On July 30, 2026, the FBI and EPA issued a joint public service announcement warning water and wastewater operators that malicious cyber actors are actively attacking operational technology (OT) devices exposed to the internet. Since July 27, utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. The observed attacks targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs), but the agencies are clear that any brand of internet-facing controller faces the same risk.
The consequences were operational, not just informational. After remotely accessing internet-facing PLCs, the attackers changed device IP addresses and turned on or changed passwords, locking operators out of their own equipment. The result was a loss of view and, in some cases, a loss of control of connected equipment. At least one utility discovered modified PLC project files, caught only because the ladder logic no longer matched across the utility’s other sites.
Reported operational effects included loss of pressure and flooding. Pressure loss in a water system is not a minor event: it can allow untreated groundwater to seep into distribution piping, turning a cybersecurity incident into a potential public health issue. How badly each utility was hit depended on whether the compromised PLC was monitoring or controlling equipment, which functions it supported, and, critically, whether staff could fall back to manual operation.
Nothing about these intrusions was exotic. The attackers did not need zero-day exploits or nation-state tooling. They reached controllers that were directly exposed to the public internet, often through cellular modems at remote sites, and used the devices’ own configuration features against their owners: changing IP addresses to break communications and setting passwords to block legitimate access.
The FBI also noted a multiplier effect: several victims had similar network setups delivered by the same third parties. When an integrator deploys the same vulnerable architecture across many customers, one successful attack becomes a repeatable playbook. Who designs and maintains your OT network matters as much as the equipment in it.
The joint advisory lays out specific defensive measures. Every one of them is achievable for a utility of any size:
None of this guidance is new. The weaknesses exploited in July are exactly what established industrial cybersecurity standards are designed to eliminate:
A control system engineered and maintained against these standards does not present internet-facing PLCs, default credentials, or flat networks to an attacker. The July campaign succeeded where those fundamentals were missing.
Start by knowing where you stand. Much of the following can be checked quickly without breaking the budget:
Then recognize the harder truth: these controls decay quietly. Firmware falls behind, firewall rules accumulate exceptions nobody remembers approving, accounts outlive the people who used them, and backups stop getting verified. Sustaining this posture requires a recurring cadence with owners and dates, and that is precisely where lean utility staff get stretched past their limits.
Vertech’s Industrial Networking & Cybersecurity (INCS) team designs SCADA systems and industrial control networks to be reliable and secure from the start, built around the same standards referenced above. That means ISA/IEC 62443-aligned assessments and network architecture, segmented networks with brokered remote access by default, firewall rules and ACLs configured as standard rather than on request, hardened remote connectivity for cellular and field sites, robust backup solutions, and unique credentials set at commissioning. The cookie-cutter integrator architectures that let attackers repeat their success across utilities are exactly what this discipline prevents.
A hardened network on day one is not the same as a hardened network in month eighteen. Vertech’s Managed Services team provides continuous operational support for SCADA and ICS environments, closing the gap between initial design and the quiet drift that leaves systems exposed later. That includes ongoing monitoring of controller configurations and credentials for exactly the changes made in these attacks (unauthorized IP modifications, password resets, and logic alterations), regular confirmation that no device has become internet-facing, sustained segmentation and access control, tested offline backups, and scheduled firmware, rule, and account reviews handled as standard practice rather than reactive projects.
For utilities running with small staff and limited cybersecurity bandwidth, the same conditions that left many of the targeted systems exposed, Managed Services converts the guidance above into a living program. Vertech owns the recurring reviews, cleanup, validation, and restore testing that lean teams cannot sustain alone, while your operators stay focused on water quality and system performance.
The July 2026 campaign required no sophistication, only targets that were exposed, unhardened, and unwatched. The FBI and EPA have told the sector exactly what to fix. If you want help finding your exposure, engineering it out, or keeping it out for good, Vertech’s INCS and Managed Services teams do this every day for water and wastewater utilities. Reach out and we will start with an honest look at where you stand.
If you experience a similar incident, report it: contact your local FBI field office, file a complaint at ic3.gov, or reach CISA’s 24/7 Operations Center at 1-844-SAY-CISA. Source: FBI/EPA Public Service Announcement, July 30, 2026.