FBI & EPA Alert: PLC Cyberattacks Disrupt US Water Systems in 12 States

FBI & EPA Alert: PLC Cyberattacks Disrupt US Water Systems in 12 States

Why it matters now: For the roughly 148,000 public drinking water systems across the United States, a single internet-connected Programmable Logic Controller (PLC) has become the weakest link in an escalating cyber conflict. In a joint public service announcement, the FBI and the Environmental Protection Agency (EPA) have confirmed that malicious cyber actors are actively targeting water and wastewater utilities — exploiting internet-facing PLCs to disrupt operations, manipulate safety thresholds, and in some cases trigger flooding and pressure loss that could allow untreated groundwater to seep into distribution pipes.

Analyst Insight: This is not a hypothetical scenario. The FBI has confirmed operational disruptions across at least 12 states — including Michigan, Minnesota, Georgia, New Jersey, and South Dakota — with effects ranging from loss of monitoring and control to physical flooding. The advisory specifically flags Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs, but CISA has also identified targeting of Schneider Electric, Siemens, and other manufacturers. The threat is vendor-agnostic and escalating.

Anatomy of the Attack: How Hackers Are Weaponizing PLCs

The attack methodology is alarmingly straightforward. Threat actors scan the public internet for exposed OT devices — specifically PLCs that have been left accessible without adequate firewall protection or network segmentation. Once located, they remotely access these devices, change administrator passwords, and alter IP configurations, effectively locking out legitimate operators while maintaining control themselves.

As Joshua Corman, executive-in-residence for public safety and resilience at the Institute for Security and Technology, explains: PLCs operate on simple conditional logic — "if this happens, then that happens." A hacker who gains access can disable the alerts that notify employees of system malfunctions, manipulate water pressure thresholds beyond safe limits, or shut down critical pumps before equipment sustains damage. In some documented cases, attackers have reconfigured PLCs to ignore safety interlocks entirely.

Confirmed Operational Impacts Reported to the FBI
  • Pressure Loss: Sudden drops in water pressure, potentially allowing untreated groundwater to seep into distribution pipes — a public health hazard.
  • Flooding: Uncontrolled pump operation or valve manipulation causing physical overflow and infrastructure damage.
  • Loss of Visibility: Operators locked out of monitoring interfaces, losing real-time awareness of system conditions.
  • Manual Mode Forced: Facilities compelled to switch to manual operations, increasing labor costs and reducing response precision.

The Stakes: Why Water Infrastructure Is Uniquely Vulnerable

Water and wastewater systems present a uniquely attractive target for several reasons. Many are operated by small municipalities with limited cybersecurity budgets and no dedicated OT security personnel. Unlike large energy utilities — which have faced regulatory pressure to harden their systems for over a decade — the water sector has lagged significantly in adopting industrial cybersecurity fundamentals.

The numbers paint a stark picture: according to research from BitSight, global ICS/OT device exposure to the public internet rose 12% in 2024 alone, with more than 180,000 devices visible each month and projections approaching 200,000 in 2025. These are not obscure, niche devices — they are the programmable brains controlling pumps, valves, chemical dosing systems, and filtration processes that millions of Americans depend on daily.

Market Trend: Dragos' 2026 OT/ICS Cybersecurity Year in Review reveals that 26% of ICS vulnerability advisories contained no patch or mitigation from the vendor. For a quarter of disclosed vulnerabilities, operators literally have no remediation path — even if they wanted one. Meanwhile, 80 distinct ransomware groups targeted industrial organizations in 2024, a 60% increase from the prior year. The attack surface is expanding faster than defensive capabilities.

What the FBI & EPA Are Telling Operators to Do — Right Now

The joint advisory is unequivocal: disconnect PLCs from the public-facing internet immediately. The agencies have issued a suite of actionable hardening recommendations that every industrial operator — regardless of sector — should review.

FBI & EPA Recommended Mitigations (Full List)
  1. Remove PLCs from direct internet exposure by implementing secure gateways and properly configured firewalls.
  2. Set strong, unique passwords on all OT devices — replace default credentials immediately.
  3. Implement Access Control Lists (ACLs) to allow only authorized communication between expected control system devices.
  4. Review manufacturer security guidance for your specific PLC models — Rockwell Automation, Siemens, and Schneider Electric have all published hardening documentation.
  5. Validate project files running on PLCs to detect unauthorized changes to logic or configuration.
  6. Ensure third-party service providers and system integrators are informed of active threats targeting internet-connected PLCs.
  7. Segment OT networks from enterprise IT networks and the internet using demilitarized zones (DMZs).
  8. Enable logging and monitoring on all PLC access attempts, with alerts for anomalous activity.

The Bigger Picture: Industrial Automation's Expanding Attack Surface

While the water sector is currently in the crosshairs, the underlying vulnerability is universal. Any industrial environment — manufacturing, energy, transportation, or building automation — that exposes PLCs or other OT devices to the internet without adequate controls is a potential target. The Iranian-affiliated group behind many of these attacks, tracked by CISA and the FBI, has demonstrated interest across multiple critical infrastructure sectors.

Cape May Mayor Zack Mullock described the attack on his city's water utility as "modern warfare," underscoring a sobering truth: the battlefield has shifted. Reducing online exposure of industrial control systems, he argued, makes critical infrastructure exponentially harder to infiltrate. The sentiment echoes across the cybersecurity community — basic cyber hygiene is no longer optional.

Key Statistics: The State of Industrial Cybersecurity (2024–2025)
  • 180,000+ — Average monthly ICS/OT devices detected on the public internet in 2024 (BitSight).
  • 12% — Year-over-year increase in global ICS/OT internet exposure (BitSight).
  • 80 — Ransomware groups targeting industrial organizations in 2024, up 60% from 2023 (Dragos).
  • 26% — ICS vulnerability advisories with no available patch or vendor mitigation (Dragos).
  • 148,000 — Approximate number of public drinking water systems in the United States (EPA).
  • 12+ states — Confirmed affected by the current wave of PLC-targeting cyberattacks (FBI/EPA).

From Alert to Action: Securing PLCs in the Real World

The FBI and EPA advisory is not the first warning — and it will not be the last. In April 2026, CISA, the FBI, EPA, and NSA issued a joint advisory specifically addressing Iranian-affiliated cyber actors exploiting PLCs across US critical infrastructure. The updated guidance expanded manufacturer scope to include Schneider Electric and Siemens, signaling that attackers are not limiting themselves to a single vendor ecosystem.

For industrial operators and system integrators, the message is unambiguous. The era of "air-gapped by assumption" is over. Every PLC connected to a network — directly or indirectly — must be treated as a potential target. The question is no longer whether your facility will be scanned by adversaries, but whether you have reduced the attack surface enough to make exploitation impractical.

Bottom Line for Industrial Operators: If your PLCs are internet-facing — even indirectly through poorly configured remote access solutions — you are operating on borrowed time. The threat actors are active, the vulnerabilities are known, and the consequences of inaction now include not just data loss but physical disruption to water supply and public health. Disconnect, segment, harden, and monitor. The tools exist. The time to deploy them is now.

Related Articles

Вернуться к блогу