wsj.com web signal

CISA warns of PLC hacks against water utilities in seven states

cybersecurity ai-business

TL;DR

  • FBI says water and wastewater utilities in at least seven states have reported incidents since July 27, 2026, with some operations degraded.
  • Attackers targeted internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing passwords and IP addresses to lock out operators.
  • CISA called the activity a significant escalation and urged operators to remove publicly exposed PLCs from the internet immediately.

A coordinated wave of intrusions has hit water and wastewater utilities in at least seven states since July 27, and the operating pattern is the plain one every OT security team has been warned about for years: internet-facing programmable logic controllers, no foothold required. The Wall Street Journal reported that the FBI and CISA are treating it as a live cross-state event, with some utilities losing monitoring and control, issuing boil-water notices, or reverting to manual operations.

The technical detail worth pausing on is where the attackers went. According to Cybersecurity Dive, the FBI and EPA say the campaign is hitting Rockwell Automation/Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 units, with intruders changing passwords and IP addresses to lock operators out. In at least one case they went further and modified the PLC project files, altering the ladder logic itself. A password reset does not undo that; the plant needs someone to reload known-good logic.

CISA's own alert called this a significant escalation and asked operators to pull publicly exposed PLCs off the internet immediately. That is a big ask for the small municipal systems that make up most of the sector, many of which run without dedicated IT staff on kit whose default settings have quietly been reachable from the open web since installation. The operational impact so far, per the reporting, has included flooding and pressure loss at some sites, though no contamination has been reported.

The honest caveat is attribution. US and state officials are treating Iran-linked actors as one suspect because the playbook resembles prior intrusions against industrial control gear, but no formal attribution has been made and investigators have flagged the risk of a false flag. The full state list beyond Minnesota, where more than 30 community water systems were hit between July 26 and 27, has not been made public.

What to watch is whether federal funding, EPA rulemaking, or state utility regulators move faster on mandatory OT segmentation now that the sector has a live example of what an exposed MicroLogix on the internet actually costs. ICS security vendors and MSSPs selling into small utilities are the obvious commercial beneficiaries.