Attackers changed IP addresses and passwords on water utility control systems, locking operators out. Utilities in at least seven US states reported incidents to the FBI from 27 July 2026, and CISA recorded boil water notices and sustained manual operations.
No exploited vulnerability has been confirmed. An internet-facing PLC that answers is all the access this required. Forescout counted 4,407 still exposed on 3 August, 2,844 of them in the US.
Key Facts
- The FBI and EPA named Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series controllers, and recorded loss of pressure and flooding among the operational effects.
- Minnesota IT Services reported a coordinated attack against more than 30 community water systems on 26 and 27 July 2026.
- The Record put the wider total at 12 states, a broader count than the seven utilities that reported directly to the FBI.
- Of the 22 exposed controllers Forescout located in cities that were attacked, 19 sat on the same mobile carrier network.
Why It Matters
Water and wastewater systems carry a physical safety consequence most sectors do not. The FBI noted that loss of pressure can allow untreated groundwater into drinking water pipes. CISA reported on 30 July that the activity has resulted in boil water notices and sustained manual operations.
The exposure also sits outside the estate most teams inventory. Forescout found more than half of all exposed Rockwell controllers worldwide, and more than 70 percent of the US ones, inside large mobile carrier networks. CISA singled out undocumented cellular modems installed by operators, vendors, or integrators as access points that routine attack surface scans may not capture.
What Happened
Minnesota IT Services reported the first wave on 28 July. Four cities confirmed operational impacts. Forescout reported that the city of Braham, Minnesota described malware that was delivered over a wireless connection, which shut down water plant controls.
The FBI and EPA issued a joint advisory two days later. Attackers reached internet-facing devices remotely, changed IP addresses and passwords, and removed monitoring and control. At least one organization reported modified project files after finding ladder logic discrepancies across several sites. No Minnesota city reported degraded water quality, and The Record has since put the total at 12 states.
The attacks have not been formally attributed. The New York Times reported on 30 July that a preliminary US assessment considered Iranian actors probably responsible, and stressed it could change. CISA advisory AA26-097A covers a separate, longer-running campaign and was updated on 22 July, four days before the Minnesota incident. Forescout notes no confirmed link between that advisory and these attacks.
The distinction matters because the two campaigns produced different effects. In the separate campaign, CISA reported that, at one US victim, the actors loaded a malicious project file. It preserved the controller's ladder logic while overriding the instruction sets governing safe operating parameters, disabling shutdown and alarm logic. No comparable effect has been reported in the water attacks. That advisory also records the actors deploying SSH software on victim modems to gain remote access on port 22.
Technical Cause
Neither US advisory establishes how the attackers found or first reached the controllers. What is established is the condition that allowed it. The devices answered directly, with no gateway between them and the outside network.
Forescout's count shows the condition is not confined to the reported victims. Exposure and exploitability are not the same measure: The Hacker News notes one relevant vulnerability requires Modbus TCP, which Forescout could not verify on those hosts. Reachability alone was enough for the changes described at the utilities already affected.
CISA tells operators to disconnect controllers from the internet and route any necessary remote access through a VPN or gateway device rather than to the controller itself. For cellular modem access specifically, joint advisory AA26-097A adds five isolated architectures worth considering, beginning with a private carrier Access Point Name (APN).
Governance and Risk Implications
1. Reachability was the precondition, not sophistication. No zero-day appears in the public account. The device had to be online and answering.
2. An inventory that stops at the internet edge is incomplete. CISA singled out cellular modems installed by operators, vendors, or integrators that routine attack surface scans may not capture. The FBI notes that where third parties repeat a network setup across customers, one working technique can carry between victims.
3. End-of-life hardware takes patching off the table. Forescout notes Rockwell discontinued the MicroLogix 1100 on 30 April 2022. When patching is no longer an available option, restricting reachability is the only control.
4. Detection has little to work with on this campaign. CISA published indicators for the separate Iranian-affiliated campaign, but no equivalent indicators have been released for the July water incidents. Controls that depend on a known signature have nothing to match, which puts the weight on limiting what can be reached in the first place.
Secure Architecture Response
The principle is vendor-neutral. Control equipment should not be individually addressable from any network the operator does not fully control, and carrier-provisioned links belong in the asset inventory alongside everything else.
This is the HIDE pillar of Entropya's HIDE. HARDEN. VERIFY framework, delivered through Digital Camouflage. Placed in front of controllers and the human machine interfaces (HMI) that manage them, the IEG Router (Iron Edge Gateway) removes the direct internet path CISA is telling operators to eliminate, and cloaks the equipment behind it so a scan returns nothing to act on. It complements or replaces a perimeter device depending on the architecture. The IEG authenticates connected systems into the Entropya Encrypted Network (EEN), Entropya’s quantum resilient software-defined network with no fixed or mappable path at all. On Forescout's count, 4,407 devices are still reachable the way this campaign required.
Four questions worth answering about your own environment
- Does your asset inventory list the cellular modems your integrators installed, and who administers them?
- If a controller at one site were compromised now, what could it reach at other sites?
- Do you hold a clean, verified backup of each controller's project file?
- Can operations continue manually if SCADA and cellular links are lost together?
Review your exposure
Assess whether your control equipment and management paths are more discoverable than they should be, including across networks provisioned by carriers and integrators.