HomePolitics

Federal Cyber Warning Issued After Attacks Hit Utility Systems Across Seven States

Federal authorities issued a public service announcement Thursday warning critical infrastructure operators about ongoing cyberattacks targeting water and wastewater utilities across at least seven states.

According to the joint alert from the Federal Bureau of Investigation and the Environmental Protection Agency, malicious cyber actors have been targeting internet-exposed programmable logic controllers since July 27, 2026.

The attacks specifically focus on Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series devices, though officials noted that similar vulnerabilities may exist in other brands of control hardware.

The intruders gain remote access to internet-facing controllers, then alter device configurations by setting new passwords and modifying IP addresses. These changes cause utility operators to lose both visibility and control over connected equipment. In some instances, affected facilities reported altered project files and discrepancies in ladder logic across multiple sites.

FBI
FBI

The disruptions have directly impacted water operations in several locations, resulting in loss of pressure and localized flooding. Federal officials noted that pressure drops in municipal water networks create a risk of untreated groundwater seeping into distribution pipes.

“Operational effects reported to the FBI have included loss of pressure and flooding,” the agencies stated in the alert. They added that the total operational impact on each victim depended on “the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.”

Investigators observed that common network configurations set up by third-party vendors allowed attackers to replicate their methods across multiple customer systems.

To prevent further compromises, the FBI and EPA advised facility operators to immediately disconnect control devices from the public internet using secure gateways and firewalls. Additional recommendations include establishing complex passwords, setting physical key switches to “run” mode to prevent logic modifications, enforcing access control lists, and regularly reviewing project files for unauthorized changes.

Authorities also urged utilities to maintain the capability to revert to manual system controls, test disaster recovery plans, and establish replacement strategies for end-of-life hardware that no longer receives security updates.

Victims of operational technology outages or related intrusions are asked to report incidents to their local FBI field office, the Internet Crime Complaint Center, or the Cybersecurity and Infrastructure Security Agency.

READ: Rot, Mold, And Bugs: 3 More Arrested As Deputies Raid Florida ‘House Of Horrors’

Please make a small donation to the Tampa Free Press to help sustain independent journalism. Your contribution enables us to continue delivering high-quality, local, and national news coverage.

Sign up: Subscribe to our free newsletter for a curated selection of top stories delivered straight to your inbox.