The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed
The FBI and EPA Warning on Water-Sector PLCs: What the MicroLogix Campaign Exposed On 30 July 2026, the FBI and the Environmental Protection Agency issued joint product security advisory I-073026-PSA covering a campaign against water and wastewater systems. Incidents were reported from 27 July onward, across at least seven states, with some reporting counting more. The advisory named the target…
On 30 July 2026, the FBI and the Environmental Protection Agency (EPA) jointly issued a product security advisory (I-073026-PSA) targeting Programmable Logic Controllers (PLCs) used in water and wastewater systems. The advisory specifically mentioned Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series PLCs. These compact controllers are used for pump control, valve scheduling, and local logic in distribution networks, often installed in pump houses, lift stations, and remote sites.
They are typically connected to cellular links and small remote offices rather than hardened data centres. The core finding of the advisory revolves around the improper placement of these controllers, which were found to be reachable on their native industrial protocols when exposed to the public internet. This allowed attackers to scan for them at scale, leading to physical operational effects such as reduced water pressure and, in some cases, flooding due to altered pump and valve behavior.
Utilities responded by issuing boil-water notices to address the contamination risk. The attackers used multiple scanning methods, including Modbus and industrial protocols such as 502, 102, and 44818, often reaching cellular modems over SSH to observe and shape the control traffic seen by the Supervisory Control and Data Acquisition (SCADA) layer.
The use of AI-generated exploit scripts and libraries like snap7 and python-snap7 was also noted, which lowered the barrier for attackers to reach previously protected equipment. The advisory emphasized that the primary issue was the exposure of these controllers to the internet rather than a novel exploit. Therefore, the recommendations from the FBI and EPA were straightforward: isolate PLCs from the public internet, use secure remote access methods, change default credentials, restrict communications to known devices, maintain a proper inventory of OT devices, and implement authentication where applicable.
Additionally, organizations were advised to approve human intervention for any autonomous changes to industrial systems to prevent unauthorized process control modifications.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.