CISA Alert: Water Sector PLC Targeting

America left its water controls online — and the comments are absolutely feral

TLDR: CISA warned that hackers are targeting internet-exposed devices used by water utilities, sometimes knocking systems offline and forcing manual operations. Commenters weren’t shocked — they were furious, calling it years of negligence, political blame-shifting, and a completely avoidable mess.

The official warning was scary enough: the U.S. cyber defense agency says hackers are increasingly going after internet-connected machines that help run water and wastewater systems. In plain English, that means devices tied to pumps, treatment systems, and other essential water operations were left reachable from the public internet. In some cases, attackers reportedly changed passwords, locked out staff, and even altered device addresses so systems dropped offline — the kind of chaos that can trigger boil-water notices and force crews into exhausting manual work.

But the real fireworks were in the community reaction, where the mood was less “surprised” and more “how is this still happening in 2026?” One commenter called it “gross incompetence at all levels,” arguing this has been warned about for 15 years and should no longer be treated like a shocking new problem. Another summed up the industry’s security with a brutal “single statement” punchline followed by a deadpan “Lol,” which is about as close as engineers get to screaming into the void.

And yes, the thread got spicy fast. There was finger-pointing over politics and foreign blame, while others insisted the bigger scandal is old-fashioned neglect at home. One especially dark comment veered into “heads should roll” territory, while another tried to cool things down by linking a Water ISAC perspective, saying the problem is systemic, boring, and years in the making — which somehow made it even worse. The internet’s verdict? This wasn’t a surprise attack story. It was a complacency scandal with water attached.

Key Points

  • CISA warned on July 30, 2026 that threat actors are increasingly targeting internet-exposed PLCs in the water and wastewater sector, including changing passwords and IP addresses to disrupt operations.
  • The article highlights cellular modems as a common blind spot that may leave PLCs or OT reachable from the internet outside normal attack-surface scans.
  • A Censys snapshot dated 2026-07-30 found 4,148 internet-exposed Rockwell Automation/Allen-Bradley EtherNet/IP hosts, with 71.0% in the United States and 11.5% in Canada.
  • The same snapshot found 4,117 internet-exposed Siemens SIMATIC S7-1200 hosts, with Greece, Spain, Italy, and Austria accounting for 86.0% of the total.
  • The report found 2,072 Schneider Electric hosts internet-exposed, but stated this was a vendor-wide fingerprint query and should not be interpreted as Schneider PLC exposure specifically.

Hottest takes

"This is gross incompetence at all levels — IT malpractice if you will." — pudgywalsh
"Describe the network security of the industrial automation industry and their customers in a single statement. Lol." — BlackRabbit1
"Some people allegedly say that the US should treat heads of companies like they do in China... Allegedly." — ilikeitdark13
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.