FBI and EPA alert: water PLC attacks spread to seven states
Second wave in 18 months escalates from defacement to operational disruption (pressure loss, flooding, manual-control reverts) while cybersecurity standards for 50,000 water systems remain voluntary.
TL;DR
The FBI and EPA issued a joint alert last week on cyberattacks targeting internet-exposed programmable logic controllers at water and wastewater utilities across at least seven states since July 27. Attackers used default credentials and unpatched legacy equipment to gain control, modifying ladder logic and locking operators out. Several utilities reported pressure loss, flooding, and reversion to manual control; one Minnesota community declared a local state of emergency. This is the second major water-sector attack wave in 18 months, and the escalation from screen defacement to operational disruption hasn't been met with binding federal cybersecurity requirements.
Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers, the small industrial computers that run pumps, valves, and treatment equipment. Some degraded operations materially: pressure loss, flooding, manual-control reversion, and one Minnesota community declaring a local state of emergency.
Nothing about these attacks required sophisticated methods. Attackers found controllers exposed to the public internet, many too old to receive security patches, and logged in. They changed IP addresses and passwords, locked operators out of their own equipment, and in at least one case modified the ladder logic controlling industrial processes. These aren't Hollywood hacks. The controllers sat exposed and undefended.
If this feels familiar, it should. In late 2023, Iranian-linked attackers compromised Unitronics PLCs at water facilities across several states, including the widely reported Aliquippa, Pennsylvania incident. CISA's Eric Goldstein called that episode a "clarion call" for basic cyber hygiene. The difference now is ambition: attackers have moved from defacing screens to disrupting operations across dozens of systems simultaneously, exploiting the fact that third-party integrators often deploy identical vulnerable configurations across many small utilities.
The structural problem isn't technical
The United States runs roughly 50,000 community water systems. Most are small, publicly funded, and operated by people whose primary job is keeping water safe and flowing, not defending industrial controllers from nation-state actors. The devices in question are often a decade or more old, and replacing them takes capital these utilities don't have. Cybersecurity rules for the sector remain largely voluntary.
Attackers understand these economics. The defenses that work cost little and require no exotic technology. The FBI and EPA guidance is sound and every water utility should act on it now: get controllers off the public internet, fix default passwords, restrict device-to-device communication, lock physical key switches, and practice manual operations. Nearly every utility believes its PLCs aren't internet-exposed right up until an inventory proves otherwise, forgotten cellular modems and integrator-installed remote access are the rule, not the exception.
The detection gap
Every attack like this follows the same pattern: configuration changes, password resets, modified project files. Each action creates a network signal before operations degrade. In this most recent wave, one victim only noticed discrepancies in ladder logic across multiple sites. Catching intrusions shouldn't depend on a sharp-eyed engineer having a good day. Continuous OT monitoring exists to surface those signals in minutes rather than days, and that difference is the difference between an incident report and a boil-water notice.
Water systems have the least margin for error and too often the fewest resources to defend themselves. The FBI and EPA have told operators plainly what's happening and what to do about it. For the third time in three years, attackers are testing whether anyone follows through.
Published ·Deep Fathom