PLC Attacks Hit Water Utilities in 12 States as CISA, FBI Warn of Escalating OT Campaign
Coordinated intrusions disrupted automated controls at dozens of water systems starting July 27; attribution is pending, though the activity pattern aligns with Iranian-affiliated PLC exploitation documented in a prior federal advisory.
Threat actors locked operators out of water and wastewater control systems across at least 12 states beginning July 27, exploiting internet-exposed programmable logic controllers to modify passwords and sever device connectivity, federal agencies said last week.
CISA issued an urgent advisory on July 30, and the FBI and EPA followed the same day with a joint public service announcement. According to the FBI-EPA PSA reviewed by ETL Newswire, water and wastewater utilities in at least seven states had reported incidents by that date, and some of that activity "degraded water operations." Subsequent reporting by ABC News put the affected-state count at 12 by August 4.
The attack method is straightforward and doesn't require bespoke tooling. According to the CISA alert, actors accessed internet-facing PLCs, changed administrator passwords to lock out authorized personnel, and altered IP address settings to disconnect the controllers from operational networks. The downstream consequences were real: boil-water notices and extended manual operations at affected utilities. CISA's advisory names Rockwell Automation/Allen-Bradley, Siemens SIMATIC, and Schneider Electric equipment as affected hardware families.
The FBI's PSA focused specifically on Rockwell Automation MicroLogix 1100 and 1400 series devices. The bureau noted it has "only observed this behavior with the referenced Rockwell PLCs" but advised operators to treat other branded PLCs as similarly exposed.
The Minnesota hit was the most publicly documented single cluster. According to SecurityWeek's coverage of the incident, a coordinated attack struck OT systems at more than 30 community water systems in Minnesota on July 26 and 27. Affected cities included Maple Plain, Braham, South St. Paul, and Plymouth. State officials said drinking water quality was not affected in confirmed Minnesota cases and no boil-water advisories were issued there.
Attribution is unresolved. The federal PSA makes no attribution. Tenable's Research Special Operations team, in an FAQ published after the Minnesota events, noted the timing is consistent with escalating Iranian-affiliated PLC exploitation activity documented in an earlier CISA advisory, AA26-097A. A July 22 update to that advisory expanded the scope of observed exploitation to include Schneider Electric and Siemens devices alongside Rockwell Automation and, for the first time, documented project file exfiltration. That's a meaningful step up from simple lockout: exfiltrated project files can expose control-logic detail useful for planning more targeted future intrusions. Confidence on any Iran nexus remains low pending formal attribution.
One structural detail in the CISA alert deserves more attention than it's getting. According to the Water ISAC summary of the advisory, CISA specifically flagged cellular modems installed by operators, vendors, or system integrators as a common blind spot, noting these connections "may not be documented or captured in routine attack surface scans." That's an asset-inventory problem, not just a patching problem, and it affects utilities of all sizes. CISA was explicit that the targeting spans organizations with mature cybersecurity programs.
CISA is simultaneously rebuilding its own workforce. According to Cybersecurity Dive's August 5 report, Acting Director Nick Andersen said the agency is in the process of hiring after major personnel cuts in 2025 and acknowledged it is "still facing challenges responding to real-life events impacting the American people." The gap between the pace of OT exploitation and the pace of agency recovery is a variable worth tracking as this campaign continues.
Sources cited:
- FBI/EPA Joint PSA I-073026-PSA (https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions)
- CISA Alert (July 30, 2026) via Censys (https://censys.com/blog/cisa-alert-water-tower-plc-targeting/)
- SecurityWeek (https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/)
- Tenable RSO FAQ (https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know)
- WaterISAC (https://www.waterisac.org/tlpclear-cisa-issues-alert-urging-water-and-wastewater-utilities-to-protect-ot-against-activity-targeting-plcs)
- Cybersecurity Dive (https://www.cybersecuritydive.com/news/cisa-critical-infrastructure-job-cuts/827094/)
- BleepingComputer (https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-water-utilities/)
This release was originally distributed via ETL Newswire. Visit FBI/EPA Joint PSA I-073026-PSA for the full story, related releases, and contact information.
Visit FBI/EPA Joint PSA I-073026-PSA →