Between March and July 2026, a wave of internet-facing PLC cyberattacks swept through U.S. municipal water systems, forcing operators in more than 30 Minnesota communities—and at least seven states nationwide—to lock down their industrial automation assets. Adversaries needed no zero-day exploits; they simply exploited default credentials and exposed remote-programming ports on legacy controllers. The result: changed passwords, altered IP addresses, and rewritten PLC project files that severed operators from their own water infrastructure.
Analyst Insight: This campaign is not a sophisticated nation-state operation. It is an industrial-scale test of a known truth—that thousands of PLCs and HMIs are still deployed with factory defaults and direct internet exposure. The attackers did not defeat security; they found where security was never installed.
The Anatomy of an Internet-Facing PLC Campaign
Xage's security analysis documents a coordinated sequence of intrusions in which adversaries modified credentials, changed controller IP addresses, and overwrote project files across exposed controllers. Each action was designed to disrupt normal operation and lock out legitimate operators.
The targets were overwhelmingly legacy Rockwell Automation and Allen-Bradley controllers—including MicroLogix 1100 and 1400 units—alongside aging HMIs. These devices are ubiquitous in water and wastewater treatment, where budgets favor longevity over modernization.
Campaign Timeline: March–July 2026
-
March–July 2026: Internet-facing PLC campaigns documented across exposed controllers.
-
July 27, 2026: More than 30 Minnesota water systems report simultaneous intrusions, including the city of Plymouth.
-
July 30, 2026: CISA issues an urgent advisory urging the Water and Wastewater Systems sector to remove publicly exposed PLCs from the internet.
-
Late July–August 2026: The FBI and EPA confirm incidents across at least seven states, with Michigan reporting nine affected systems.
Why Legacy PLCs Are the Weakest Link
Most water utilities operate on a cost-sensitive refresh cycle. Legacy PLCs and HMIs are often deployed with default settings, unchanged credentials, and remote-programming ports opened for integrator convenience—then never closed.
Once those ports face the public internet, they become discoverable by commodity scanning tools. Default passwords are widely known, making authentication a formality rather than a barrier.
Market Trend: The attack surface is expanding faster than remediation. A single 2026 snapshot identified thousands of exposed industrial hosts—including thousands of Rockwell EtherNet/IP and Siemens SIMATIC S7-1200 devices—visible on the public internet. Each is a potential entry point for the next campaign.
Internet-Facing PLC Security: The Enforcement-Layer Fix
Patching every legacy controller is unrealistic. Xage's analysis argues instead for externalizing trust decisions—moving authentication, multi-factor authentication (MFA), and policy evaluation out of the fragile device and into a dedicated enforcement layer that sits in front of it.
That architecture treats the PLC as an untrusted endpoint. Every session is authenticated, authorized, and logged before it ever reaches the controller, regardless of the device's native security posture.
Recommended Controls for Water Utilities
- Disconnect PLCs and HMIs from the public internet; route remote access through VPNs or secure gateways.
- Change all default passwords and enforce password protection on every controller.
- Apply IP allowlisting to permit access only from known engineering workstations.
- Deploy an identity-based enforcement layer with MFA and granular policy evaluation in front of legacy OT assets.
- Inventory undocumented cellular modems and vendor-installed remote access paths.
Frequently Asked Questions
Were these attacks sophisticated?
No. The intrusions relied on publicly exposed PLCs, default credentials, and open remote-programming ports—not novel exploits or zero-day vulnerabilities.
Which PLC models were targeted?
Analysis and federal advisories point to legacy Rockwell Automation and Allen-Bradley controllers, including MicroLogix 1100 and 1400 units, alongside aging HMIs in water and wastewater facilities.
Did the attacks affect water quality?
Minnesota officials stressed that the cyberattacks did not impact water quality. However, some utilities issued boil-water notices and switched to manual mode as a precaution, and the likely intent of the intrusions was to cause loss of system pressure and potential contamination risk.
What should plant operators do first?
Remove every PLC and HMI from direct internet exposure immediately. Then inventory remote-access paths, change default credentials, and move authentication to an enforcement layer with MFA.
The water sector's cyberattack cycle will not break by patching faster. It will break when operators stop trusting legacy controllers to secure themselves—and start externalizing that trust to a layer they control.