CISA Warns Water Utilities: Over 100 Internet‑Exposed PLCs Compromised in July 2026
What Happened — In July 2026, more than 100 water‑ and wastewater‑sector programmable logic controllers (PLCs) that were directly reachable from the internet were accessed by threat actors. Attackers altered IP addresses, passwords, and even disabled shutdown processes and alarms, creating unsafe operating conditions. CISA responded with a detailed “exposure reduction” guide urging utilities to locate and secure any internet‑facing PLCs before they are abused.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a control‑gap that SOC 2’s Logical Access (CC6.1) and System Operations (CC7.1) criteria are designed to prevent and evidence.
- Continuous discovery and evidence collection of exposed assets turn a reactive “find‑and‑fix” effort into a defensible audit trail.
- Verisq’s Control Mapping capability can ingest external scans (Shodan, Censys, CISA’s scanner) and automatically map findings to SOC 2 controls, providing real‑time compliance evidence.
Who Is Affected – Water and wastewater utilities, municipal infrastructure operators, and any organization that relies on PLCs for critical process control.
Recommended Actions
- Run external asset‑discovery scans (Shodan, Censys, or CISA’s Cyber Hygiene service) against all IP ranges.
- Isolate any PLCs that do not require internet access; route necessary remote sessions through a centrally managed, MFA‑protected gateway.
- Document the remediation steps and integrate scan results into your continuous‑compliance platform to satisfy SOC 2 evidence requirements.
Source: Security Affairs
Technical Notes – Attack vector: misconfiguration – PLCs exposed via cellular modems with no firewall or gateway. Exploited protocols included Modbus, EtherNet/IP, DNP3, BACnet, and OPC UA. No specific CVE was cited; the risk stems from insecure exposure rather than a software flaw. Source: same as above