Skip to content

Build1 publisher2 min readPublished

FBI and EPA pin the water-sector PLC attacks on controllers reachable from the open internet

The FBI and EPA's advisory I-073026-PSA blames a water-sector campaign across at least seven states on MicroLogix controllers left reachable on the open internet. The remedy they describe is network placement.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying FBI and EPA pin the water-sector PLC attacks on controllers reachable from the open internet
Generated illustration

What happened

  • Altered pump-and-valve logic dropped water pressure and, in some places, caused flooding at the affected utilities.
  • On the exposed controllers, attackers changed device passwords and IP addresses, disconnected supervisory systems, and rewrote the ladder logic that drives the equipment.
  • The EPA announced $11.75m through its drinking water resilience grant program, directed at ten projects across six states.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint These controllers sit in pump houses, lift stations and remote sites on cellular links, so keeping PLCs off the public internet means re-architecting remote access site by site.
  • exposure Published libraries and generated scripts lower the cost of producing valid OT protocol traffic, so equipment once protected mainly by obscurity is within reach of a larger pool of attackers.
  • decision CISA's layer forces a decision about automation: any AI agent or tool with authority over process control now needs human approval and full audit logging before it changes anything.

A MicroLogix 1100 or 1400, the Allen-Bradley line the advisory names, answers its native industrial protocols to anyone who can reach it on the network. [3] The FBI and EPA found controllers answering on the open internet, and the campaign scanned for them at scale, sweeping the ports those protocols use, among them 502, 102 and 44818. [5][9] There was no vulnerability to patch. The actions attackers took are operations the protocol already permits to anyone who opens a session.

Reporting cited in the advisory describes attackers reaching cellular modems over SSH. That puts them on the link that carries the control traffic, where they can observe and shape what the SCADA layer sees. Relocating the PLC alone does not reach that exposure. [10] A loss of pressure also opens the way for contamination to enter the distribution system, and some utilities issued boil-water notices. [7]

The FBI and EPA tell operators to take PLCs off public internet exposure, require a VPN or secure gateway for any remote access, replace default credentials, and restrict communications to known devices. [16] CISA added an OT layer: keep a real asset inventory, and turn on authentication where protocols such as Modbus and SNMP offer it, because both assume a trusted network. [17]

The money announced alongside is small against the problem. That works out to about $1.175m for each of the ten funded projects. [1] Water utilities are among the most resource-constrained operators of critical infrastructure, many serving small populations with single-digit IT and OT staff, so the defensive work the advisory describes lands where there is least capacity to do it. [15]

One detail points past the water sector. Reporting cites AI-written exploit scripts and the snap7 and python-snap7 libraries, aimed at Siemens S7 hardware; the controllers this advisory names are Allen-Bradley. [11] The engineering knowledge to craft valid protocol traffic and reason about a running process has long been the costly part of an OT attack. [12]

What to watch

  • Whether Rockwell or CISA issues device-level authentication or firmware guidance for MicroLogix beyond network placement.
  • Whether the incident count climbs past seven states as more utilities report intrusions.
  • Whether the ten drinking-water resilience grants fund OT network segmentation specifically, rather than general infrastructure work.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories