September 29, 2026
September 29, 2026
The FBI and Environmental Protection Agency have warned that malicious actors are targeting internet-accessible programmable logic controllers at US water and wastewater utilities. Since July 27, 2026, organizations in at least seven states have reported incidents involving Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. After gaining remote access, the attackers changed device passwords and IP addresses, depriving operators of monitoring and control capabilities; one utility also found altered project files and discrepancies in ladder logic. Reported consequences included loss of water pressure and flooding, with the severity depending on the PLC’s function and the facility’s ability to switch to manual operation. Similar third-party network configurations across multiple utilities may have allowed the attackers to repeat the same techniques at several sites.
The agencies recommend removing PLCs from direct internet exposure and routing essential remote access through monitored gateways, firewalls or VPN-based architectures. Utilities should secure and monitor cellular modems, use strong and unique passwords, restrict communications through access-control lists, and place controller key switches in run mode to prevent unauthorized configuration or logic changes. Operators should also compare active PLC programs with verified files, inspect connected modems, workstations and human-machine interfaces for lateral movement, maintain clean backups, and regularly test manual operating procedures and business-continuity plans. Because unsupported equipment is particularly vulnerable, organizations should inventory end-of-life assets and replace or isolate them under a defined retirement schedule.
Source: Industrial Cyber