WASHINGTON — The FBI and the Environmental Protection Agency issued a joint public service announcement warning water and wastewater utilities nationwide that malicious cyber actors are targeting internet-connected industrial equipment, causing operational disruptions in at least seven states, according to the July 30 alert.
According to the FBI and EPA, the attacks have specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers, devices used to monitor and control water system operations, though the agencies said similar risks apply to other PLC brands as well. Since July 27, utility companies in at least seven states have reported incidents to the FBI, with some activity degrading water operations, according to the alert.
The FBI and EPA said the attackers remotely accessed internet-facing devices and changed IP addresses and passwords, causing utilities to lose monitoring and control functionality. According to the alert, reported operational effects have included loss of water pressure and flooding, with pressure loss potentially allowing untreated groundwater to seep into pipes. The Cybersecurity and Infrastructure Security Agency said separately that it has observed a significant increase in threat actors targeting programmable logic controllers across the water and wastewater sector, noting the activity has already led to boil water notices and utilities switching to manual operations in some cases.
To reduce risk, the FBI and EPA are recommending utilities remove PLCs from direct internet exposure using secure gateways and firewalls, set strong and unique passwords, and use access control lists to limit communication to only authorized control system devices.
The threat isn’t new to Texas. State officials have pointed to a January 2024 cyberattack on the public water system in Muleshoe, Texas, which followed a similar Iran-linked attack on a Pennsylvania water authority the previous month, according to the Governor’s press office.
In response to the growing threat, San Antonio has become a test site for a new federal cybersecurity pilot program aimed at protecting water systems. National Cyber Director Sean Cairncross announced the pilot, saying the federal government had spent too long simply studying the problem instead of acting on it, according to the San Antonio Express-News. Texas Governor Greg Abbott, who also spoke at the announcement, said China, Russia, and Iran launch cyberattacks against critical infrastructure, including water treatment facilities, on a daily basis. Abbott separately said an Iranian-backed cyberattack hit more than 30 municipal water utilities across 12 states in July, a somewhat larger tally than the seven states cited in the federal alert, though both accounts describe the same broad wave of intrusions.




