TheCyberExpress

FBI Warns Of PLC Cyberattacks On Water Utilities


The PLC cyberattacks targeting the Water and Wastewater Sector have prompted a joint warning from the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA), after multiple cyber incidents disrupted water operations across the United States. Since July 27, 2026, utility companies in at least seven states have reported attacks involving internet-facing PLCs, with some incidents resulting in degraded operations after threat actors altered device configurations.

According to the Public Service Announcement (PSA), malicious cyber actors targeted Programmable Logic Controllers manufactured by Rockwell Automation, specifically the Allen-Bradley MicroLogix 1100 and 1400 series. The agencies warned that while the observed activity involved these devices, organizations using PLCs from other vendors should also review their security posture.

PLC Cyberattacks Disrupt Water Operations

The FBI said attackers gained remote access to exposed PLCs connected directly to the internet and modified device settings, including IP addresses and passwords. These unauthorized changes caused operators to lose monitoring and control capabilities over affected systems.

In some reported cases, organizations also discovered modified PLC project files after identifying discrepancies in ladder logic across multiple sites. The agencies noted that similar network configurations deployed by third-party providers across different customers could enable threat actors to compromise multiple organizations using the same vulnerable setup.

The operational impact varied depending on how the compromised controller was being used. Systems relying on PLCs for equipment control experienced more significant disruption than those using the devices only for monitoring.

Reported Operational Impact

The FBI stated that affected organizations experienced operational disruptions, including pressure loss and flooding.

The PSA warned that reduced pressure within water systems could potentially allow untreated groundwater to enter water pipelines. The severity of the disruption depended on several factors, including whether the PLC controlled equipment or only monitored it, the specific hardware model involved, and whether operators could quickly switch affected systems to manual operation.

The FBI and EPA said they continue working with impacted organizations while encouraging other critical infrastructure operators to strengthen protections against similar attacks.

FBI and EPA Recommend Immediate Security Measures

To reduce the risk of compromise, the agencies urged organizations to disconnect internet-facing PLCs from direct public internet access and instead use secure gateways and firewalls for remote connectivity.

The advisory also recommends securing cellular modems with strong authentication, enabling logging to detect suspicious activity, and implementing isolated network architectures such as private Access Point Names (APNs), Software-Defined Wide Area Networks (SD-WAN), Zero Trust Network Access (ZTNA), or site-to-site Virtual Private Networks (VPNs).

Organizations are advised to use complex, unique passwords for PLC devices and strictly limit communications through firewall rules or access control lists (ACLs) so only authorized control system devices can communicate with PLCs.

Additional recommendations include placing hardware and software key switches in run mode to prevent unauthorized configuration changes, validating project files before returning devices to operation, reviewing PLC logic for unauthorized modifications, verifying backups before restoration, and examining connected devices for signs of lateral movement.

The agencies also encouraged operators to maintain the ability to manually operate Operational Technology (OT) systems, routinely test disaster recovery procedures, and develop replacement plans for end-of-life hardware that no longer receives security updates.

Incident Reporting Encouraged

Organizations experiencing similar PLC cyberattacks or OT security incidents are encouraged to report them to their local FBI field office and submit a complaint through the Internet Crime Complaint Center (IC3).

The advisory also asks affected organizations to provide technical details, including PLC model numbers, serial numbers, IP addresses, and any unusual network activity connected to programmable controllers. For incidents involving Rockwell Automation products, organizations are advised to contact the company’s Product Security Incident Response Team.

The FBI, EPA, and partner agencies also referenced previously published guidance covering incident response, cybersecurity best practices for water systems, and secure connectivity principles for Operational Technology (OT) environments.



Source link