Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-facing industrial equipment found roughly 4,400 exposed programmable logic controllers used in U.S. water systems, including 22 in cities that have already experienced water system attacks. This comes despite repeated federal warnings to operators to take such equipment offline.
Why this matters: Water systems are critical infrastructure that most people never think about until something goes wrong. Exposed PLCs are not a theoretical risk — 22 of these devices sit in cities that have already been targeted. The controllers manage physical processes: pressure, treatment, flow. An attacker who reaches one is not stealing data, they are touching the water itself. Federal agencies warned operators to fix this. Thousands did not. That is an accountability problem, and it belongs to the utilities and the regulators who are supposed to hold them to a standard.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.