Skip to content

Leadership1 publisher3 min readPublished

FBI names Allen-Bradley MicroLogix PLCs in water intrusions across at least seven states

The bureau and the EPA describe intruders changing IP addresses and switching passwords on internet-facing controllers, and the remedy they list is network design and credentials rather than firmware anyone can ship.

The Board Room · Leadership desk

What happened

  • The FBI and EPA warned critical infrastructure owners and operators that cyber actors are attacking internet-facing OT devices, naming Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs.
  • Water and wastewater utilities in at least seven states have reported incidents to the FBI since 27 July 2026, and some of that activity degraded water operations.
  • One organization reported modified PLC project files after noticing ladder logic discrepancies across several of its sites.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint With no firmware fix on the list, remediation cannot be handed to a patch window or a vendor schedule; it consumes control-engineering hours the utility was spending on production work.
  • exposure Part of a utility's exposure sits in its integrator's standard build, so closing your own site leaves the shared weakness intact elsewhere, and buyers cannot see that defect from inside their own network.
  • decision The prioritisation call becomes which controllers actually actuate equipment at sites that cannot be run by hand, because those are where a lost view turns into lost water.
  • precedent Since the bureau extends its caution to other PLC brands on advice rather than observation, running a different vendor's controllers will no longer satisfy an auditor asking about internet-reachable OT.

The advisory names hardware but no vulnerability, which is what determines who has to act. Of the six precautions the FBI and EPA list, none is a firmware update for the MicroLogix line [12]: five are network design or credential changes, and the sixth asks operators to secure and update the cellular modems used for field connectivity [11]. There is nothing to wait for from the vendor and nothing to slot into a patch window, so the work lands on whoever owns the network drawing and the password policy.

The bureau describes actors reaching internet-facing devices and then changing IP addresses and turning passwords on, which cost operators their view of connected equipment and, at some sites, its function [4]. Turning a password on is a different act from defeating one, and the recommendations ask operators to set complex, unique passwords on devices [8]. Whatever the state of authentication beforehand, that fix touches every device individually, which is why it is cheap per unit and expensive in aggregate.

The line most likely to reorder someone's quarter concerns third parties. Across several victims, the FBI says similarities in network setup supplied by third parties may let actors multiply their successes where the same vulnerable arrangement exists across customers [7]. For a utility that bought a packaged control system, the useful question is not what did we configure, but what did our integrator ship to its other customers, and that answer does not appear on the utility's own network diagram.

The advisory is addressed to critical infrastructure asset owners and operators generally [1], and the FBI states it has only observed this behaviour on the named Rockwell models while advising that similar considerations apply to other branded PLCs [3]. That is a claim about what the bureau has seen, not about which controllers will answer an unauthenticated connection from the public internet. Seven states is a floor rather than a census, because it counts the utilities that reported to the FBI [2].

The advisory also supplies an order of operations. Impact varied with whether the PLC monitored or controlled equipment, with the model, with the function it supported, and with whether the site could switch to manual operation [9]. That puts controlling devices at sites without a manual fallback first, since reported effects have included loss of pressure and flooding, and the FBI notes pressure loss can let untreated ground water seep into pipes [5][10]. An inventory of internet-reachable controllers is this week's job. Brokered remote access through a gateway with inbound ports closed [13], plus isolated cellular architectures [11], is a capital plan.

The supplied record leaves the actor unattributed and omits a victim total [14]. On the evidence available, the exposure finding is solid, and the extension beyond water rests on the FBI's advice rather than its observation [3], which is enough to justify an inventory and not enough to justify replacing a vendor.

What to watch

  • Whether Rockwell Automation issues its own guidance for the MicroLogix 1100 and 1400 beyond the FBI and EPA precautions.
  • Whether the count of affected states rises above seven, or the FBI names an actor and publishes indicators of compromise.
  • Whether any of the third-party providers whose network setups recur across victims is identified.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories