Boil water notices, caused by a password change
The FBI and CISA report attackers changing IP addresses and passwords on exposed water sector PLCs, causing pressure loss, flooding and manual operations.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
There is no exploit in this story. No zero-day, no malware, no phishing email.
Someone found controllers that were reachable from the public internet, connected to them, changed their IP addresses and set passwords the operators did not know. The result, according to the FBI, included loss of pressure and flooding, and pressure loss in a water system can let untreated groundwater seep into pipes [1]. CISA reports the same activity producing boil water notices and sustained manual operations [2].
The whole intrusion is the part most security programmes assume is already handled.
What happened
On July 30, 2026, the FBI and EPA issued a joint public service announcement, and CISA published a parallel alert the same day [1][2].
Since July 27, 2026, water and wastewater utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations [1]. The targeted devices are programmable logic controllers, the small industrial computers that open valves, run pumps and report readings. Specifically, the FBI names Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 series controllers, while cautioning that similar considerations apply to other brands [1]. That is a statement about what they have observed, not a guarantee about everything else.
What the actors did, once connected, is almost mundane. They changed device IP addresses and enabled and set passwords, producing a loss of view and in some cases loss of function over connected equipment [1]. At least one organisation reported modified PLC project files after noticing ladder logic discrepancies across several sites [1].
Nobody has attributed this. The FBI, EPA and CISA name no actor and state no motive, and neither will I.
CISA’s framing is worth quoting for its bluntness: remove publicly exposed PLCs and other operational technology from the internet as soon as possible [2].
Why this matters
The asset inventory is the vulnerability. CISA makes a point that should worry anyone who has run an OT asset review: the targeting includes cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans [2]. A modem fitted years ago for remote field access, by a contractor, on a work order nobody kept, is exactly the kind of asset that does not appear on the list you scan. Even organisations with mature processes are told to revalidate their external connections [2].
Small utilities are in scope. CISA states the activity targets water entities of all sizes [2]. A great many water systems are small municipal operations with no security staff, where the SCADA vendor is also the IT department. This advisory is aimed squarely at them, and the recommended mitigations are deliberately ones that do not require a security team.
One integrator’s pattern is many utilities’ risk. The FBI observes that similarities in network setups provided by third parties across several victims may let an actor multiply successes where the same vulnerable configuration exists across customers [1]. If your integrator has a house style for remote access, that house style is now part of your threat model.
Physical consequences. This is the distinction between IT and OT that gets repeated until it sounds abstract, and then stops being abstract. Loss of pressure and flooding are the reported effects [1]. Pressure loss risks contamination. A boil water notice is a public health event, and it is being caused here by a configuration change.
Technical breakdown
There is no clever tradecraft to explain, which is itself the finding. The sequence below is drawn from the FBI and CISA descriptions.
- ReconnaissanceScans the public internet for control equipment and cellular modems left reachable by operators, vendors or integrators
BREAK THE CHAIN HERE
Remove PLCs from direct internet exposure and broker every remote connection through a secure gateway or jump host, so no inbound port reaches the controller. Detection: scan your own public address ranges and cellular estate for responding OT protocols, and treat every hit as an inventory failure to be closed. - Initial accessConnects directly to an exposed controller protected by a default password, a weak one, or none at all
BREAK THE CHAIN HERE
Set strong unique passwords on every controller and apply an access control list so only known engineering hosts can talk to it. Detection: enable and review logs on connected modems for authentication attempts from unexpected addresses. - DiscoveryReads device configuration to establish what the controller monitors or operates
- ImpactChanges the device IP address, cutting operators off from monitoring and control
- PersistenceEnables and sets a password the utility does not know, locking the operator out of their own equipment
BREAK THE CHAIN HERE
Keep a known-clean backup of each PLC image so a lockout is a restore rather than a crisis. Rockwell publishes specific guidance for regaining access to a MicroLogix 1400 when the password is unknown. Detection: alert on configuration writes to control equipment outside a maintenance window. - ImpactIn at least one case modifies PLC project files, producing ladder logic discrepancies noticed across several sites
- ImpactLoss of view and in some cases loss of function follows, with reported effects including loss of pressure and flooding
- Lateral opportunityWhere a third party has deployed the same network pattern across multiple customers, one success indicates where others will work
BREAK THE CHAIN HERE
Ask your integrator to document the remote-access design they deployed for you, and whether the same pattern is in use elsewhere. Detection: compare your remote-access architecture against the joint secure-connectivity principles for OT rather than against your own past practice.
Four steps carry a break, and the first one does most of the work. Every step after it depends on the controller answering an unsolicited connection from the internet. Remove that and the rest of the chain has nowhere to start.
The FBI’s mitigation list is specific enough to act on directly. Remove inbound port exposure so the OT system is never directly reachable, and broker access through a secure gateway. Ensure cellular modems used for field connectivity carry strong authentication and are updated. Enable and regularly review modem logs. For unauthorised access via cellular paths, consider isolated architectures: a private access point name, a non-public 5G network, cellular SD-WAN, zero trust network access, or a site-to-site VPN. Use complex, unique device passwords [1].
CISA adds one that is easy to skip and painful to skip: after disconnecting PLCs from the internet, make sure you hold a known-clean backup of the PLC image in case a modified password locks you out [2]. The lockout is the mechanism of harm here. A backup converts it from an emergency into an afternoon.
What defenders should do Monday morning
Immediate: today.
Find out whether any control equipment is reachable from the internet. Do not answer from the asset register; answer from a scan of your own public addresses, and specifically include cellular modems fitted by vendors or integrators, which are the assets CISA flags as most likely to be undocumented [2]. Anything you find, disconnect or place behind a gateway now [1][2].
Change default and weak passwords on controllers, and confirm password protection is actually enabled rather than merely available [1][2].
Near term: this week.
Apply an access control list so only known engineering hosts can reach control equipment [1][2]. Enable logging on connected modems and read it [1]. Take and verify a known-clean backup of each PLC image, so a password lockout is recoverable [2]. If you run Rockwell MicroLogix 1400 controllers, read the vendor’s guidance on restoring access when the password is unknown before you need it [2].
Ask your integrator, in writing, how remote access to your equipment is designed, and whether the same design is deployed at their other customers [1].
Structural: this quarter.
Move remote access onto an isolated architecture rather than an exposed one private APN, non-public 5G, cellular SD-WAN, ZTNA or site-to-site VPN [1]. Establish a recurring external attack-surface review that covers cellular and vendor-installed connectivity, not just the addresses your IT team knows about. Write down which functions can be run manually and for how long, because that capability determined how badly affected utilities were hit [1].
Free help exists and is underused: the EPA runs a cybersecurity technical assistance programme for the water sector, and CISA has regional offices [1][2].
Checklist
- Scan your own public IP ranges for responding control equipment.
- Include vendor and integrator cellular modems in that scan.
- Disconnect exposed PLCs; broker remote access through a gateway or VPN.
- Enable password protection and replace default and weak passwords.
- Apply an ACL limiting which hosts may reach control equipment.
- Turn on modem logging and assign someone to review it.
- Take a verified known-clean backup of every PLC image.
- Read Rockwell’s MicroLogix 1400 password-recovery guidance in advance.
- Ask your integrator to document your remote-access design in writing.
- Document which processes can run manually, and for how long.
- Contact the EPA technical assistance programme or your CISA regional office.
The unglamorous conclusion
Most security writing rewards complexity, because complexity is interesting. This campaign offers none. There is no malware to reverse, no exploit to analyse, no actor to name. Someone connected to equipment that was listening on the public internet and changed its settings.
And it produced boil water notices, manual operations, flooding, and the risk of untreated groundwater entering drinking water pipes [1][2].
The gap it exposes is not technical sophistication. It is that a modem installed by a contractor in a pump house years ago is still answering, and nobody has a record that it exists. That is an inventory problem, and inventory problems are solved by going and looking, which is unglamorous, cheap, and the entire recommendation here.
FREQUENTLY ASKED
- We are a small utility with no security staff. Where do we start?
- With one question: is any control equipment reachable from the public internet? That includes cellular modems installed by a vendor or integrator that may never have appeared on an asset list. CISA's guidance is to remove that exposure first and route operational remote access through a VPN or gateway instead. It is the single highest-value action and it does not require a security team.
- Is this a sophisticated attack?
- No, and that is the point worth absorbing. The reported activity is remote access to devices that were reachable from the internet, followed by changing IP addresses and setting passwords. There is no exploit chain here. The controllers answered because they were listening, and in some cases had default or absent credentials.
- Why is a password change such a serious outcome?
- Because it is the operator who gets locked out. Setting a password the utility does not know removes their ability to monitor or control the equipment, which forces manual operations. The FBI reports operational effects including loss of pressure and flooding, and notes that pressure loss can allow untreated groundwater to seep into pipes.
- We only use PLCs for monitoring, not control. Are we lower risk?
- Somewhat, and the FBI says as much, impact depended on whether the controller monitored or controlled equipment, which model it was, and whether the utility could switch to manual. Lower risk is not no risk: losing visibility across a distributed water system is itself an operational problem, and monitoring devices sit on the same networks as controlling ones.
- Our integrator set this up. Is that our problem?
- Operationally, yes. The FBI notes that similar network setups provided by third parties across several victims may let one success repeat at other customers. If your integrator uses a standard remote-access pattern, that pattern is now part of your risk, and it is worth asking them directly what it looks like.
REFERENCES
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗