,117 Internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200. Exposure concentrates heavily in southern and central Europe: Greece, Spain, Italy, and Austria together account for 86.0% of the total, each dominated by that country’s leading mobile carrier rather than fixed-line or hosting providers.

§2 Mixed · 41%

Geographic Distribution Siemens SIMATIC S7-1200 exposure by country (Censys, 2026-07-30). Network / ASN Distribution Siemens SIMATIC S7-1200 exposure by country (Censys, 2026-07-30).

§3 AI · 80%

Schneider Electric (Vendor-Wide) 2,072 internet-exposed hosts fingerprint as Schneider Electric hardware (snapshot 2026-07-30). This query has no PLC-model or protocol filter. This total should not be read as Schneider Electric PLC exposure specifically. Turkey and Australia account for 55.5% of the total combined. Geographic Distribution Schneider Electric (Vendor-Wide) exposure by country (Censys, 2026-07-30).

§4 Human · 14%

Network/ASN Distribution Schneider Electric (Vendor-Wide) exposure by network/ASN (Censys, 2026-07-30). Censys Queries Rockwell/Allen-Bradley: (host.services.protocol=EIP) and host.services.eip.identity.vendor_name="Rockwell Automation/Allen-Bradley" Siemens SIMATIC S7-1200: host.hardware.vendor: "siemens" and host.hardware.product: "simatic_s7-1200" Schneider Electric: host.hardware.vendor = "schneider-electric"