The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a significant increase in cyberattacks targeting water supply and wastewater systems, urging operators to strengthen protections for critical infrastructure.


In a statement, CISA said it is observing a growing number of cyber threat actors targeting programmable logic controllers (PLCs), which are used to automate and control water and wastewater operations, Caliber.Az reports. 


"CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers [PLCs] in the Water and Wastewater Systems [WWS] Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology [OT] from the internet as soon as possible," the agency said.


According to CISA, attackers have changed passwords to lock operators out of control systems and altered IP addresses to disconnect PLCs. The agency said the attacks have resulted in boil water notices and forced some utilities to rely on manual operations.


CISA warned that water utilities of all sizes are being targeted, including organisations with established cybersecurity programmes. The agency advised operators to review all external connections, including cellular modems installed by vendors or system integrators that may not be included in routine security assessments.


The agency added that operational technology exposed to the internet faces an elevated risk of unauthorised access, configuration changes, service disruptions and, in severe cases, physical damage to infrastructure.


By Sabina Mammadli