Morning Overview

Water utilities in at least seven states told the FBI that hackers had begun disrupting their operations

Water and wastewater utilities in at least seven states have reported to federal authorities that intruders reached into the industrial controls running their systems and, in some cases, degraded the flow and treatment of drinking water. The incidents, disclosed in a warning from the FBI and the Environmental Protection Agency, centered on internet-exposed control hardware that attackers were able to reconfigure remotely. The events add municipal water systems to the growing list of critical infrastructure being probed and disrupted through digital means.

The FBI and EPA public service announcement

The two agencies laid out the threat in a public service announcement issued July 30, 2026, warning critical-infrastructure owners that malicious cyber actors were attacking operational technology devices. According to the notice, utilities in at least seven states had reported incidents since July 27, and some of that activity degraded water operations. Officials said they were engaging directly with affected organizations while urging the wider sector to harden its defenses.

The alert focused on a specific class of equipment: Rockwell Automation’s Allen-Bradley programmable logic controllers, particularly the MicroLogix 1100 and 1400 series. While investigators said they had observed the behavior only with those Rockwell devices, they cautioned that similar risks apply to other branded controllers configured the same way.

How attackers manipulated the programmable logic controllers

Programmable logic controllers are the small, rugged computers that automate physical processes, opening valves, running pumps and monitoring pressure across a treatment plant. The agencies said that after remotely accessing internet-facing controllers, the actors changed the devices’ IP addresses and set new passwords, locking operators out and stripping away their ability to see and command the equipment.

The tampering went beyond access. At least one organization reported that project files running on its controllers had been modified, a discovery made after staff noticed discrepancies in the ladder logic that governs how the machines behave across several sites. The FBI also warned that where multiple utilities shared similar network setups provided by the same third parties, a single successful technique could be replicated against many victims at once.

Pressure loss, flooding and a return to manual operation

The operational effects reported to the FBI included loss of pressure and flooding. Those are not abstract inconveniences: a drop in water pressure can allow untreated groundwater to seep into distribution pipes, creating a potential contamination pathway, while flooding points to equipment being driven outside its safe parameters.

How badly a given facility was affected depended on several factors, the agencies said, including whether the compromised controller was merely monitoring a process or actively controlling it, the specific device model involved, and whether operators retained the ability to switch to manual control. Plants that could revert to hands-on operation were better positioned to keep water moving while they worked to expel the intruders.

The agencies stressed that no single facility’s experience predicts another’s, because the same intrusion technique can produce very different outcomes depending on how a plant is engineered and staffed. That variability was one reason the warning urged the entire sector to act rather than only the utilities already hit.

Why internet-exposed control systems are the weak point

The root vulnerability was exposure. Control devices that face the public internet can be located and reached by anyone, and when they are protected by weak or default credentials, they become inviting targets. The agencies noted that end-of-life hardware, which no longer receives security patches, is routinely singled out by attackers for exactly this reason.

Federal investigators did not publicly name who was behind the intrusions, and the announcement stopped short of attributing the activity to any specific actor or government. The emphasis instead fell on the shared characteristics of the victims, whose systems were reachable from the open internet and, in several cases, built on comparable configurations that let one intrusion multiply into many.

The water sector’s exposure is compounded by structural realities. Many community systems are small, run on tight budgets and rely on aging equipment that was never designed to sit on the public internet, yet remote connectivity has been bolted on to allow off-site monitoring. That mismatch between decades-old control hardware and modern network exposure is what repeatedly turns utilities into accessible targets, and it is why the agencies elevated removing controllers from direct internet reach above nearly every other recommendation.

The mitigations regulators are urging utilities to adopt

The core recommendation is to remove controllers from direct internet exposure, routing any remote access through a secure gateway that mediates and monitors every connection rather than leaving the hardware openly reachable. The agencies also urged operators to secure cellular field modems with strong authentication and to keep logs that can flag suspicious activity early.

Additional guidance included setting complex, unique passwords, using access-control lists so that only authorized devices can communicate with the controllers, and placing physical key switches into the run position to block unauthorized changes to a device’s logic and firmware. Operators were further advised to review project files against known-good copies, maintain the ability to run systems manually, and plan replacements for aging equipment before it reaches end of life. Utilities that experience similar outages were directed to contact their local FBI field office, file a report with the Internet Crime Complaint Center, and notify the cybersecurity agency’s operations center.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview