Attackers did not need ransomware to take a water treatment plant offline. They needed a controller reachable from the public internet and a password they could change.
From FBI and EPA public service announcement I-073026-PSA, issued July 30:
Since July 27, water and wastewater utilities in at least seven states have reported incidents, and some of that activity degraded water operations. The actors are targeting internet-facing Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 controllers. The method is blunt: reach the exposed PLC, change its IP address and password, lock the operator out of their own equipment. Reported consequences include loss of monitoring and control, water pressure drops, and flooding. One organization found modified PLC project files after noticing ladder logic discrepancies.
Minnesota was the visible edge. On July 26 and 27, more than 30 community water systems were hit in a coordinated attack on operational technology. One treatment plant went offline, several cities lost automated controls and ran manually, and one declared a local state of emergency. Water quality was not affected. Michigan has since reported intrusions at nine of its systems.
Four days earlier, CISA updated AA26-097A, warning Iranian-affiliated actors were compromising internet-connected PLCs across water, energy and government sectors. Tenable assessed the pattern as consistent with CyberAv3ngers tradecraft. No formal attribution yet.
Set attribution aside. It does not change Monday.
What should is access. Nothing here required a zero day or malware. It required equipment that answers from the internet and an authentication path an outsider could take over. That does not stop at water. It covers desalination and power generation, port and terminal automation, oil and gas, building management in hospitals and data centres, and the vendor remote access sitting quietly across all of them. Water surfaced first because those utilities are small, underfunded and numerous. The exposure is universal.
Three questions worth answering this week, whatever sector you operate in:
1️⃣ Which of your controllers and management interfaces answer from the public internet, through cellular modems, engineering laptops and unapproved vendor remote access?
2️⃣ Do you hold a copy of every controller configuration, and would you notice if the running logic stopped matching it?
3️⃣ How long can you run manually? When did you last prove that rather than assume it?
Only the first is fixed with a firewall rule.
This is the work we do at FearsOff. We map the external attack surface an adversary actually sees, test the crossover path from corporate IT, identity and vendor remote access into environments meant to be isolated, and hand over what is exposed, how it chains, and what to fix in what order. If you run critical infrastructure or carry obligations for operational resilience, the honest way to find out how you fare is to have someone try it first.