PLC Attacks on U.S. Water Systems Trigger FBI and EPA Probe

PLC Attacks on U.S. Water Systems Trigger FBI and EPA Probe

PLC Attacks on U.S. Water Systems Trigger FBI and EPA Probe

at U.S. water utilities is no longer a theoretical risk modeled in tabletop exercises. It is an active, documented campaign. According to federal advisories and a Help Net Security week-in-review published on September 27, 2026, attackers compromised internet-facing PLCs at water systems across at least seven states by early August, remotely altering device settings and, in several cases, strippin

3 min readContent reviewed

Detail

The defining feature of this campaign is not sophistication, it is exposure. Attackers did not need zero-days or supply-chain implants. They reached controllers that were directly addressable from the public internet, a configuration that security agencies have warned against for years. The lesson for the OT market is blunt: the cheapest, highest-impact security control remains network architecture, not new hardware.

The timeline matters. On July 30, 2026, the FBI and EPA issued a joint Public Service Announcement warning that malicious actors were targeting Operational Technology (OT) devices, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs, causing operational disruptions. Reporting since then has widened the picture.

By early August, water systems in at least seven U.S. states had been hit. Minnesota authorities disclosed that more than 30 municipal water facilities in the state were targeted. Broader tallies have pointed to activity in as many as a dozen states, though federal agencies have not publicly named every jurisdiction.

July 30, 2026 , targeting of Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs.

a pump station shutdown in Georgia that dropped water pressure and triggered a boil-water advisory (no related illnesses reported).

The mechanics reported by federal agencies are deceptively simple. After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, locking out legitimate operators and severing monitoring and control functionality. In effect, the attackers did not necessarily damage the equipment, they orphaned it from the people responsible for running it.

That distinction is critical for maintenance strategy. A controller that is still physically healthy but unreachable is, operationally, offline. Without a known-clean backup of the PLC image and a rapid restore path, recovery can stall precisely when pressure and treatment systems need fast intervention.

Sourcing help

Send the BOM for one quote covering active stock, EOL stock and cross-references.

Need a quote for this part?

Send us the part number or article link — we will confirm price, availability and lead time.

WhatsApp us

Related Articles

Torna al blog