Threat actors are actively targeting internet-exposed industrial control systems and PLCs across US facilities. Here is what infrastructure leaders need to know, and how to harden your operational environment today.
Update — August 2026
CISA has issued a joint Cybersecurity Advisory confirming an active threat to Siemens S7 series PLCs. Attackers are leveraging publicly documented weaknesses in the legacy S7comm protocol to compromise internet-exposed controllers, overwrite control logic, and disrupt industrial processes. All operators running Siemens S7-300/400/1200/1500 equipment should treat this as an active exploitation event and apply the hardening steps below immediately.
Download the CISA Guidance (PDF)Direct Internet-Facing PLCs & HMIs
Valve overrides, pressure loss & emergency boil orders
Mandatory IT/OT DMZ network segmentation
Watch Episode 2 by 5D Cyber: How Hackers Hijacked US Water Plants
For decades, industrial control systems (ICS) were assumed safe behind the "air gap," the physical separation between operational technology (OT) and corporate networks. That air gap has effectively dissolved. Modern water, wastewater, and manufacturing facilities now connect PLCs, HMIs, and SCADA systems to business networks for remote monitoring, efficiency, and vendor support. The result is severe exposure across the sector, and attackers have shifted from stealing data to causing real-world, physical disruption.
A joint CISA advisory published August 18, 2026 confirms malicious actors are actively exploiting internet-exposed Siemens S7 series programmable logic controllers. The legacy S7comm (S7 Communication) protocol, used widely across water, energy, and manufacturing environments, lacks native authentication and encryption — allowing attackers who can reach a controller to read and overwrite its logic, issue unauthorized set-point commands, and disrupt physical processes.
The advisory is a sharp reminder that the threat is not theoretical. It moves from opportunistic scanning to confirmed, targeted exploitation of a specific, widely deployed vendor platform — and underscores why every utility and industrial operator should audit for exposed S7 ports today.
Read the Full CISA Advisory (PDF)Devices reachable via open ports on public IP addresses, directly discoverable by internet-wide scanners.
Factory passwords left unchanged on field controllers, granting immediate access to anyone who can reach the device.
Direct routing paths between corporate IT and industrial OT, allowing an IT compromise to pivot into control systems.
Management portals lacking phishing-resistant Multi-Factor Authentication, exposed to credential theft and session hijacking.
A prioritized, practical sequence to close the exposure gap across your operational environment.
Disallow direct web access to control devices; audit exposed industrial ports (Modbus, EtherNet/IP, BACnet) using continuous attack surface scanning.
Mandate Multi-Factor Authentication on all remote management gateways and change every factory-default credential across field devices.
Deploy industrial firewalls to establish a strict DMZ between enterprise business networks and control subnets.
Keep offline, air-gapped backups of all PLC logic and test physical manual valve controls on a regular schedule.
Deploy behavioral network sensors to flag unauthorized firmware changes or abnormal set-point commands in real time.
Use this readiness matrix to benchmark your facility against the controls that matter most.
5D Cyber operates a specialized infrastructure security practice built for water, wastewater, and industrial organizations. We translate operational risk into measurable, audit-ready defense:
Rapid discovery of exposed controllers and shadow IT across your public footprint.
Custom DMZ and secure jump-box design to isolate control systems from the enterprise network.
Real-time perimeter and gateway threat monitoring, with rapid containment of active intrusions.
Custom tabletop exercises and operational recovery playbooks to restore control systems under pressure.
Don't wait for an active lockout to discover your perimeter blind spots. Schedule a confidential infrastructure review with the 5D Cyber engineering team.