CISA Warns: Water Tower PLCs Exposed and Targeted
Censys analyzes CISA's alert on threat actors targeting water sector PLCs, revealing widespread exposure of these critical devices and urging immediate action.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding threat actors actively targeting programmable logic controllers (PLCs) in the water and wastewater sector. Censys, a leader in attack surface management, has analyzed this alert and provided critical insights into the scope of the problem.
The Threat Landscape
PLCs are essential components in water treatment facilities, controlling everything from pumps to chemical dosing. The alert highlights that these devices are being targeted by adversaries, potentially to disrupt water services or cause physical damage. Censys's analysis reveals that a significant number of these PLCs are directly exposed to the internet, making them easy targets for malicious actors.
Censys Findings
Using its extensive internet scanning capabilities, Censys identified that many water sector PLCs are accessible via default credentials or have known vulnerabilities that have not been patched. The company's research shows that the exposure is not limited to small utilities; even larger, well-funded operations have gaps in their security posture.
The alert emphasizes the need for immediate action, including changing default passwords, applying patches, and segmenting networks to limit exposure. Censys's data supports this, showing that many exposed devices are running outdated firmware with known exploits.
Implications for Critical Infrastructure
This targeting of water infrastructure is a stark reminder of the vulnerabilities inherent in industrial control systems (ICS). The potential impact of a successful attack on water treatment facilities is severe, affecting public health and safety. Censys's analysis underscores the importance of continuous monitoring and proactive security measures for critical infrastructure.
Recommendations
Censys recommends that water utilities immediately:
- Inventory all internet-facing devices and assess their exposure.
- Change all default credentials and enforce strong authentication.
- Apply security patches and update firmware promptly.
- Segment networks to isolate critical control systems from corporate IT.
- Implement continuous monitoring to detect and respond to threats in real-time.
The CISA alert and Censys's analysis serve as a wake-up call for the water sector. The tools and knowledge to secure these systems exist, but they must be applied with urgency to protect essential services.
The tools and knowledge to secure these systems exist, but they must be applied with urgency to protect essential services.
Source: Censys