Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesOn November 28, 2023, CISA warned that attackers were actively exploiting programmable logic controllers (PLCs) used in water and wastewater operations, including a Unitronics Vision Series PLC with a human-machine interface (HMI) at a U.S. water facility. The authority took the affected system offline and switched to manual operations. CISA reported no known risk to that municipality’s drinking water or water supply.
What happened in the Unitronics water-utility incident?
CISA’s November 28, 2023 alert described active exploitation of PLCs in the Water and Wastewater Systems sector. At one U.S. facility, the identified device was a Unitronics Vision Series PLC paired with an HMI. The water authority isolated the system and continued operations manually.
The alert did not identify the municipality in its public text, report customer totals, or say that attackers contaminated water. Its documented impact was an operational-technology security incident: unauthorized access to equipment that helps control and monitor physical processes.
Why an exposed PLC is an operational risk
PLCs are industrial computers that execute control logic and communicate with sensors, pumps, valves, chemical systems and alarms. CISA lists water-sector uses such as:
#1 Best Overall
- Starting and stopping pumps that fill tanks and reservoirs.
- Pacing chemical flow.
- Collecting compliance data.
- Annunciating critical alarms.
An attacker does not need to contaminate water for a PLC compromise to matter. Unauthorized changes can alter process timing, suppress alarms, interrupt pumping or force operators into slower manual procedures. The consequences depend on the facility’s engineering safeguards, local operating procedures and how quickly the affected controller is isolated.
How the attackers appear to have reached the controller
CISA said the Unitronics device was exposed to the internet and likely had weak password security. The alert described network probing for the default TCP port 20256, followed by scripts specific to Unitronics PCOM/TCP communications to query and validate systems.
Changing the port can reduce automated scanning of the default service, and CISA advised using PCOM/TCP filters where available. Those measures are supplementary controls, not substitutes for removing direct exposure, enforcing strong credentials and controlling remote access.
Was the water supply affected?
For the November 2023 facility, CISA’s statement was limited to that municipality and said there was no known risk to its drinking water or supply. It does not establish that every PLC intrusion is harmless; it describes the status known during that specific response.
Rank #2
- -- PLC Type: Fully compatible with FX1S, 10 Transistor Input (NPN Type), 7 Relay Output. Have additional 4 Transistor Output: 2 for high speed pulse 100KHz & 2 for direction, can drive 2 servos or 2 steppers with pulse, built-in 2AD(0-10V) and 2DA(0-10V), also 2 NTC10K B3435 probe. Just read the address of AD DA NTC's will ok, 2 high speed input 100KHz X0 X1 to control encoder
- -- PLC software: Use GX Workers 2 or Developer (pls download from GX Workers 2 website, we only have Chinese version), support Command + T Ladder Diagram + SFC for programming
- -- HMI Software: YKBuilder V5.3 and Choose FE serial 380 model in HMI software. (Pls contact us, we will share it and the video instruction and guidelines), very easy to use, just create the buttun and set the address
- -- Use the same Cable for download program from PC to PLC/HMI: Use the: mini port – USB cable, pls install HMI & PLC’s USB driver first, which we will share.
Separate CISA reporting in 2026 concerns later activity, not a retroactive change to the 2023 incident. A July 30, 2026 water-sector alert said observed PLC targeting had resulted in boil-water notices and sustained manual operations in other activity, without giving a customer count in the published text.
The security layers CISA recommends
1. Remove direct internet exposure
CISA’s clearest instruction in the 2023 alert was: “Disconnect the PLC from the open internet.” A PLC should not accept unsolicited connections from the public internet. Review router rules, NAT mappings, cloud management paths and any undocumented modem connection that could bypass the normal firewall.
2. Put remote access behind a controlled gateway
When engineers or vendors genuinely need remote access, place a firewall, VPN or secure gateway between the remote user and the PLC. CISA’s 2026 wording is explicit: “Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.”
A gateway can provide controls that the PLC may not support itself, including multifactor authentication (MFA), session logging, approval workflows, time-limited access and source-IP restrictions. Do not expose the PLC merely because a vendor needs occasional maintenance access.
Rank #3
- -- PLC Type: Fully compatible with FX1S, 7 Input 5 Relay Output (24V pulse single). Have additional 4 Transistor Output: 2 for high speed pulse 100KHz & 2 for direction, can drive 2 servos or 2 steppers with pulse
- -- PLC software: Use GX Workers 2 or Developer (pls download from GX Workers 2 website, we only have Chinese version), support Command + T Ladder Diagram + SFC for programming
- -- HMI Software: YKBuilder V5.3/7.0 (Pls contact us, we will share it and the video instruction and guidelines). For HMI model: pls choose FE Serial, 280D
- -- Use the same Cable for download program from PC to PLC/HMI: Use the: mini port – USB cable, pls install HMI & PLC’s USB driver first, which we will share.
3. Replace default and weak passwords
Unitronics’ default password “1111” must not remain in use. Set a strong, unique password, store it in an approved credential-management process and restrict knowledge of it to authorized personnel. CISA’s joint December 2023 advisory also called for strong unique passwords on publicly reachable Unitronics Vision devices.
4. Use MFA and network allowlisting where applicable
Require MFA for remote access to the operational-technology network, even when the PLC itself cannot perform MFA. On the firewall or gateway, allow only known management networks, addresses and protocols. CISA’s July 2026 guidance specifically recommends allowlisting known IP addresses.
5. Maintain clean backups and practice recovery
Keep offline or otherwise protected copies of PLC logic, HMI projects, configurations, credentials and network documentation. Test that a backup can be restored, and practice factory reset and redeployment procedures.
This matters because an intruder may change a password or alter a project file, leaving operators unable to log in or unsure whether the running logic is trustworthy. CISA’s 2026 alert recommends a known-clean PLC image backup for recovery from a modified-password lockout.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
6. Update PLC and HMI software
Apply the latest software and security updates supplied by the manufacturer for the specific PLC and HMI models. The December 14, 2023 joint advisory told operators to upgrade Unitronics devices to VisiLogic 9.9.00. That was historical advice for that advisory and should not be treated as the newest available version in 2026; verify the current release with Unitronics before scheduling maintenance.
7. Check vendors, integrators and cellular paths
Third-party service providers should follow the same password, VPN, MFA, backup and exposure requirements. Ask vendors and integrators to document every remote path and remove dormant accounts.
CISA’s July 2026 water-sector alert warns that cellular modems installed by operators, vendors or integrators may be undocumented and missed by routine internet-exposure scans. Include modems and out-of-band links in asset inventories and firewall reviews.
8. Validate project files and monitor for unauthorized changes
A July 22, 2026 joint advisory update said targeting had expanded beyond Unitronics to Schneider Electric, Siemens and possibly other PLC manufacturers. It recommends strict network access control, validation of PLC project files for unauthorized changes and notifying service providers about active threats.
Best Value
- The PL2303GT chip is 1 of the latest G-Series IC product added to the popular PL2303 USB to Serial
- (UART) Bridge Controller family, replacing the PL2303RA USB to RS232 serial chip. It provides an advanced
- full-featured single-chip bridge solution for connecting a full-duplex UART asynchronous serial interface
- device to any Serial Bus (USB) capable host. The PL2303GT provides highly compatible USB
- drivers to simulate the traditional COM port (via virtual COM Port) on most operating systems allowing
Direct exposure versus managed remote access
| Access pattern | Unsolicited exposure | MFA and source restrictions | Operational use | CISA-aligned position |
|---|---|---|---|---|
| PLC directly on the public internet | Internet scanners can reach the controller and its service ports. | Often limited by the PLC’s own features; no central session control. | Convenient but difficult to govern safely. | Remove this exposure. |
| PLC behind firewall, VPN or gateway | Remote traffic is mediated before it reaches the controller. | Gateway can enforce MFA, allowlisting, logging and time-limited access. | Supports authorized engineering access while reducing attack paths. | Use this pattern when remote access is necessary. |
How the 2023 incident fits the broader campaign
The November 2023 alert concerned one identified Unitronics device at a U.S. facility. A separate joint advisory from CISA, the FBI, NSA, EPA and Israel National Cyber Directorate, first published December 1, 2023 and updated December 14, described a broader campaign attributed to IRGC-affiliated actors using the CyberAv3ngers persona.
That advisory reported at least 75 compromised devices, including at least 34 in the U.S. Water and Wastewater Systems sector. Those figures describe the wider campaign against Unitronics devices, not the single water-authority incident in the November alert.
A practical checklist for water-utility operators
- Inventory every PLC, HMI, engineering workstation, router, VPN endpoint and cellular modem.
- Check external scanning and firewall records for internet-reachable PLC services, including TCP 20256 and PCOM/TCP traffic.
- Disconnect direct public-internet access and remove unnecessary port forwards.
- Place required remote access behind a managed VPN or gateway with MFA, logging and known-source restrictions.
- Replace default passwords, including Unitronics “1111,” and disable unused accounts.
- Confirm current manufacturer software and firmware for each device.
- Compare running logic and project files with an approved baseline.
- Create and test a known-clean restoration image, including factory-reset and redeployment steps.
- Require vendors and integrators to document and secure their access paths.
- Prepare a response plan that covers isolation, manual operation, engineering validation and communications with CISA and other authorities.
What the public record does not establish
CISA’s published material does not name the municipality in the November 2023 alert, provide a numerical impact for that specific facility, identify contamination, or endorse a particular firewall, VPN or gateway product. The later 2026 warnings describe separate activity and broader PLC targeting; they should not be presented as additional details of the original Unitronics event.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

