07/31/2026
Malicious actors have been attacking internet‑facing Programmable Logic Controllers (PLCs) used in the Water and Wastewater Sector.
Recommended protections:
Remove PLCs from direct internet exposure; use secure gateways and firewalls
Secure cellular modems with strong authentication, logging, and isolated architectures (private APN, SD‑WAN, ZTNA, VPN)
Use strong, unique passwords
Restrict network access with ACLs and firewall rules
Lock PLCs in “run” mode to prevent unauthorized logic changes
Maintain the ability to operate systems manually for continuity
Regularly review PLC project files and logs for unauthorized changes
Reimage compromised devices if lateral movement is suspected
Track and replace end‑of‑life hardware, applying compensating controls when replacement is delayed
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devi...