in

Expert Morgan Wright: Exposed PLCs Leaving Town Water Systems at Risk

America’s water taps and wastewater pumps are quietly running on tech older than most smartphones — and according to a joint federal advisory, foreign hackers are poking at those exposed controllers like kids at a candy store. Cybersecurity expert Morgan Wright told Fox viewers what many in the field already suspect: our defenses around programmable logic controllers — PLCs — aren’t nearly where they need to be.

What agencies are saying — and what they found

Federal cyber and national security agencies rolled out advisory AA26-097A after spotting Iranian-affiliated actors exploiting internet-exposed PLCs across multiple critical-infrastructure sectors. The advisory — expanded to include Rockwell, Schneider Electric and Siemens gear — lays out how attackers used vendor engineering tools, exposed modems, and weak or shared credentials to read and alter PLC project files.

The practical fallout: more than 30 Minnesota community water and wastewater systems reported disruptions, forcing operators to isolate equipment, run systems manually, or temporarily take plants offline while investigators dug in. The FBI and EPA even issued a public-service notice urging utilities to treat this as ongoing, not hypothetical, risk.

Why PLCs are such a hard problem

PLCs were built to keep things moving — deterministic control, uptime first — not to fend off nation-state hackers. Many controllers sit in legacy installations with patchy inventories, default passwords, and third-party remote links that never should have been internet-accessible.

That’s a toxic mix: vendor-specific engineering files give attackers a roadmap to change ladder logic, flip I/O states, or lock operators out by changing IPs and passwords. In short, it’s less a mystery exploit and more a series of unlocked doors in front of a crowd of bad actors.

Real consequences for everyday Americans

This isn’t tech theater. When monitoring and control vanish, operators lose the data that tells them if pressure is dropping or a pump is failing — and that can mean raw public-health risk for neighborhoods that depend on those systems. Utilities had to switch to manual operations; that means overtime, slow responses, and higher costs that towns will ultimately foot the bill for.

Imagine a small town where the water department has one IT person and a handful of aging controllers: that town’s facing the choice between expensive retrofits or rolling the dice on the next attack. Which do you think will happen first if nobody forces the issue?

Fixes are known — the problem is doing them

Agencies are blunt about mitigations: remove PLCs from direct internet exposure, inventory every OT asset (yes, including cellular modems), restrict engineering tools to secure jump hosts, enforce unique credentials and multi-factor controls where possible, and preserve manual fallback modes. Those steps matter and they work — but they cost money and require skilled people to implement and maintain.

The ugly truth is this: many small utilities are underfunded and understaffed, vendors have been slow to ship secure-by-design controllers, and federal guidance without funding is just another memo. If you care about clean water and reliable power, “call your congressman” isn’t a slogan — it’s a reality check.

So here’s the question that won’t die: are we going to treat cyber-secure infrastructure like national defense — with prioritized funding, accountability, and tough standards — or keep hoping the next advisory and another press conference will be enough?

Written by admin

Leave a Reply

Your email address will not be published. Required fields are marked *

ICE arrests nearly 50,000 in July under President Donald Trump

Rakoff OKs $72.5M Bank of America Epstein Payout — Justice Sold?

Rakoff OKs $72.5M Bank of America Epstein Payout — Justice Sold?