LR pixel

What is the Attack?

Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.

The activity does not involve a specific CVE. Instead, attackers are taking advantage of Internet-exposed PLCs, weak or default credentials, and inadequate access controls to obtain unauthorized access to OT environments.

Once access to an exposed PLC is obtained, attackers may manipulate configurations, operating parameters, or connected industrial processes. Such access can interfere with normal operations and potentially affect the availability and reliability of water and wastewater services.

What is the recommended Mitigation?

• Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs.

• Change default credentials and enforce strong, unique passwords for PLCs and associated OT systems.

• Implement access control lists (ACLs) to restrict communications to authorized devices and expected sources.

• Restrict remote access to OT environments and require secure authentication for authorized users.

• Monitor PLC configurations and network activity for unauthorized changes, including unexpected modifications to IP addresses, passwords, or operating parameters.

• Segment OT and IT networks to limit lateral movement following a compromise.

• Review exposed PLCs and other Internet-facing OT assets and remove unnecessary public access.

• Maintain offline backups of PLC configurations to support recovery if unauthorized changes or operational disruptions occur.

The FBI specifically recommends removing PLCs from direct Internet exposure, using strong unique passwords, and implementing ACLs to restrict communications

What FortiGuard Coverage is available?

• FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets.

OT App Detection | FortiGuard Labs


• FortiGuard IPS Service: Detects and blocks network-based attacks targeting exposed OT/ICS services and PLC infrastructure.

• FortiGuard Web Filtering: Blocks access to known malicious infrastructure associated with threat activity.

• FortiGuard Antivirus & Behavior Detection: Detects malicious payloads that may be delivered following network compromise.

• FortiGuard IOC Service: Identifies known indicators associated with malicious infrastructure and post-compromise activity.

• FortiGuard Incident Response: Supports investigation, containment, and recovery following an OT/ICS compromise.