VYPR
advisoryPublished Aug 6, 2026· Updated Aug 19, 2026· 6 sources

Cyberattacks Disrupt US Water Utilities, Exposing Critical Infrastructure Vulnerabilities

Multiple water and wastewater utilities across at least seven U.S. states have been targeted by cyberattacks exploiting unpatched, internet-exposed industrial control systems, leading to operational disruptions and a local state of emergency.

In a stark reminder of the fragility of critical infrastructure, water and wastewater utilities across at least seven U.S. states have been targeted by a wave of cyberattacks since late July. The FBI and Environmental Protection Agency (EPA) issued a joint alert on August 6th, highlighting that these attacks exploited internet-facing programmable logic controllers (PLCs) – the industrial computers that manage essential functions like pumps, valves, and water treatment processes.

These attacks, while not sophisticated, have had tangible impacts. Utilities reported disruptions including pressure loss and flooding, forcing some systems to revert to manual operations. The severity in one Minnesota community led to the declaration of a local state of emergency. Crucially, attackers did not rely on zero-day exploits or novel malware. Instead, they exploited basic security oversights: PLCs directly exposed to the public internet, many running outdated software that no longer receives security patches. Attackers gained access, altered configurations, changed IP addresses and passwords, and effectively locked operators out of their own equipment, with at least one incident involving modifications to the core control logic.

This incident echoes a similar series of attacks against water utilities in late 2023, which also prompted federal guidance. However, the current wave demonstrates an escalation in attacker ambition and methodology. Moving beyond mere screen defacement, attackers are now targeting dozens of systems simultaneously. This broader impact is facilitated by the common practice of third-party integrators deploying identical, vulnerable configurations across numerous small utilities, creating a widespread attack surface.

The root cause of these recurring vulnerabilities lies in systemic issues within the U.S. water sector. With approximately 50,000 community water systems, many are small, publicly funded entities where cybersecurity is a secondary concern to the primary mission of providing safe and reliable water. The aging infrastructure, often a decade or more old, requires capital investment for replacement that many utilities lack. Furthermore, cybersecurity regulations for water systems remain largely voluntary, creating an environment where basic security measures are often overlooked.

Despite the systemic challenges, the defenses required to mitigate these threats are neither complex nor costly. The FBI and EPA have outlined clear, actionable steps that organizations should implement immediately. Key recommendations include isolating PLCs from the public internet by routing remote access through secure gateways, enforcing strong, unique passwords to replace default or shared credentials, and implementing network segmentation with firewall rules to restrict device communication. Locking down control logic and practicing manual operations are also critical for resilience.

Asset visibility is paramount; many utilities are unaware of their own internet-exposed devices until an attack occurs. A comprehensive inventory often reveals forgotten modems and integrator-installed remote access points. Continuous monitoring of Operational Technology (OT) environments is essential to detect the subtle signals of intrusion—such as configuration changes or password resets—before they escalate into widespread operational degradation. The difference between detecting an intrusion early and a system failure can be the difference between a minor incident report and a public health crisis.

Water systems operate with minimal margins for error and often possess the fewest resources for defense. The repeated nature of these attacks suggests that threat actors are testing the resolve of the sector to implement basic security hygiene. The FBI and EPA have provided a clear roadmap; the onus is now on the utilities to act decisively and prove that these vulnerabilities can and will be addressed, safeguarding a vital public service.

This incident underscores a persistent challenge in securing industrial control systems: the gap between the criticality of the service provided and the investment in its cybersecurity. The attacks exploit not just technical flaws but also the economic and structural realities of the sector, highlighting the urgent need for both regulatory action and increased funding to bolster the resilience of America's water infrastructure.

Forescout's August 3 scan identified over 4,400 Rockwell Automation PLCs exposed online, with 22 found in US cities that have recently been targeted by cyberattacks on water utilities. While no compromise was confirmed, the scan also noted that 19 of these 22 controllers, and over 70% of the US-based exposed controllers overall, utilized the same mobile carrier network, highlighting potential supply chain or network infrastructure vulnerabilities.

New research from Forescout indicates that over 4,400 Rockwell Automation PLCs remain exposed online, with a significant portion (65%) located in the United States, potentially impacting water systems. While the FBI and EPA advisory confirmed that threat actors specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, modifying logic and credentials, this new report details that 19 out of 22 targeted hosts were susceptible to CVE-2017-16740, a Modbus TCP denial-of-service flaw, based on firmware analysis.

The ongoing cyberattacks targeting water and wastewater utilities have now impacted at least 12 U.S. states, expanding from an initial report in Minnesota. Officials believe these incidents are part of a coordinated campaign linked to Iranian hackers who are specifically targeting internet-exposed programmable logic controllers (PLCs) used in operational technology. The FBI has noted that attackers remotely access these PLCs, change passwords, and disable monitoring, leading to disruptions like flooding and loss of water pressure, with some facilities issuing precautionary boil water advisories.

New Jersey and Alabama have confirmed their water and wastewater facilities were targeted in the ongoing campaign, bringing the total number of identified states to at least a dozen. While disruptions were limited, with only phone systems affected in New Jersey and no service impact in Alabama, the expansion of targets highlights the persistent threat to critical infrastructure. The FBI has confirmed at least seven states were targeted as of July 30, with CISA urging the water sector to enhance its operational technology security.

This new reporting delves into the perplexing nature of the recent cyberattacks on U.S. water utilities, highlighting the attackers' apparent lack of sophisticated execution and clear objectives. Experts are baffled by the decision to change passwords and IP addresses on compromised Programmable Logic Controllers (PLCs), which effectively alerted operators to the intrusion without causing significant damage, a move that seems counterproductive to achieving destructive goals.

Synthesized by Vypr AI