CISA Warns of Active Exploitation Targeting Water Sector Programmable Logic Controllers
CISA has reported that hackers are targeting internet-connected water infrastructure equipment known as PLCs. These attacks can lock out operators and disrupt water services. Organizations are urged to remove these devices from the public internet immediately.

English Brief
CISA has reported that hackers are targeting internet-connected water infrastructure equipment known as PLCs. These attacks can lock out operators and disrupt water services. Organizations are urged to remove these devices from the public internet immediately.
الموجز العربي
وكالة الأمن السيبراني (CISA) تحذر من هجمات نشطة تستهدف وحدات التحكم المنطقية القابلة للبرمجة في قطاع المياه
حذرت وكالة الأمن السيبراني الأمريكية من قيام قراصنة باستهداف أجهزة التحكم الصناعية (PLCs) المتصلة بالإنترنت في محطات المياه، مما قد يؤدي إلى تعطيل الخدمات. وتدعو الوكالة إلى فصل هذه الأجهزة عن الإنترنت فوراً لحمايتها.
- 1Disconnect OT assets from the public internet immediately.
- 2Audit and identify all cellular modems and remote gateways connected to the network.
- 3Establish secure remote access using VPNs or dedicated gateway devices only.
English Advisory
// Intelligence Summary
CISA has observed a significant rise in malicious activity targeting Programmable Logic Controllers (PLCs) within the Water and Wastewater Systems (WWS) sector. Attackers are exploiting exposed OT assets to modify configurations, change access passwords, and disrupt operational availability.
التقرير العربي
// ملخص استخباراتي
رصدت وكالة الأمن السيبراني (CISA) زيادة ملحوظة في الأنشطة الضارة التي تستهدف وحدات التحكم المنطقية القابلة للبرمجة (PLCs) داخل قطاع المياه والصرف الصحي. يستغل المهاجمون الأجهزة الصناعية المكشوفة لتعديل الإعدادات، وتغيير كلمات مرور الوصول، وتعطيل استمرارية العمليات التشغيلية.
// Technical Context
The exploitation involves identifying internet-facing OT hardware, often via cellular modems or undocumented remote access points. Once access is gained, actors perform unauthorized administrative changes, including resetting passwords to lock legitimate operators out and modifying network configurations to effectively take the equipment offline.
// السياق الفني
تتضمن عملية الاستغلال تحديد أجهزة تكنولوجيا التشغيل (OT) المتصلة بالإنترنت، وغالباً ما يتم ذلك عبر أجهزة مودم خلوية أو نقاط وصول عن بُعد غير موثقة. بمجرد الوصول، يقوم المهاجمون بإجراء تغييرات إدارية غير مصرح بها، بما في ذلك إعادة تعيين كلمات المرور لحجب المشغلين الشرعيين، وتعديل إعدادات الشبكة لإخراج المعدات عن الخدمة.
// Exposure Notes
Beyond directly documented assets, organizations are warned to audit undocumented cellular modems and remote gateways. Even mature security environments may be vulnerable if shadow IT assets provide a bypass to the internet.
// ملاحظات التعرض
بالإضافة إلى الأصول الموثقة، يُحذر المؤسسات من ضرورة فحص أجهزة المودم الخلوية والبوابات البعيدة غير الموثقة. حتى البيئات الأمنية المتطورة قد تكون معرضة للخطر إذا كانت أصول تكنولوجيا المعلومات غير الخاضعة للرقابة توفر وصولاً مباشراً إلى الإنترنت.
// Defensive Priority
Immediate priority is to remove all OT devices from public-facing internet exposure. Implement secure remote access via VPNs, enforce strong password policies, and ensure offline backups of PLC images are maintained to facilitate recovery from lockout scenarios.
// أولوية الدفاع
الأولوية القصوى هي إزالة جميع أجهزة تكنولوجيا التشغيل (OT) من الشبكة العامة. يجب تنفيذ الوصول الآمن عن بُعد عبر شبكات VPN، وفرض سياسات صارمة لكلمات المرور، والتأكد من الاحتفاظ بنسخ احتياطية غير متصلة بالإنترنت لصور وحدات التحكم لضمان سرعة الاستعادة في حال حدوث هجوم.
Mitigation Checklist
- 1Disconnect OT assets from the public internet immediately.
- 2Audit and identify all cellular modems and remote gateways connected to the network.
- 3Establish secure remote access using VPNs or dedicated gateway devices only.
- 4Change all default passwords on PLCs and implement robust authentication.
- 5Create and store off-site backups of PLC configurations.
- 6Apply IP allowlisting to restrict remote access to trusted engineering workstations.
قائمة إجراءات التخفيف
- 1افصل أصول تكنولوجيا التشغيل (OT) عن الإنترنت العام فوراً.
- 2قم بإجراء تدقيق لتحديد جميع أجهزة المودم الخلوية والبوابات البعيدة المتصلة بالشبكة.
- 3قم بتنفيذ وصول آمن عن بُعد باستخدام شبكات VPN أو بوابات مخصصة فقط.
- 4قم بتغيير جميع كلمات المرور الافتراضية في أجهزة التحكم (PLCs) وطبق مصادقة قوية.
- 5قم بإنشاء وتخزين نسخ احتياطية لإعدادات أجهزة التحكم خارج الموقع.
- 6طبق نظام القائمة البيضاء (IP Whitelisting) لقصر الوصول عن بُعد على محطات عمل هندسية موثوقة فقط.
- Source: CISA Alerts
# 1. Disconnect OT assets from the public internet immediately.
# 2. Audit and identify all cellular modems and remote gateways connected to the network.
# 3. Establish secure remote access using VPNs or dedicated gateway devices only.
# 4. Change all default passwords on PLCs and implement robust authentication.
# 5. Create and store off-site backups of PLC configurations.
# 6. Apply IP allowlisting to restrict remote access to trusted engineering workstations.