FBI and EPA warn of cyberattacks on water sector PLCs after string of US incidents
- A joint FBI–EPA advisory warns that cyberattackers are exploiting internet-facing programmable logic controllers at US water utilities, with incidents reported in at least seven states since late July.

Written byOlivia Tempest
4 August 20262 min read

The FBI and EPA have issued a joint Public Service Announcement (PSA) warning that malicious cyber actors are targeting internet-facing programmable logic controllers (PLCs) used by Water and Wastewater Sector (WWS) utilities, in some cases disrupting operations.
Utilities in at least seven US states have reported incidents to the FBI since 27 July 2026, with some activity degrading water operations. The warning follows a recent cyberattack on more than 30 water systems in Minnesota, reported by Smart Water Magazine, in which municipalities including Plymouth, South St. Paul, Maple Plain and Braham saw a coordinated attack on operational technology on 26–27 July 2026. The PSA does not name Minnesota specifically, and it is not confirmed whether the two are directly linked, but the timing overlaps closely.
Rockwell Automation PLCs in the crosshairs
The FBI has specifically observed activity targeting Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs, though it notes that similar risks may apply to other-branded PLCs.
After remotely accessing internet-facing devices, attackers reportedly changed IP addresses and passwords, cutting off staff’s monitoring and control functionality. At least one organisation found modified PLC project files after spotting discrepancies in ladder logic across several sites. Similarities in network setups provided by third-party integrators may also let attackers replicate intrusions across customers with comparable configurations.
Reported effects have included loss of pressure and flooding; a pressure loss could potentially let untreated groundwater seep into pipes. Severity for each victim depended on factors including whether the PLC was used for monitoring or control, the device model, and whether staff could switch to manual operations.

Recommended mitigations
The FBI and EPA recommend that WWS asset owners and operators:
- Remove PLCs from direct internet exposure, routing remote access through a secure gateway or jump host, securing cellular modems with strong authentication, and considering isolated architectures such as private APN, ZTNA or site-to-site VPN.
- Use strong, unique passwords on all OT devices.
- Restrict network access via firewall rules or ACLs, blocking unauthorized or hosting-provider IP addresses.
- Keep key switches in the run position, using program/remote mode only when actively updating software.
- Maintain manual operation capability, testing fail-safes, backups and standby systems regularly.
- Review PLC project files for unauthorized changes and check logs on connected devices for signs of lateral movement.
- Plan for end-of-life replacements, tracking EOL systems and applying compensating controls where replacement is delayed.







