WASHINGTON — The Federal Bureau of Investigation and the U.S. Environmental Protection Agency are warning owners and operators of water and wastewater facilities that malicious cyber actors are actively targeting internet-connected industrial control systems, causing operational disruptions at utilities in multiple states and highlighting growing cybersecurity risks facing the nation’s critical infrastructure.
According to a joint Public Service Announcement released Thursday, cyberattacks reported since July 27 have affected water and wastewater utilities in at least seven states. Federal officials said some of the incidents have already degraded normal operations after attackers gained unauthorized remote access to internet-facing operational technology devices.
The FBI said the activity observed thus far has specifically involved Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs). While investigators have not confirmed attacks against other manufacturers, officials cautioned that organizations using any internet-exposed programmable logic controllers should review their security posture immediately because similar attack methods could be adapted to other industrial control systems.
Programmable logic controllers are specialized industrial computers used to automate and manage physical processes inside critical infrastructure facilities. Within water and wastewater systems, PLCs commonly regulate pumps, valves, treatment equipment, pressure systems, chemical processes, and other operational functions that allow utilities to safely deliver drinking water and manage wastewater treatment.
According to the FBI and EPA, attackers remotely accessed exposed PLCs and changed device Internet Protocol (IP) addresses and passwords, effectively preventing operators from monitoring or controlling connected equipment. At least one organization reported modified PLC project files after identifying ladder-logic discrepancies across several sites.
Federal officials said several affected organizations shared similar network architectures provided by third-party vendors, raising concerns that attackers may be able to exploit common system configurations across multiple utility customers using comparable remote-access environments.
The operational consequences have extended beyond simple loss of visibility into industrial systems.
The FBI reported that operational effects included pressure loss and flooding after operational technology devices were compromised. Officials warned that pressure loss within drinking water systems can create conditions allowing untreated groundwater to enter distribution lines, potentially increasing public health risks if not quickly identified and corrected.
The severity of each incident depended largely on how individual PLCs were configured. Facilities using the devices only for monitoring generally experienced fewer operational disruptions than those relying on PLCs to directly control pumps, valves, and other automated processes. Utilities capable of quickly switching to manual operations were also able to reduce operational impacts while restoring affected systems.
The warning reflects a broader trend observed throughout the critical infrastructure sector, where cybercriminals and other malicious actors target operational technology rather than traditional information technology systems. Unlike office networks, operational technology directly controls physical equipment responsible for delivering essential services such as electricity, drinking water, wastewater treatment, manufacturing, and transportation.
To reduce the risk of compromise, the FBI and EPA strongly recommend that organizations remove programmable logic controllers from direct internet exposure and instead route remote access through secure gateways protected by firewalls. Agencies also recommend implementing strong, unique passwords, enabling logging on remote access devices, restricting communications through access control lists, securing cellular modems used for remote connectivity, and deploying network architectures that isolate operational technology from public internet access whenever possible.
Federal officials further urged organizations to place both physical and software key switches into operational “run” mode after maintenance is completed to prevent unauthorized modifications to device logic and firmware. Operators should also routinely validate PLC project files against known-good configurations, verify backups before restoring systems, and review logs from connected workstations, human-machine interfaces, and communication devices for signs of unauthorized activity or lateral movement.
The agencies also stressed the importance of maintaining the ability to manually operate critical infrastructure during a cyber incident. Business continuity plans, disaster recovery procedures, software backups, standby systems, and manual control capabilities should be regularly tested so utilities can continue delivering essential services even if automated systems become unavailable.
Another significant concern identified in the advisory involves end-of-life industrial hardware. Devices that no longer receive manufacturer security updates or software patches frequently become attractive targets because newly discovered vulnerabilities often remain permanently uncorrected. Federal officials recommend utilities maintain long-term replacement plans, track aging equipment, and isolate unsupported systems whenever immediate replacement is not possible.
The FBI is asking organizations experiencing similar operational technology incidents to contact their local FBI field office and submit reports through the Internet Crime Complaint Center (IC3). Agencies are encouraging victims to preserve information including programmable logic controller model numbers, serial numbers, IP addresses, and records of suspicious network activity to assist investigators.
The FBI and EPA continue working with affected organizations, while the Cybersecurity and Infrastructure Security Agency has also warned critical infrastructure operators to review and strengthen their operational technology security controls.
This advisory serves as another reminder that cyberattacks against critical infrastructure can carry real-world consequences. While many cybersecurity incidents involve stolen information or disrupted business operations, attacks against operational technology have the potential to affect essential public services, underscoring the importance of securing industrial control systems that millions of Americans depend upon every day.
Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Environmental Protection Agency (EPA) – Top Cyber Actions. (Free Download)
Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Environmental Protection Agency (EPA) – Incident Response Guide: Water and Wastewater Sector. (Free Download)
UK National Cyber Security Centre (NCSC), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security, U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. Federal Bureau of Investigation (FBI), Germany’s Federal Office for Information Security (BSI), Netherlands’ National Cyber Security Centre (NCSC-NL), and New Zealand’s National Cyber Security Centre (NCSC-NZ) – Secure Connectivity Principles for Operational Technology (OT) (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



