OptoBlog

Water utilities got hacked—get your PLCs off the public internet

Posted by Dan White on Aug 19, 2026, 7:25:35 AM

Last month's water-utility attacks hit exposed PLCs. Here's how to tell if yours is one, and how to take it offline for good.

Somewhere in your plant or remote infrastructure, a controller might be reachable from the public internet right now.

Someone probably set up remote access years ago so they wouldn't have to drive an hour out to a remote site every time it needed a look.

Nobody circled back. For a long time, that felt harmless. Last month, it stopped feeling that way.

What happened in Minnesota

Over two days in late July, attackers disrupted water and wastewater utilities in at least seven states. More than 30 communities in Minnesota were hit, and several went public, including Braham, Plymouth, and South St. Paul. The attackers didn’t need anything exotic. They found internet-facing PLCs, changed their IP addresses and passwords, locked operators out, and in some places caused real pressure loss and flooding.

CyberBlog_MinnesotaCyberAttack

Allen-Bradley, Siemens, and Schneider controllers were all affected. Within days, CISA issued an advisory telling water utilities to get their PLCs off the public internet, segment their networks, and change default passwords. 

How to tell if you're exposed

You don’t have to guess. A few quick checks:

  • Ask the plain question: can anyone reach a controller from outside your network without a VPN? If remote staff or an integrator log straight into a PLC over the internet, it's exposed.

  • Search Shodan for your public IP address. Shodan indexes internet-facing devices, and it's the same place attackers start. If your controller shows up there, everyone can see it too.

  • Check your firewall for open inbound OT ports, like 502 for Modbus, 44818 and 2222 for EtherNet/IP, or 102 for Siemens S7. A port like that open to the internet is an unlocked door.


How groov keeps your controllers off the public internet

The fix isn’t to unplug and go blind. You still need remote data, and sometimes remote access. The point is to get both without leaving a controller exposed. That’s how groov EPIC and groov RIO are built.

But you don’t have to replace the PLCs you already run. Put a groov EPIC or groov RIO in front of your existing Allen-Bradley, Siemens, or Schneider controllers, read their data over OPC UA, Ethernet/IP, ProfiNET, or Modbus, and publish it outbound. The same kind of controllers that were exposed last month come off the public internet and keep doing their job.

GCDCWWS_Aerial-Plant-Overview_1200

The Genesee County Drain Commissioner Division of Water & Waste Services (GCDC-WWS) operates 180 remote sites across 600 square miles in the state of Michigan.

Two networks, one box. groov EPIC has two independent network interfaces, so it sits between your control network and your business network or the internet. Your controllers and I/O live on a segmented network behind it, not out in the open.

CyberBlog_EPICnetworkdiagram

Data goes out, nothing comes in. Instead of opening a port and waiting for connections, groov publishes data outbound over MQTT Sparkplug to a broker, and the systems that need it subscribe. There’s no inbound port for an attacker to find, because the controller never accepts unsolicited connections.

CyberBlog_MQTTarch

Secure by default. groov devices ship with a built-in firewall, encrypted connections, and real user accounts, not a default password waiting to be guessed.

CyberBlog_FirewallgroovManage

Use groov EPIC's built-in firewall to make sure no open ports are exposed on public internet.


You can fix this

The utilities in the headlines weren’t anomalies. They were typical, busy, and their controllers were exposed long before anyone thought to check. You can check yours today, and you can fix it without starting over.

If you want a hand mapping it out, talk to an Opto 22 engineer. We work with water and wastewater systems every day. 

 

 

Topics: PLCs, groov EPIC, cybersecurity, groov RIO

Written by Dan White

Dan has worked at Opto 22 for more than a decade. His Tufts Engineering background, MBA in International Business, and prior industrial controls experience give him a unique edge in automation. Dan enjoys staying active through biking, basketball, skiing – and keeping up with his three young kids!
Find me on:

    Subscribe to Email Updates

    Recent Posts

    Posts by Topic

    see all