America’s Water Infrastructure Is Under Cyberattack

Aug 18, 2026

 America’s Water Infrastructure Is Under Cyberattack— And This Is an Operational Issue, Not Just an IT Issue

The FBI and EPA have issued a warning to U.S. water and wastewater utilities following cyberattacks against internet-facing operational technology.

Since July 27, 2026, incidents have been reported by utilities in at least seven states. The FBI specifically identified internet-exposed Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs).

Attackers gained remote access and changed PLC IP addresses and passwords, causing operators to lose monitoring and, in some cases, control of equipment. The FBI reports that operational consequences have included loss of water pressure and flooding. At least one affected organization also identified discrepancies in PLC ladder logic.

For controls engineers, programmers, integrators, utility managers, and municipal leaders, the message is important:

A PLC should not be treated like an ordinary internet-connected device.

The FBI has not publicly identified the specific protocol or vulnerability used for initial access. However, these controllers support industrial Ethernet communications, and the MicroLogix 1400 can support EtherNet/IP, Modbus TCP/IP, DNP3 over IP, and an embedded web server depending on configuration.

Utilities should therefore know exactly:

• Which PLCs are reachable from external networks
• Which Ethernet services and protocols are enabled
• Whether inbound connections are exposed
• Who is authorized to modify PLC configurations and logic
• Whether firewall and access-control rules restrict communications to known systems
• Whether cellular modems and remote-access paths are properly secured
• Whether known-good PLC programs and configurations are backed up and validated
• Whether operators can safely transition to manual operation
• Which controllers are approaching or beyond end-of-life support

The FBI and EPA's primary recommendation is straightforward: remove PLCs from direct public internet exposure. Remote access should be mediated, authenticated, monitored, and controlled through appropriate security architecture.

Water cybersecurity is no longer simply an information-technology concern. When cyber access reaches operational technology, a digital intrusion can become a physical infrastructure event.

Protecting America's water systems requires cybersecurity professionals, PLC programmers, engineers, operators, integrators, manufacturers, regulators, and utility leadership working from the same operational-security framework.

Critical infrastructure deserves critical-infrastructure-grade protection.