• FluTrackers.com Inc. does not provide medical advice. Information on this web site is collected from various internet resources, and the FluTrackers board of directors makes no warranty to the safety, efficacy, correctness or completeness of the information posted on this site by any author or poster. The information collated here is for instructional and/or discussion purposes only and is NOT intended to diagnose or treat any disease, illness, or other medical condition. Every individual reader or poster should seek advice from their personal physician/healthcare practitioner before considering or using any interventions that are discussed on this website. By continuing to access this website you agree to consult your personal physican before using any interventions posted on this website, and you agree to hold harmless FluTrackers.com Inc., the board of directors, the members, and all authors and posters for any effects from use of any medication, supplement, vitamin or other substance, device, intervention, etc. mentioned in posts on this website, or other internet venues referenced in posts on this website.
  • We are not asking for any donations. Do not donate to any entity who says they are raising funds for us.

US gov. : Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptio

Commonground

Senior Moderator
[emphasis is mine]
July 30, 2026

Introduction

The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.

After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.

Threat landscape

MCAs are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities. At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.

Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations. The FBI and EPA are engaging with victim organizations and are providing the following recommendations for critical infrastructure asset owners and operators.

Tips to protect yourself

The FBI and EPA recommend individuals take the following precautions:
  • Disconnect PLC from the public-facing internet. Follow the joint guidance Secure connectivity principles for OT to safely allow remote access. Specifically, “remove inbound port exposure,” so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled. Do this through a secure gateway (jump host) that brokers the connection.
    • Ensure cellular modems, used for remote field connectivity and access, are secured with strong authentication and updated.
    • Enable logs for connected modems and regularly review for suspicious activity to detect intrusions and improve incident response speed.
    • To mitigate unauthorized access to OT via cellular modems, organizations should consider implementing isolated architectures, such as private Access Point Name (APN), 5G Public Network Integrated Non-Public Network (PNI-NPN), cellular Software-Defined Wide Area Network (SD-WAN), Zero Trust Network Access (ZTNA), or a site-to-site virtual private network (VPN)
  • Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable. Implementing robust password practices remains a critical security measure that can help prevent unauthorized access and strengthen the overall security posture of OT devices.
  • Strictly control network access to PLC devices. Configure firewall rules or access control list (ACL) security features on PLCs or programmable controllers to allow only authorized communications between expected control system devices. Block access from unauthorized or threat actor-controlled IP addresses, such as those associated with hosting providers
  • Place physical and software key switches into the run position to block unauthorized changes to logic, configuration, and firmware. Devices should only be in the program or remote position when updating or downloading software online and immediately switched back to the run position when complete. (See Rockwell Automation’s System Security Design Guidelines for manufacturer’s instructions.)
    • Prior to switching the device to run mode, review and validate project files, as changing modes will lock in the current project file downloaded to the device.
  • Practice and maintain the ability to operate OT systems manually. The capability for organizations to revert to manual controls to quickly restore operations is vital in the immediate aftermath of an incident. Business continuity and disaster recovery plans, fail-safe mechanisms, islanding capabilities, software backups, and standby systems should all be routinely tested to ensure safe manual operations in the event of an incident.
  • Review project files running on PLCs for unauthorized changes. Use vendor provided integrity checking tools and visually compare the running program to known good logic. Ensure reusable logic and input/output configurations are valid.
    • If restoring backups, verify the backup does not contain malicious logic before deployment.
    • Review logs and configurations on all connected devices, including modems, HMIs, and workstations, to assess potential lateral movement by threat actors. If it appears the actors connected to additional devices, reimage these devices to remove any potential malicious changes or access tools.
  • Plan for end-of-life (EOL) replacements when possible. When a hardware device is EOL, the manufacturer no longer sells the product and is not actively supporting the hardware, which also means they are no longer releasing software updates or security patches for the device. Since EOL devices no longer receive security updates, they are routinely targeted by MCAs.
    • Maintain a rolling 12-month EOL forecast, reviewed quarterly with owners and procurement.
    • Track EOL systems by product, owner, location, and retirement date.
    • Replace or isolate EOL assets; if delays occur, apply compensating controls with firm decommission dates.
Report it

If you or someone you know has sustained similar OT outages, please contact your local FBI field office and file a complaint with the IC3 at ic3.gov. Additionally, you can contact CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). Be sure to include as much information as possible:
  • model numbers, serials, and IPs of programmable logic controllers connected to network
  • unusual IPs on networks connected to programmable logic controllers
  • EPA’s Cybersecurity Technical Assistance
  • Rockwell Automation: Contact the Rockwell Automation Product Security Incident Response Team (PSIRT) at PSIRT@rockwellautomation.com for questions regarding this guidance or to report cyber incidents related to Rockwell Automation products.
For additional information on mitigating threats to OT systems, please see previous guidance documents:
Disclaimer: The information in this document is being provided "as is" for informational purposes only. The FBI does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI.

https://www.fbi.gov/investigate/cyb...c-controllers-causing-operational-disruptions
 
Joint Cybersecurity Advisory
Click image for larger version  Name:	Screenshot 2026-08-01 at 8.44.22 AM.png Views:	1 Size:	461.6 KB ID:	1039322

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

Publication: April 7, 2026
Last Update: July 22, 2026

Federal Bureau of Investigation
Cybersecurity and Infrastructure Security Agency
National Security Agency
Environmental Protection Agency
Department of Energy
United States Cyber Command – Cyber National
Mission Force
Department of the Treasury


Last Update July 22, 2026

Executive Summary​​

The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting

of internet-connected operational technology (OT) devices, including programmable logic controllers

(PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through

malicious project file interactions and manipulation of data on human machine interface (HMI) and

supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and

financial loss.

Last Update Description

This update adds new guidance on detecting malicious changes in reusable code modules exploited

within Rockwell Automation PLC programs. It also expands scope to include observed targeting of

Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the

importance of restricting direct internet access and providing best practices for secure deployment.

Affected Products

Potentially all internet exposed PLCs, including Rockwell Automation/Allen-Bradley, Schneider

Electric, Siemens, and other branded/manufactured PLCs.

Key Actions

 Install PLCs consistent with manufacturers' guidelines and security best practices.

 Remove PLCs from direct internet exposure via secure gateway and firewall; work with IT/OT

team members and/or integrators to perform this action.

 Query available logs for the provided indicators of compromise (IOCs) and check available logs

for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and

502, especially traffic originating from foreign hosting providers.

 For Rockwell Automation devices, place the physical mode switch on the controller into run

position. If you suspect your organization was targeted, including against other branded PLC

devices, contact the authoring agencies and PLC manufacturer for guidance.

For a downloadable copy of July 22, 2026 IOCs, see:

 AA26-097A STIX XML (July 2026) (29 KB)

Indicators of Compromise

 AA26-097A STIX JSON (July 2026) (30 KB)

For a downloadable copy of historical April 7, 2026 IOCs, see:

 AA26-097A STIX XML (36 KB)

 AA26-097A STIX JSON (12 KB)

Intended Audience

Organizations: Critical Infrastructure

Sectors: Government Services and Facilities, Water and Wastewater Systems (WWS), and Energy

Roles: Integrators, asset owners, defensive cybersecurity analysts, OT cybersecurity engineers,

cybersecurity architects, secure systems developer

[Page 2 of 15 | Product ID: AA26-097A]

Table of Contents

Continued:
https://www.cisa.gov/sites/default/...rs-across-us-critical-infrastructure_508c.pdf



 
FBI investigates as Michigan joins Minnesota in reporting cyberattacks on its water systems

​August 2, 2026
Michigan on Saturday joined Minnesota in reporting cyberattacks on nine of the state's water systems but an official said all systems were operating "safely."​

... The reports in Michigan surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems.

Soon after, the state received "a small number of reports from Michigan communities indicating activity consistent with what federal agencies described," said Dale George, the director of communications at the state's Department of Environment, Great Lakes, and Energy. He later said nine systems were impacted.

... https://abc11.com/post/water-system...-amid-warning-possible-iran-hackers/19614740/
 
August 2, 2026

​7 states now targeted by cyberattacks on American water system, sources say

Sources tell ABC News that Georgia and Michigan are among the seven states now reporting cyberattacks on their water systems, raising concerns about the security of America's infrastructure. ABC News’ Aaron Katersky reports.

https://abcnews.com/video/135305723/

 
2 New Jersey municipal water systems targeted in cyberattacks
August 5, 2026,

Excerpt:
"Our New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) responded to two cyber incidents affecting New Jersey municipal water systems this past week. The NJCCIC is working directly with the affected utilities alongside our federal partners at the FBI and the Cybersecurity and Infrastructure Security Agency," the state said Wednesday.

https://abcnews.com/US/2-new-jersey-municipal-water-systems-targeted-cyberattacks/story?id=135383816

 
At least 12 states report cyberattacks on water systems possibly linked to Iran-backed hackers, sources say
Updated on: August 6, 2026

Cyberattacks on U.S. water systems that officials suspect may be linked to Iran-backed hackers have been reported in at least a dozen states, sources familiar with the matter told CBS News on Wednesday.

Those states include Michigan, Minnesota, Georgia, New Jersey and South Dakota. In Minnesota specifically, more than 30 community water systems were impacted, CBS News previously learned.
-snip-
So far, according to officials, the cyberattacks have had no impact on drinking water, which has remained safe.

Continued: https://www.cbsnews.com/news/more-states-water-systems-cyberattacks-iran-backed-hackers/
 
Oregon drinking water system accessed in recent cyber attacks

​Aug. 7, 2026

A week after a New York Times report revealed that at least 100 water systems were hacked in other states, Oregon Gov. Tina Kotek’s office told OPB Friday that hackers had gained access to an Oregon water district’s core operating technology.

State leaders wouldn’t say if the attack was linked to a swarm of cyber attacks that the Times said were initiated by hackers in Iran. Oregon is still assessing the impact of the attack, and officials contacted by OPB would not identify which water district was targeted.

... https://www.opb.org/article/2026/08/07/oregon-drinking-water-system-accessed-cyber-attacks/
 
Back
Top