The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) have issued a joint Public Service Announcement (PSA) on July 30, alerting the nation to ongoing cyberattacks against water and wastewater utilities. These attacks, which began as early as July 27, have targeted internet-connected operational technology (OT) devices, disrupting normal water operations in at least seven states.
"Hackers have targeted water systems in several US states in a coordinated cyberattack that has caused some utilities to issue boil-water notices and switch to manual mode, taking their systems offline, according to US officials." — US Officials, via CNN
According to federal officials, malicious cyber actors have specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs), which are widely used to monitor and control critical water infrastructure. While these specific models were identified, the agencies cautioned that similar vulnerabilities could exist in other brands of industrial controllers, indicating a broader potential threat landscape.
The attacks involve remote access to internet-facing PLCs, where cyber actors have changed internet protocol (IP) addresses and passwords. This unauthorized access has resulted in utilities losing monitoring and control capabilities over their systems. The FBI reported that attackers also altered device configurations by modifying IP addresses and enabling passwords, leading to a loss of visibility and, in some cases, direct control over connected equipment. Furthermore, at least one organization discovered unauthorized modifications to PLC project files after identifying discrepancies in ladder logic across multiple facilities, suggesting sophisticated intrusion methods.
Federal officials believe that similarities in network configurations used by third-party providers might have facilitated the compromise of multiple organizations utilizing comparable systems. The operational impacts reported have included instances of localized flooding and temporary losses of water pressure. The FBI has warned that a reduction in water pressure could create hazardous conditions, potentially allowing untreated groundwater to infiltrate portions of a water distribution system, posing a significant public health risk. The CNN network, citing US officials, reported that these coordinated cyberattacks have caused some utilities to issue boil-water notices and switch to manual operation, taking their systems offline.
While the attacks have affected utilities in at least seven states, the FBI has not publicly identified the specific states involved. However, the Alabama Department of Environmental Management (ADEM) has proactively urged municipal water and wastewater operators across Alabama to conduct thorough cybersecurity assessments and review all internet-connected equipment. This precautionary measure was taken despite Alabama officials confirming no reported water service interruptions, pressure losses, or boil water advisories linked to this specific cyber campaign within the state.
In response to the escalating threat, the FBI and EPA have issued a series of urgent recommendations for water and wastewater utilities nationwide. Paramount among these is the advice to disconnect programmable logic controllers from the public internet whenever feasible, advocating for the use of secure gateways and firewalls instead. Other critical recommendations include implementing strong, unique passwords for all systems, restricting network access to essential personnel and devices, and regularly reviewing project files for any unauthorized modifications.
The agencies also stressed the importance of maintaining the ability to manually operate systems in the event of a cyber compromise, ensuring continuity of essential services. Replacing outdated equipment that has reached its end-of-service life is another key recommendation, as older systems often lack modern security features. Additionally, utilities are encouraged to routinely review system logs and device configurations, verify the integrity of backups before system restoration, and immediately report any suspicious cyber activity to federal authorities. The FBI specifically requested that organizations experiencing potential attacks notify the bureau, the Internet Crime Complaint Center (IC3), and the Cybersecurity and Infrastructure Security Agency (CISA) to enable a coordinated federal response to the ongoing campaign.
This federal warning underscores the critical vulnerability of essential public infrastructure to cyber threats and highlights the urgent need for robust cybersecurity defenses to protect public health and safety.