{
  "id": 556743,
  "title": "degraded water operations",
  "url": "https://urgent.news/2026/08/11/degraded-water-operations",
  "topic": "world",
  "section": "World",
  "published": "2026-08-11T11:01:31.000Z",
  "source": {
    "name": "Rest of World",
    "slug": "restofworld-2",
    "url": "https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions?_bhlid=7f3dfd57fa27098288a42666a9bbe74b6532cbbc"
  },
  "original_language": "en",
  "account": "The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) have issued a public warning about cyber attacks targeting critical infrastructure systems. The attacks specifically target Operational Technology (OT) devices, particularly Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) such as MicroLogix 1100 and 1400 series. Since July 27, 2026, at least seven states have reported incidents to the FBI, and some of these actions have disrupted water operations.\n\nCyber actors have been able to remotely access internet-facing devices, changing IP addresses and passwords, leading to a loss of monitoring and control functionality. To mitigate the risk of compromise, the FBI and EPA advise removing PLCs from direct internet exposure using secure gateways and firewalls. They also recommend setting strong, unique passwords and implementing access control lists to restrict communication to authorized devices only.\n\nOnce compromised, the impact on operational facilities can vary depending on the type of function the PLC was configured for, the specific equipment, the device's capabilities, and the ability to switch to manual operations. At least one organization reported altered PLC project files due to discrepancies in ladder logic across multiple sites. Additionally, network setups provided by third parties may amplify the threat if vulnerable configurations exist across customer networks.\n\nThe FBI and EPA are working with affected organizations and have offered the following recommendations for critical infrastructure asset owners and operators. They urge any individuals affected by similar OT outages to contact their local FBI field office and file a complaint with the Internet Crime Complaint Center (IC3) at ic3.gov. Victims can also reach out to the Cybersecurity and Infrastructure Security Agency (CISA) through their 24/7 Operations Center at contact@cisa.dhs.gov or by calling 1-844-Say-CISA (1-844-729-2472). They should provide as much information as possible when reaching out.\n\nFor more details on mitigating threats to OT systems, victims are directed to previously released guidance documents. The FBI emphasizes that this information is provided for informational purposes only and does not endorse any specific commercial entities, products, or services mentioned within the document.",
  "summary": null,
  "key_points": [
    "FBI and EPA warn of cyber attacks targeting critical infrastructure systems.",
    "At least seven states report disrupted water operations since July 27, 2026.",
    "FBI advises removing PLCs from direct internet exposure to mitigate risk."
  ],
  "editors_take": "The warning by the FBI and EPA marks a heightened urgency for water operators to secure their systems, implying a significant escalation of cyber threats to critical infrastructure.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}