posted in Technology

CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet

CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.

Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.

I assume it is this CISA: https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency

www.privacyguides.org/news/2026/07/31/cisa-releases-guidance-urging-water-treatment-facilities-to-disconnect-equipment-from-the-internet/
Privacy GuidesCISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the InternetCISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.

Replying to @⁨new_otters_raft@piefed.ca⁩

So are we just kind of admitting that there exists no way to expose any networked device to the internet securely? Because if it’s not possible for PLCs I don’t see why it would be possible for any device. If water utilities have to take these offline, then how does that advice not apply for every internet-capable device in every commercial and industrial facility worldwide?

Replying to @⁨khepri@lemmy.world⁩

So are we just kind of admitting that there exists no way to expose any networked device to the internet securely?

It’s done all the time. It’s not a product you can buy, though, it’s a process. There’s probably a good “go by” for how to start the process for citywide infrastructure, but it’s just one more document for people to ignore.

en