Ongoing Malicious Activity Impacting Wisconsin Public Drinking Water And Wastewater Systems
On July 27, 2026, staff at the Wisconsin Statewide Intelligence Center (WSIC) expressed concern that Programmable Logic Controllers (PLCs) located at systems within Wisconsin may be susceptible to connections from malicious cyber actors. This leads us to believe that the cyber threat is ongoing in Wisconsin and requires immediate action to prevent potentially serious impacts to our systems.
Recommended Actions:
The Wisconsin Department of Natural Resources (DNR) strongly recommends that all systems do the following:
- Closely review the CISA advisory to determine if any systems use PLCs from the listed manufacturers (Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens and other branded/manufactured PLCs).
- Remove PLCs from direct internet exposure via secure gateway and firewall.
- Ensure that ports 44818, 2222, 102 and 502 are inaccessible from remote connections.
- Ensure all operational PLCs are supported by the vendor and have received current security updates.
-
Report any suspected or confirmed incidents to WSIC’s Cyber Incident Reporting Form. Please make sure to list any potentially malicious IP addresses that had communication with your PLCs.
Please contact WSIC at dojdciwsiccfcu@doj.state.wi.us or (608) 242-5393 for any questions about the advisory or reporting.
Background Information:
On July 22, 2026, the US Cybersecurity & Infrastructure Security Agency (CISA) updated a cybersecurity advisory related to an ongoing attempt by cyber threat actors (CTAs) to target remotely accessible Programmable Logic Controllers (PLCs). The CTA has been confirmed to access PLCs through open ports 44818, 2222, 102 and 502. The CTA may attempt to disable communication between MicroLogix Controllers after gaining remote access with goals of taking control of the system, impacting normal operations and potentially leading to total system shutdown.
Between July 26-27, 2026, Minnesota reported that the CTAs were able to gain access to the PLCs and drop system pressures, which on several incidents triggered alarms and prompted a response from law enforcement. If a cyber-attack successfully drops pressures far enough, it could result in a full system shutdown. Furthermore, for drinking water systems, it could create a suction effect that potentially allows unsafe contaminants to enter the system.
The updated advisory includes a list of known Internet Protocol (IP) addresses that have been used to communicate with PLCs. The updated CISA advisory can be found on CISA’s website.
Thank you for your diligence in this situation. For additional Cybersecurity resources, visit the DNR’s Cybersecurity Webpage.
|