Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.2026-08-014 min2026networkthreats
4 min read
Read format

FBI Says Exposed MicroLogix PLCs Disrupted Water Operations

Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.

By Justin Howe
Editorial view of a compact PLC and cellular gateway inside a water plant control cabinet, with pipes and a pump visible behind it.

The FBI and EPA say attackers have remotely altered internet-facing controllers at water and wastewater utilities in at least seven states since July 27. The affected devices were Rockwell Automation MicroLogix 1100 and 1400 programmable logic controllers. Some incidents degraded water operations.

The agencies’ July 30 alert describes a direct operating consequence. After reaching exposed PLCs, the actors changed IP addresses and enabled or changed passwords. Operators lost monitoring and control. Reported effects included loss of pressure and flooding, although the alert does not identify utilities, quantify each effect, or attribute the activity.

Changed network settings cut operators off from equipment

A PLC may only monitor equipment, or it may control pumps, valves, and other physical processes. That distinction determined the impact in the incidents reported to the FBI. The alert says attackers changed network and authentication settings on the controller, causing loss of visibility and, in some cases, loss of function for connected equipment.

At least one organization found modified PLC project files after operators noticed ladder-logic differences across several sites. The agencies also found similar third-party network setups across multiple victims. They say those repeated designs may have allowed one workable access method to succeed against several customers.

The alert documents direct internet exposure, remote access, configuration changes, and operational disruption. It names no exploit chain or product vulnerability used in these incidents. Treating this as a patch-only event would skip the path the agencies actually documented.

Layered diagram showing public access reaching a MicroLogix PLC, settings and project files changing, and operators losing monitoring or control of a water process.

Figure details

An external connection reaches a MicroLogix 1100 or 1400 PLC that is directly exposed to the internet. The reported actors changed controller IP addresses and passwords, and at least one organization found modified PLC project files. Those changes separated the operator's HMI or workstation from the controller and caused loss of monitoring or control. Operational effects varied with the PLC's assigned function and included pressure loss and flooding. A secure gateway, an allowlist, Hard Run mode after logic validation, and a tested manual operating path interrupt different parts of this sequence.

Project files and connected devices define the investigation

Restoring an IP address or password does not prove the controller is trustworthy. The FBI and EPA direct operators to compare the running project with known-good logic, validate reusable logic and input/output configuration, and inspect connected modems, human-machine interfaces, and workstations for lateral movement. A backup also needs review before restoration because it may contain altered logic.

The agencies recommend placing physical and software key switches in Run mode to block unauthorized changes. Operators should first validate the loaded project because switching modes can lock the current file into place. Rockwell Automation’s PN1015 advisory separately recommends Hard Run for multiple MicroLogix 1100 and 1400 risks and says control devices should not be reachable from the internet.

Age complicates the response. Rockwell lists the MicroLogix 1100 as discontinued since April 30, 2022. The federal alert calls for a rolling 12-month end-of-life forecast, with each system tracked by product, owner, location, and retirement date. Delayed replacements need isolation and a firm decommission date.

Water operators should prove both logic and access are controlled

Inventory every MicroLogix 1100 and 1400, including units behind cellular modems or third-party remote-access equipment. Remove inbound internet exposure and require a monitored gateway. Restrict PLC communication to expected control-system devices with firewall rules or access control lists. Confirm unique credentials and record the approved remote-access path.

Then compare the running controller project, ladder logic, and input/output configuration with a known-good source. Check PLC, modem, HMI, and workstation logs and configurations for unexplained connections or changes. After the loaded project is validated, place the controller in Run or Hard Run as supported. Test the manual operating procedure while normal monitoring is available.

Close the incident only when the PLC has no direct public path, its allowlist matches the approved control architecture, the running logic matches a trusted baseline, connected devices show no unexplained access, credentials have been replaced, and operators have demonstrated safe manual control. Missing project baselines, modem logs, or connected-device evidence keep the incident open.

Primary sources

Continue reading

Article figurePinch or double-tap to zoom, then drag to pan.