FBI and EPA Warn of Cyber Attacks on Internet-Facing Controllers in Water Systems
WASHINGTON — The Federal Bureau of Investigation and the Environmental Protection Agency issued Public Service Announcement I-073026-PSA on July 30 stating that malicious cyber actors have conducted cyber attacks against Operational Technology devices, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series Programmable Logic Controllers, in the Water and Wastewater Sector.
Since July 27, utility companies in at least seven states have reported incidents to the FBI, with some of the activity degrading water operations. After remotely accessing internet-facing devices, the actors changed IP addresses and passwords, producing a loss of monitoring and control functionality.
The Cybersecurity and Infrastructure Security Agency stated on July 30 that it is observing a significant increase in cyber threat actors targeting programmable logic controllers in the Water and Wastewater Systems Sector.
The activity has resulted in boil water notices and sustained manual operations. CISA noted that the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.
Observed Configuration Changes and Operational Effects
Malicious cyber actors are targeting internet-exposed PLCs of the Rockwell MicroLogix 1100 and 1400 series to remotely alter device configurations. The changes produce a loss of view and, in some cases, function of connected equipment.
At least one organization reported modified PLC project files after observing ladder logic discrepancies across several sites. Across several victims, similarities in network setups provided by third parties may allow the actors to replicate successes where the same vulnerable configurations exist.
Operational effects reported to the FBI include loss of pressure and flooding. Pressure loss in water systems could allow untreated groundwater to enter pipes. The scale of impact on any given victim depended on whether the PLC was configured for monitoring or for control, the specific model (1100 versus 1400), the function supported, and the organization’s ability to switch to manual operations.
CISA confirmed that the activity has produced boil water notices and periods of sustained manual operation. The agency stated that exposed OT assets risk defacement, configuration changes, operational disruptions, and physical damage.
Rockwell Automation issued security notice SD1790 on July 30 specifically addressing recovery of MicroLogix 1400 controllers when the password is unknown.
The notice covers Series A, B, and C controllers with catalog numbers 1766-L32AWA, 1766-L32AWAA, 1766-L32BWA, 1766-L32BWAA, 1766-L32BXB, and 1766-L32BXBA. No CVE is associated with the notice.
The recovery procedure erases the controller’s program, data, and network configuration by powering off the unit, removing the 1747-BA battery, powering on to enter a fault state, powering off again, reconnecting the battery, resetting the IP address via the LCD panel, and downloading a known-good project file with RSLogix 500.
An offline .RSS project-file backup is required before the reset. For Series B controllers, Rockwell recommends applying firmware FRN 21.002 or later and enabling Enhanced Password Security.
Official Statements
-
Federal Bureau of Investigation and Environmental Protection Agency, Public Service Announcement I-073026-PSA, July 30: “The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.”
-
Federal Bureau of Investigation and Environmental Protection Agency, Public Service Announcement I-073026-PSA, July 30: “After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality.”
-
Federal Bureau of Investigation and Environmental Protection Agency, Public Service Announcement I-073026-PSA, July 30: “Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes.”
-
Cybersecurity and Infrastructure Security Agency, Alert, July 30: “CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. Threat actors have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations.”
-
Cybersecurity and Infrastructure Security Agency, Alert, July 30: “Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.”
-
Rockwell Automation, Security Notice SD1790, July 30: “Threat actors have tampered with device configurations by changing IP addresses, setting passwords, and causing loss of operator view. This guidance helps restore access by returning the controller to factory default state for redownloading a known good project file.”
-
CISA, FBI, NSA, EPA, DOE, and U.S. Cyber Command, Advisory AA26-097A update, July 22: “The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations.”
Full Report & Analysis
The full report includes expert analysis and risk assessment.
Full Report & Analysis →