What happened

CISA says it is observing a significant increase in threat actors targeting programmable logic controllers in the water and wastewater sector. On exposed systems, attackers have changed passwords to lock out operators and altered IP addresses to disconnect controllers. The resulting disruption has included boil-water notices and sustained manual operation.

Rockwell Automation has separately confirmed activity against internet-exposed MicroLogix 1400 controllers. Its notice covers Series A, B and C devices and describes remote configuration tampering that can remove the operator's view. This is not presented as a newly disclosed software flaw: Rockwell assigns no CVE and describes the notice as operational recovery guidance.

[1][2]

Why an incomplete inventory is part of the risk

CISA warns that the targeting reaches water organisations of every size, including those with mature security processes. One reason is that cellular modems installed by operators, vendors or system integrators may sit outside the normal asset inventory and routine external scanning.

That detail matters well beyond water. A controller can be physically inside a plant and still be publicly reachable through a modem, port-forwarding rule or forgotten support connection. If responsibility is split between operations, IT and a supplier, each team can reasonably believe somebody else is managing the exposure.

[1]

What defenders should do now

Owners should identify every externally reachable PLC and remove direct internet access. CISA says legitimate remote access should pass through a VPN or gateway rather than terminating on the controller itself. It also recommends password protection, replacing default passwords and allowing remote connections only from known engineering laptops or other essential OT assets.

Recovery readiness deserves equal attention. After exposure is removed, CISA advises keeping a known-clean controller image in case an attacker has changed the password. Rockwell says MicroLogix 1400 recovery can erase the program, data and network configuration, so a current offline project backup is required before its procedure is attempted. Follow the vendor's current instructions for the exact series and involve the responsible control engineer; this is not a job for improvised remote testing.

  • Ask OT owners, IT teams and integrators separately for their lists of remote connections, modems and forwarding rules.
  • Validate exposure from an authorised external viewpoint, including connections that bypass the corporate perimeter.
  • Remove public addressing and direct port forwarding; place approved remote access behind a controlled gateway.
  • Replace defaults, restrict source addresses and review whether web management is genuinely required.
  • Prove that offline project files are current, clean and usable before an incident makes recovery urgent.
[1][2]

The Beekeeper view

This story is not really about a novel exploit. It is about ordinary internet exposure reaching equipment whose failure changes a physical process. That makes discovery and ownership more important than dramatic vulnerability labels.

For UK organisations with operational technology, the useful question is not merely whether the main firewall looks tidy. It is whether every supplier-installed route, mobile connection and ageing controller is known, justified and recoverable. The forgotten modem is still part of the perimeter; it simply has fewer people watching it.

Direct internet access turns an operational controller into a public-facing system, often without the inventory, monitoring or recovery discipline that public exposure demands.

Primary sources

  1. CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs — US Cybersecurity and Infrastructure Security Agency, 30 July 2026
  2. IMPORTANT NOTICE: Restoring Access to a MicroLogix 1400 Controller When the Password Is Unknown — Rockwell Automation, 30 July 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.