Water System Cyberattacks:What Operators Should Check Now
Federal and state agencies reported cyber activity affecting water-utility operational technology in late July 2026. The FBI and EPA said actors remotely accessed internet-facing Rockwell MicroLogix 1100 and 1400 PLCs, changed IP addresses and passwords, and disrupted monitoring or control.
Start with what's confirmed.
The July 2026 notices document operational impacts. They do not establish one universal attack path or a definitive responsible actor.
Internet-facing PLCs were accessed.
The FBI and EPA reported malicious access to Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs.
Device settings were changed.
Actors changed IP addresses and passwords, causing losses of monitoring or control. Modified PLC project files were also reported.
Multiple utilities were affected.
Minnesota IT Services said more than 30 community water systems were targeted. The FBI said utilities in at least seven states reported incidents.
Operational effects were real.
Reported effects included loss of monitoring or control, pressure loss, flooding, and the need to move some operations to manual control.
The July 30, 2026 federal notice named no responsible actor. Subsequent reporting described an investigation into a possible foreign link without definitive attribution at that time.
An incident can become an operations problem fast.
The impact depends on what the PLC monitors or controls, the equipment and process involved, and whether the utility can safely switch to manual operations.
Lose visibility
Operators may lose the normal view of connected equipment and the information used to monitor operations.
Lose control or access
Connected equipment may stop responding through normal controls, while changed passwords or IP addresses can lock authorized staff out.
Create pressure risk
The FBI said pressure loss could allow untreated groundwater to enter pipes, making pressure events both operational and public-health concerns.
Complicate recovery
Utilities may need to compare running programs with known-good logic and verify backups before restoration.
Force manual operation
Utilities may need to operate manually while containment, investigation, recovery, and coordination continue.
The first sign may look operational. Public reporting described utilities responding to a malfunctioning well or interrupted device communications before the full cause was known.
Trace the actual path into the control environment.
Direct internet exposure is one path. A field PLC may also sit behind systems that provide monitoring, control, communications, or remote maintenance.
What remote, vendor, internet, cellular, or backup paths can reach the environment?
Which firewall, gateway, or IT/OT boundary accepts or passes those connections?
Which SCADA, HMI, or engineering workstation can send information or commands downstream?
Does a radio or cellular headend provide a path to remote sites?
Which remote PLCs, RTUs, pumps, or stations receive commands from those upstream systems?
Are there temporary laptops, removable media, dual-connected systems, or maintenance links outside the normal diagram?
Five things water utilities should do now.
The July 30, 2026 FBI/EPA PSA recommends removing PLCs from direct internet exposure, securing cellular modems, restricting network access, validating running logic, checking connected systems, testing manual operations, and planning for end-of-life equipment.
Find exposed and connected assets
Inventory PLCs, HMIs, modems, gateways, workstations, and remote sites. Identify direct internet exposure and every upstream route into the control environment.
Remove direct internet exposure
Don't leave PLCs directly reachable from the public internet. Broker required remote access through a secured, monitored gateway or jump host.
Restrict access and changes
Use unique passwords, tightly scoped firewall or ACL rules, and secure cellular modems with strong authentication and logging.
Validate logic and investigate upstream
Compare running PLC projects with known-good logic. Review available logs and configurations on connected modems, HMIs, workstations, and gateways.
Test manual operation and recovery
Practice safe manual operation, verify backups before restoration, test communications, and plan replacement or isolation of end-of-life devices.
Can the people responsible answer these questions?
Use these with operators, IT staff, the controls integrator, utility leadership, and the governing board.
Do we have a current list of PLCs, HMIs, radios, modems, workstations, gateways, and remote sites?
Do we know every route that can carry data or commands into the control environment?
Do we know who can change PLC programs, passwords, addresses, and remote-access settings?
Would we notice an unknown system communicating with control equipment or an unexpected configuration change?
Is manual operation documented and tested under realistic conditions?
Are backups current, protected, tested, and verified as known-good before restoration?
Where CrunchAtlas fits.
CrunchAtlas works alongside operators, integrators, MSPs, and existing security tools. It can add passive network visibility, investigation, and evidence without actively probing operational systems.
Network Detection and Response
Use passive network evidence to identify and investigate suspicious activity on supported IT and OT segments without actively probing operational systems.
Explore NDR → 02Alert Investigation
Work security signals into an investigated case with affected systems, evidence, a verdict, confidence, and recommended next steps.
Explore Alert Investigation →Continue into the water industry page, platform, or related operator guidance.
Water utility PLC and SCADA security, answered.
Are PLCs safe if they aren't directly connected to the internet?
Not automatically. Direct exposure is a major risk, but a PLC may still be reachable through an HMI, engineering workstation, gateway, modem, vendor connection, or another trusted system upstream.
Does a private radio network isolate remote sites?
It can reduce direct exposure. The utility still needs to secure the radio headend, the system sending commands, any remote-management path, and every network that can reach those systems.
What does air-gapped actually mean?
In this guide, air-gapped means the control environment has no direct or indirect network connection to an outside network. Remote access, modems, dual-connected computers, and other network bridges mean it isn't air-gapped. Maintenance laptops and removable media still need controls even without a permanent network connection.
Is a firewall enough to protect the control network?
No single control is enough. The important questions are which traffic is allowed, which devices are trusted, whether rules are limited to operational need, and whether access is logged and reviewed.
Does the controls integrator own cybersecurity?
Only if the scope and responsibilities say so. The utility should document who owns passwords, remote access, firewall rules, backups, logging, PLC changes, incident response, and notification duties.
Would an alarm always reveal a cyber incident?
No. If the HMI, communications path, or monitoring system is affected, the alarm may be missing, delayed, or untrustworthy. Operators need another way to confirm field conditions.
Are manual operations and backups enough for recovery?
Only if they've been tested and verified. Manual procedures need workable staffing, site access, communications, and safety limits. Backups need to be current, protected, and checked against approved logic before restoration.
Primary guidance
This page separates confirmed agency reporting from CrunchAtlas operator guidance and illustrative architecture.
Additional reporting is linked where it supports a specific point. Architecture and operating conditions vary by utility.
Know what's connected. Know who can change it. Know how you'll keep operating.
Bring us the architecture, telemetry, or incident evidence you already have. We'll show you where CrunchAtlas fits alongside your operators and existing providers.
The utility and its authorized partners remain responsible for operational, engineering, regulatory, and consequential response decisions.