More Than 100 U.S. Water Systems Were Targeted in July
On August 26, the Cybersecurity and Infrastructure Security Agency (CISA) disclosed malicious cyber activity targeting more than 100 internet-exposed systems in the U.S. Water and Wastewater Systems sector during July 2026. A common target was a programmable logic controller (PLC) connected directly to a cellular modem.
CISA Internet Exposure Reduction Guidance →
Directly exposed PLCs give attackers a short path into operational technology. Water operators should remove unnecessary internet exposure and maintain visibility across the remote access, cellular, vendor, and other connections that remain.
CrunchAtlas passively monitors OT network activity through our sensor or security data already in place, without actively probing PLCs or control equipment.
What Happened to the Water Systems
On July 30, the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) warned that water and wastewater utilities in at least seven states had reported cyber incidents involving internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs.
Attackers remotely accessed the controllers, changed IP addresses and passwords, and disrupted monitoring and control. The FBI also reported operational effects including loss of pressure and flooding.
FBI and EPA Public Service Announcement, July 30, 2026 →
The incidents show how quickly a cyber event can become an operational problem when attackers can reach control equipment directly. Changes to a PLC can affect the operator's ability to see and control the physical process.
What Water Operators Should Check
CISA, the FBI, and EPA are recommending that operators reduce direct internet exposure and place necessary remote connections behind controlled access.
For water and wastewater environments, the immediate work includes:
Inventory PLCs, HMIs, RTUs, cellular modems, remote-access systems, and other operational technology reachable from the internet.
Identify remote connections maintained by vendors, integrators, managed service providers, and other third parties.
Remove direct internet access where it is not operationally necessary.
Put required remote access behind a secure gateway, firewall, VPN, jump host, or another centrally managed access point.
Replace default or weak credentials, update supported systems, and restrict communications to authorized systems.
Review network activity around PLCs, modems, HMIs, and connected workstations for unauthorized access or unexpected changes.
FBI and EPA Public Service Announcement →
Exposure is only part of the investigation. If a PLC's IP address changes or an unexpected system connects to it, operators need to understand what communicated with the controller, what happened around the same time, and whether related activity appears elsewhere in the environment.
CrunchAtlas builds that context around suspicious activity so operators can investigate the event as a whole rather than working from an isolated alert.
The Water Attacks Are Part of a Larger PLC Problem
The July water incidents were followed by another federal warning involving PLCs used across U.S. critical infrastructure.
On August 19, the National Security Agency (NSA), CISA, FBI, Department of Energy, EPA, and other partners warned that cyber actors were targeting U.S.-based Siemens S7 Series PLCs. The advisory described AI-generated exploitation scripts disguised as legitimate monitoring tools and activity affecting sectors including water, energy, manufacturing, chemicals, and food and agriculture.
NSA: Active Threats Targeting Siemens S7 Series PLCs, August 19, 2026 →
Read our breakdown of the Siemens S7 advisory →
The Rockwell incidents and Siemens warning involve different equipment, but the risk is similar: exposed or poorly protected controllers put attackers closer to the physical process.
In water systems, that can mean loss of monitoring, loss of control, pressure disruption, or flooding.
After the Exposed PLC Is Removed
Taking a PLC off the public internet removes an obvious attack path, but remote access, vendor connections, engineering workstations, cellular communications, and other OT systems still remain.
Operators need visibility into what happens across those connections.
Unexpected PLC communications, unusual remote access, or configuration changes should be investigated with the surrounding network activity and systems involved.
That helps determine whether the activity is routine, misconfigured, unauthorized, or part of a broader intrusion.
How CrunchAtlas Helps
CrunchAtlas passively monitors OT activity through our sensor or data already in place, without actively probing PLCs or control equipment.
When suspicious behavior appears, CrunchAtlas connects the systems, communications, timing, and supporting evidence into one investigation.