FBI and EPA Warn of Active Cyberattacks on Water Utilities as Forescout Finds Thousands of PLCs Still Exposed Online
A joint FBI-EPA advisory confirmed attacks on water systems in at least seven states; Forescout's Vedere Labs counted 4,407 internet-facing industrial controllers, 65 percent of them in the U.S., with 22 found in the same cities already hit.
The FBI and the Environmental Protection Agency issued a joint public service announcement on July 30 warning that malicious cyber actors have been targeting water and wastewater utilities across at least seven states since July 27, with some incidents degrading water operations. Days later, Forescout's Vedere Labs published findings that show exactly why the attacks have been so easy to carry out.
According to the FBI-EPA advisory reviewed directly on FBI.gov, the campaign targets Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), specifically the MicroLogix 1100 and 1400 series. The agency said it has observed attackers changing IP addresses and setting passwords on controllers that were already reachable from the open internet, causing operators to lose visibility and, in some cases, control of connected equipment. No exploitation of a software vulnerability was required.
On August 5, Forescout's Vedere Labs published an OT security analysis showing that the structural conditions enabling those attacks are widespread. Researchers queried the Shodan search engine on August 3 and returned 4,407 devices globally exposing port 44818, the EtherNet/IP engineering protocol used by the targeted controller families. According to the Vedere Labs report, 65 percent of those devices are in the United States, followed by Canada at 12 percent. More than half sit on large mobile carrier networks, consistent with what the FBI-EPA advisory described as cellular modem connectivity.
The overlap with confirmed attack sites is specific. Forescout identified 22 internet-facing Rockwell controllers inside the municipal boundaries of cities already hit by the campaign. According to the Vedere Labs analysis, 19 of those 22 ran firmware susceptible to CVE-2017-16740, a Rockwell CVSS 8.6-rated Modbus TCP buffer overflow in MicroLogix 1400 Series B and C devices that the vendor patched in firmware revision 21.003. Whether Modbus TCP was enabled on those hosts, which is a prerequisite for exploitation, could not be verified remotely.
Attempts to attribute the campaign have been contested from the start. Several media outlets reported links to Iranian actors, but Sai Molige, senior manager of threat hunting at Forescout, pushed back on that framing. In a statement to CyberScoop, Molige said the evidence is more consistent with mass scanning and opportunistic exploitation of a known vulnerability class than with a targeted, actor-specific campaign. That's a meaningful distinction. Attribution here is, at best, a low-confidence assessment, and the advisory itself does not name a responsible party.
Minnesota IT Services reported on July 28 that a coordinated attack hit more than 30 water systems statewide. According to reporting reviewed by Cybersecurity News, the city of Braham said attackers delivered malware through a wireless connection to shut down water plant controls, while Plymouth reported that affected equipment, including two water towers and 14 sewer lift stations, connected via cellular routers.
The exposure numbers have improved over time, but slowly and unevenly. The Vedere Labs historical series shows the count of exposed EtherNet/IP hosts dropped 47 percent from a peak of 7,814 in March 2020 to a low of 4,169 in June 2026. That progress stalled: the August 3 snapshot came in at 4,407, a tick upward from the June low. Forescout also found expired certificates, abandoned remote-access hostnames, and forgotten servers tied to municipal utilities, structural asset-visibility gaps that compound the risk beyond PLC counts alone.
CISA, Rockwell Automation, and federal law enforcement have issued at least three major advisories warning against direct internet exposure of industrial controllers since 2018. The Vedere Labs report frames the current situation plainly: those warnings have been largely ignored. The recommended mitigations in the FBI-EPA advisory are not new, either: disconnect PLCs from the public internet, disable unused services, and restrict Modbus TCP and port 44818 with strict allowlists.
The FBI has noted that while the observed behavior involves Rockwell devices, similar risks apply to any PLC brand exposed on the open internet. That's worth tracking as the incident count, currently confirmed in seven states by the FBI and at least 12 in broader reporting, continues to develop.
Sources cited:
- FBI / EPA Joint Public Service Announcement (FBI.gov) (https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions)
- Forescout Vedere Labs OT Security Analysis (https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/)
- CyberScoop (https://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/)
- The Hacker News (https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html)
- Cybersecurity News (https://cybersecuritynews.com/internet-exposed-rockwell-plcs/amp/)
- TechTimes (https://www.techtimes.com/articles/323480/20260807/water-utilities-hacked-across-12-states-cannot-secure-what-they-cannot-see.htm)
This release was originally distributed via ETL Newswire. Visit FBI / EPA Joint Public Service Announcement (FBI.gov) for the full story, related releases, and contact information.
Visit FBI / EPA Joint Public Service Announcement (FBI.gov) →