Why it matters now: Attacks on U.S. water utilities have moved from abstract warnings to physical disruption. The FBI and EPA confirm malicious actors remotely seized Allen-Bradley programmable logic controllers (PLCs) at internet-facing water systems, with operators reporting lost water pressure and flooding. This is direct manipulation of the controls that dose chemicals, hold pressure, and protect drinking water — not a conventional data breach. The escalation has triggered a White House pilot and a hard reset on water utility PLC cybersecurity.
For industrial automation buyers, integrators, and OT security teams, the message is clear: internet-exposed PLCs are no longer a theoretical risk. They are an active target with documented operational consequences.
The Attack: Internet-Exposed Allen-Bradley PLCs Under Siege
Since July 27, 2026, water and wastewater utilities in at least seven states reported incidents to the FBI. Threat actors targeted Rockwell Automation / Allen-Bradley PLCs, specifically the legacy MicroLogix 1100 and 1400 series, alongside PLCs from other manufacturers.
Once inside, attackers changed IP addresses and passwords, locking out operators and severing monitoring and control functionality. Reported operational effects included loss of water pressure and flooding — with pressure loss potentially allowing untreated groundwater to seep into distribution pipes.
Campaign details and indicators — what the FBI and EPA documented
-
Target devices: Rockwell Automation / Allen-Bradley PLCs, primarily MicroLogix 1100 and 1400 series.
-
Timeline: Incidents reported since July 27, 2026, across at least seven states.
-
Tactics: Remote access to internet-facing devices; IP address and password changes; device lockout.
-
Observed impact: Loss of pressure, flooding, and altered PLC project files with ladder logic discrepancies.
-
Preceding activity: An earlier April 2026 advisory from CISA, FBI, NSA, EPA, DOE, and U.S. Cyber Command warned of actors exploiting internet-connected PLCs across water, energy, and municipal environments.
Analyst Insight: The targeting of MicroLogix 1100 and 1400 controllers is deliberate. These are aging, widely deployed, and frequently exposed for remote monitoring — exactly the conditions attackers exploit. Expect legacy PLC replacement cycles to accelerate as utilities weigh end-of-life hardware against rising OT security exposure.
Why Water Utilities Are the Soft Target in OT Security
Water and wastewater facilities present a uniquely attractive attack surface. Many operate legacy PLCs that predate modern security controls, with thin IT/OT budgets and limited cybersecurity staffing.
Remote telemetry and SCADA connectivity, often added for operational convenience, have pushed controllers directly onto the public internet. Default credentials, flat networks, and absent access control lists compound the exposure.
Market context: why the water sector is structurally exposed
- The EPA regulates roughly 150,000 public water systems in the United States, the majority small and under-resourced.
- Legacy PLCs such as the MicroLogix 1100/1400 are common across rural and municipal treatment plants.
- OT/ICS security spending in the water sector has historically lagged energy and manufacturing, despite equal criticality.
Market Trend: The incident is accelerating OT cybersecurity investment in water infrastructure. Expect demand for industrial firewalls, secure remote access gateways, network segmentation, and PLC hardening services to rise as utilities move to remove controllers from direct internet exposure.
Watershed 250: The White House Moves on Water PLC Cybersecurity
In response, the Trump administration launched Project Watershed 250, a six-month pilot announced August 31, 2026, in San Antonio, Texas. The program unites the White House Office of the National Cyber Director, Texas Cyber Command, the office of Governor Greg Abbott, and private-sector cybersecurity vendors.
Parsons was selected as prime contractor to deliver red teaming, vulnerability assessments, remediation, and AI-enabled cyber defense. The EPA and CISA participate as federal partners. The goal is to map sector-wide vulnerabilities and shift utilities from reactive incident response to proactive hardening — with plans to scale the model nationwide.
Project Watershed 250 at a glance
-
Duration: Six-month pilot, launched August 31, 2026.
-
Location: Texas, serving systems relied on by 31 million Texans.
-
Partners: Office of the National Cyber Director, Texas Cyber Command, Texas Governor's office, EPA, CISA, and a dozen private cybersecurity vendors.
-
Scope: Cyber assessments, hands-on remediation, red teaming, and AI-enabled defensive tools.
-
Intent: A scalable national model for water sector OT security.
Hardening OT and PLC Environments: What to Do Now
The FBI and EPA issued concrete mitigation guidance that should anchor any water utility or industrial integrator's immediate response. The core directive: remove PLCs from direct internet exposure and re-establish controlled access.
FBI / EPA mitigation checklist for internet-facing PLCs
- Disconnect PLCs from the public-facing internet; route access through secure gateways and firewalls.
- Set strong, unique passwords and change any default credentials.
- Apply access control lists (ACLs) to allow only authorized device communication.
- Set physical PLC mode switches to "Run" to prevent unauthorized program changes.
- Maintain manual operation capability as a fail-safe.
- Review PLC project files and ladder logic for unauthorized modifications.
- Plan for end-of-life replacements of legacy controllers.
Analyst Insight: For Koeed customers and system integrators, this advisory is a procurement signal. Hardware alone is no longer sufficient — buyers should evaluate PLCs and HMIs alongside network segmentation, secure remote access, and lifecycle support. Controllers with modern authentication, secure firmware updates, and easy air-gapping options will gain preference.
FAQ: Water Utility PLC Security Explained
What is a PLC, and why is it a target?
A programmable logic controller (PLC) is an industrial control device that manages physical processes — opening valves, dosing chemicals, and regulating pressure. Because it directly controls physical outcomes, compromising a PLC can cause flooding, contamination risk, or service loss.
Which PLCs were compromised in these attacks?
The FBI and EPA specifically flagged Rockwell Automation / Allen-Bradley PLCs, particularly the MicroLogix 1100 and 1400 series, though systems using other brands were also noted as potential targets.
What is Project Watershed 250?
Project Watershed 250 is a six-month White House pilot launched in Texas to assess and harden water utility cybersecurity using federal capabilities and private-sector AI and OT security tools, with the intent to scale nationwide.
What should water utilities do immediately?
Remove PLCs from direct internet exposure, enforce strong unique credentials, restrict network access with ACLs, set controllers to "Run" mode, and verify project files for unauthorized changes.
Bottom line: The water sector's OT infrastructure is now a demonstrated battlefield. For operators and the industrial automation supply chain alike, the response is the same — treat PLC cybersecurity as a physical-safety issue, not an IT afterthought.