The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed
On 30 July 2026, the FBI and the Environmental Protection Agency issued joint product security advisory I-073026-PSA covering a campaign against water and wastewater systems. Incidents were reported from 27 July onward, across at least seven states, with some reporting counting more. The advisory named the target class directly: Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers.
What the controllers do, and where they were sitting
MicroLogix 1100 and 1400 units are compact controllers used for pump control, valve scheduling and the local logic that keeps a distribution network in balance. They are installed in pump houses, lift stations and remote sites, which is exactly why they end up on cellular links and small remote offices rather than in a hardened data centre.
The advisory's core finding is about placement rather than about a novel exploit. Internet-exposed controllers were reachable on their native industrial protocols, and the campaign scanned for them at scale.
What operators observed
The reported operational effects were physical. Water pressure dropped, and in some cases flooding followed because the logic governing pump and valve behaviour had been altered. When a utility loses pressure, the consequences extend past inconvenience: pressure loss creates the conditions for contamination to enter a distribution system, and utilities have responded by issuing boil-water notices.
The tradecraft described in subsequent reporting is a mix of opportunistic scanning and deliberate manipulation. Attackers identified exposed controllers, changed device passwords and IP addresses, disconnected supervisory systems, and in some cases modified ladder logic, which is the program that governs how the equipment behaves. Multiple protocols were used in the scanning effort, including the ports associated with Modbus and with other industrial protocols such as 502, 102 and 44818.
There is also an identity angle that deserves attention. Reporting describes attackers reaching cellular modems over SSH, which places the intrusion on the communications infrastructure that carries the control traffic rather than only on the controller. An attacker holding a modem can observe and shape what the SCADA layer sees.
The tooling question
Reporting cites the use of AI-written exploit scripts and of the snap7 and python-snap7 libraries against Siemens S7 hardware. That detail matters less for the specific targets than for what it signals about effort. The expensive part of OT attack development has historically been the engineering knowledge required to craft valid protocol traffic and to reason about process behaviour. Libraries and generated code compress that cost. The result is that a larger population of attackers can reach equipment that was previously protected mainly by obscurity and by the difficulty of speaking its protocols correctly.
The account and money problem
Alongside the advisory, the EPA announced 11.75 million dollars through its drinking water infrastructure resilience and sustainability grant programme, directed at ten projects across six states.
The figure is worth putting in perspective rather than dismissing. Water utilities are among the most resource-constrained operators of critical infrastructure, frequently serving small populations with single-digit IT and OT staff. The gap between what a coordinated campaign can attempt and what a small utility can defend against is not a technology gap. It is a funding and staffing gap, and grant money is the mechanism that closes it, slowly.
The controls the advisory actually recommends
The advice from the FBI and EPA is deliberately unglamorous. Keep PLCs off the public internet. Put remote access behind a VPN or a secure gateway. Change default credentials. Restrict communications to known devices only.
CISA added an OT-specific layer that is worth adopting even where the technical control is awkward. Maintain a real asset inventory of OT devices, because an organisation cannot protect equipment it has not catalogued. Add authentication where industrial protocols offer it, including Modbus and SNMP, since both historically assume a trusted network. And where AI agents or automated tooling are given any authority over industrial systems, require human approval and full audit logging, because autonomous changes to process control are precisely the action an operator cannot afford to discover after the fact.
What to do in the next thirty days
Map which of your controllers have any route to the internet, including indirect routes through cellular modems, remote-access gateways and vendor support links. That exercise is uncomfortable and it is the one that matters most, because the campaign depended on reachability rather than on a specific vulnerability.
Then change credentials on every controller that has one, and stop treating the network it sits on as implicitly trusted. Where a controller cannot be isolated, put a monitoring point in front of it and alert on configuration changes, password changes and logic downloads, which are the events that precede physical consequence.
Limitations
The advisory summarises incidents across multiple utilities and does not publish a full technical timeline for any single one. Reported state counts vary between sources, and some operational details come from subsequent analysis rather than from the advisory itself. This article distinguishes what the agencies stated from what later reporting added, and does not attribute the campaign to a specific actor, because the public record does not.
References
- FBI and EPA joint advisory on water and wastewater sector PLC intrusions (I-073026-PSA): https://baijiahao.baidu.com/s?for=pc&id=1876029752785530238
- US water systems hit: PLCs remotely controlled: https://m.11467.com/blog/d19515427.htm
- Critical infrastructure case review: https://blog.securemymind.com/tag/%E5%85%B3%E9%94%AE%E5%9F%BA%E7%A1%80%E8%AE%BE%E6%96%BD/page/3
Top comments (0)