On July 30, 2026, the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) issued an urgent Public Service Announcement warning critical infrastructure operators about active cyberattacks targeting operational technology (OT) in the Water and Wastewater Sector (WWS). Malicious actors have exploited exposed industrial controllers, causing operational disruptions across multiple U.S. states.
Chronology of the Cyber Incident
The initial surge of attacks began over the weekend of July 26 and July 27, 2026, when Minnesota IT Services (MNIT) activated state cybersecurity response teams following coordinated breaches at more than 30 local community water systems. By July 30, 2026, federal investigators confirmed that utility facilities in at least seven states had reported similar security incidents to the FBI.
Threat actors specifically targeted internet-exposed Programmable Logic Controllers (PLCs), focusing primarily on Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series devices. After discovering these devices online, adversaries accessed them remotely without proper authentication and altered internal configurations. Specifically, attackers modified IP address settings and administrative passwords, effectively locking legitimate plant operators out of their monitoring and control software.
Impact on Critical Infrastructure and Public Operations
While water safety parameters remained within public health limits due to manual secondary safeguards, the attacks degraded operational technology functions across affected facilities. The loss of real-time telemetry, remote monitoring, and automated pump adjustments forced utility staff to revert to manual site inspections and manual valve overrides.
This incident highlights a persistent vulnerability across municipal utilities: connecting legacy industrial control systems directly to the public internet without adequate perimeter defenses or multi-factor authentication. Threat actors can easily locate exposed PLCs using automated internet scanners like Shodan or Censys, enabling rapid, low-complexity attacks against public utilities.
Security Guidance and Protection Steps
In response to the campaign, federal authorities recommend immediate defensive actions for all critical infrastructure asset owners:
1. Remove PLCs from Direct Internet Exposure: Place all MicroLogix and other industrial controllers behind secure firewalls or Virtual Private Networks (VPNs). Ensure no PLC control port is accessible directly via public IP addresses. 2. Implement Access Control Lists (ACLs): Restrict communication with PLCs so that only authorized, hardcoded IP addresses within the internal management network can issue configuration commands. 3. Change Default Credentials: Immediately update administrative passwords on all industrial controllers to long, complex strings unique to each device. 4. Maintain Offline Configuration Backups: Store verified ladder logic and network configuration backups offline to allow rapid recovery if a device is hijacked or locked out.
CYBERSHIELDZONE