Water systems hacked: Rockwell PLC cyberattacks in US

US water systems hacked across seven states, say federal agencies

Water systems hacked incidents have made headlines across the United States, with a coordinated wave of cyberattacks targeting public utilities in at least seven states. Federal authorities have confirmed that attackers exploited internet-exposed Rockwell Automation Allen-Bradley MicroLogix PLCs, causing operational disruptions. While this event occurred outside the UK, the techniques used highlight risks that UK organisations with industrial control systems must urgently review.

Overview of the water systems hacked attacks

Beginning on 27 July 2026, utilities in at least seven US states reported cyber incidents to the FBI, with some organisations experiencing degraded operations. According to the FBI and Environmental Protection Agency (EPA), attackers remotely accessed operational technology by targeting publicly accessible Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers (PLCs). Once inside, they changed device IP addresses, set new passwords, and in some cases, modified the PLC ladder logic, making it impossible for operators to monitor or control water systems.

At least one affected utility discovered altered PLC project files after noticing inconsistencies in ladder logic, suggesting that attackers tampered with automation routines. Operational consequences included water pressure loss and even flooding. The Cybersecurity and Infrastructure Security Agency (CISA) stated that some utilities were forced to issue boil-water notices and revert to manual operations as a result of these attacks.

  • Attackers accessed internet-facing PLCs via remote connections
  • Device configuration, including IP addresses and passwords, was altered
  • Operators were locked out of monitoring and control interfaces
  • Physical impacts included pressure loss and flooding at several facilities
  • Some affected organisations issued public health advisories

Technical analysis: How the Rockwell PLC attacks unfolded

The attacks centred on remote access to Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs, targeting both Series A, B, and C variants. Notably, these devices were reachable from the public internet, sometimes through integrator-installed or undocumented cellular modems. The attackers did not exploit a specific software vulnerability (CVE), but rather took advantage of poor security practices such as direct internet exposure and weak or default credentials.

Attack sequence and indicators

  • Initial access: Attackers scanned for PLCs exposed to the internet, including those with unsecured cellular connections.
  • Configuration change: Once connected, they altered IP addresses and set new passwords, effectively locking operators out.
  • Project file tampering: In at least one case, attackers modified ladder logic and PLC project files, disrupting automated processes.
  • Operational disruption: The loss of visibility and control led to reduced water pressure, flooding, and forced manual intervention.

Technical guidance from CISA highlights the importance of monitoring for suspicious traffic on OT-specific protocols and ports, including EtherNet/IP (CIP 44818 and 2222), Siemens S7 (102), and Modbus/TCP (502). CISA has released STIX indicator packages (AA26-097A) containing network indicators and other artefacts relevant to this campaign, recommending organisations ingest these for detection and response.

Affected products and official response

  • Rockwell Automation Allen-Bradley MicroLogix 1100 PLCs: All internet-facing deployments targeted, versions unspecified.
  • Rockwell Automation Allen-Bradley MicroLogix 1400 PLCs: Series A, B, C internet-facing deployments targeted; Rockwell issued recovery steps for unknown password scenarios.

Rockwell Automation stressed that these PLCs are not designed for direct public internet connectivity and published recovery guidance for regaining access when passwords have been changed. The FBI and EPA issued a sector-wide public service announcement (I-073026-PSA) urging immediate removal of PLCs from internet exposure, enforcement of strong credentials, and use of access control lists to restrict communications.

Timeline of the coordinated cyberattacks

  • 26-27 July 2026: Over 30 community water systems in Minnesota targeted. Statewide incident response initiated.
  • 28 July 2026: Minnesota IT Services publicly acknowledges coordinated attack and response measures.
  • 30 July 2026: CISA issues alert to the sector; FBI/EPA PSA released detailing tactics and device targeting.
  • 31 July 2026: National reporting confirms at least seven affected states and ongoing federal investigation. Preliminary suspicion focuses on Iran-linked actors, though no formal attribution is made in the PSA.

Authorities have not publicly disclosed the names of all affected states. However, Minnesota officials confirmed more than 30 community systems were impacted within 48 hours, prompting a rapid statewide and federal response.

Current exploitation status and guidance

The campaign is confirmed to be ongoing, with active exploitation reported in at least seven states since late July 2026. Threat actors have not been officially identified in the federal public service announcement, but CISA and other US government advisories have warned of tactics commonly associated with Iranian-affiliated groups targeting internet-connected PLCs across critical infrastructure sectors. The attacks have forced some utilities to operate in manual mode and issue boil-water advisories to consumers.

CISA and the FBI/EPA have provided the following key mitigation steps for utilities and organisations operating similar systems:

  • Remove all PLCs and OT devices from direct internet exposure immediately
  • Enforce strong, unique passwords and disable default credentials
  • Use VPNs or secure gateways for remote access
  • Implement access control lists and IP allow-lists to restrict communication to authorised systems
  • Regularly monitor and review logs for suspicious network activity, especially on OT-specific ports
  • Maintain verified backups of device configurations and project files

Rockwell Automation and CISA both recommend that organisations follow the UK National Cyber Security Centre’s secure connectivity principles for OT, as referenced in the latest CISA alert, for any remote access requirements.

Why this matters for UK organisations

Although these attacks occurred in the United States, the methods used are directly relevant to UK organisations operating industrial control systems. Many UK water providers, manufacturers, and building managers utilise similar legacy PLCs and remote access setups. The US incidents demonstrate that simple exposure of PLCs to the internet, combined with weak authentication, can allow attackers to cause significant disruption without exploiting a software flaw. Organisations should act now to ensure their OT environments are not directly accessible from the internet and that robust authentication and network segmentation are enforced.

Originally reported by kens5.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call