FBI, EPA warn of cyberattacks targeting PLCs at multiple U.S. water utilities

0

The U.S. Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are warning water and wastewater utilities about a series of cyberattacks targeting internet-connected operational technology devices. The attacks have disrupted operations at facilities in at least seven states.

The warning comes after the City of Braham, Minnesota, announced that its water treatment plant was temporarily taken offline following what officials described as a malicious cyberattack. In a public statement, the city said crews determined the outage “was a result of a malicious cyber-attack of computerized operating systems by unknown actors.”

“This attack did not alter or cause any issue to the physical water plant or water quality or safety,” the city said. “Rather the attackers shut down the operating controls which shut down the well and water treatment plant.”

The city said operators restored the facility after identifying and addressing the issue, adding that residents could return to normal water use. Officials also noted that Braham was “not alone in this attack,” stating they had been informed that at least four other communities experienced similar incidents and that the State of Minnesota was assisting with the investigation and mitigation efforts.

Subscribe to our Newsletter!

The latest environmental engineering news direct to your inbox. You can unsubscribe at any time.

In a separate incident, the City of Rapid City, South Dakota, said it recently detected a cyber incident involving one of its wastewater lift stations. City officials said the attempt was identified quickly and safeguards were implemented to protect the system.

“At no time was the city’s water or wastewater infrastructure systems placed in jeopardy,” the city said, adding that it is working with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and other federal partners.

“We continually take steps to ensure the continued security and reliability of our water and wastewater systems,” said Rapid City Public Works Director Mike Theis. “We want to assure residents our city water system remains safe and we are continuing to remain vigilant in monitoring for cyberattacks across city systems.”

In a joint public service announcement, the agencies said malicious cyber actors have been targeting internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs). Since July 27, 2026, utilities in at least seven U.S. states have reported incidents to the FBI, with some attacks degrading water system operations.

While the U.S. has yet to verify whether the threats emerged from Iran, U.S. President Donald Trump and other key officials highlighted the apparent lack of financial motives behind the cyberattacks, which stepped up since the U.S. and Israel launched a war against the country five months ago.

According to the agencies, attackers remotely accessed exposed PLCs and altered device IP addresses and passwords, resulting in the loss of monitoring and control capabilities. In at least one case, an organization also discovered unauthorized modifications to PLC project files after identifying discrepancies in ladder logic across multiple sites.

The FBI said the operational impacts have included pressure loss and flooding. Loss of water pressure can create the potential for untreated groundwater to infiltrate drinking water distribution systems. The severity of the disruptions depended on whether compromised PLCs were used for monitoring or active process control, the specific equipment involved, and whether utilities were able to switch to manual operations.

The agencies also noted that similarities in network architectures deployed by third-party vendors across multiple facilities may have allowed attackers to compromise more than one organization using the same vulnerable configurations.

To reduce the risk of compromise, the FBI and EPA are urging critical infrastructure owners and operators to remove PLCs from direct internet exposure by using secure gateways and firewalls, implement strong unique passwords, and configure access control lists to limit communications to authorized control system devices.

Additional recommendations include securing cellular modems used for remote access with strong authentication, enabling and reviewing modem logs for suspicious activity, implementing secure remote access technologies such as private APNs, VPNs or Zero Trust Network Access, and placing PLC key switches in run mode to prevent unauthorized logic changes.

The agencies also advised organizations to routinely verify PLC project files for unauthorized modifications, validate backups before restoration, review logs from connected operational technology devices for signs of lateral movement, and regularly test manual operating procedures, business continuity plans and disaster recovery capabilities.

Utilities are also encouraged to develop rolling forecasts for replacing end-of-life operational technology equipment, as unsupported hardware no longer receives security updates and is frequently targeted by cyberattackers.

LEAVE A REPLY

Please enter your comment!
Please enter your name here