In late July 2026, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory warning of a coordinated campaign by malicious cyber actors against the U.S. Water and Wastewater Systems (WWS) sector. Threat actors are targeting internet-facing Operational Technology (OT), specifically Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series Programmable Logic Controllers (PLCs). The attacks have caused tangible operational disruptions in at least seven states, including loss of system control, flooding, and the issuance of boil water notices. Federal agencies are urging all WWS facilities to immediately isolate OT assets from the internet, implement robust access controls, and maintain secure backups to prevent further compromise.
The attacks, which have escalated since July 27, 2026, involve threat actors gaining remote access to publicly exposed PLCs. Once access is achieved, they manipulate the device configurations to disrupt operations and lock out legitimate users. Key tactics include changing device passwords and altering IP addresses, which severs the connection between the PLC and the Supervisory Control and Data Acquisition (SCADA) systems used for monitoring and control. The FBI has confirmed reports of direct operational impacts, such as loss of water pressure and facility flooding. The simultaneous targeting of over 30 systems indicates a potentially widespread and coordinated campaign, possibly exploiting a shared vulnerability, a common third-party service integrator, or default credentials.
The threat actors' primary TTPs involve scanning the internet for exposed OT devices and exploiting weak or default security configurations. The campaign specifically targets Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs.
Attack Chain:
T1190 - Exploit Public-Facing Application or by using default/weak credentials associated with T1078 - Valid Accounts. The presence of undocumented cellular modems suggests exploitation of T0886 - Remote Services.T1489 - Service Stop and T1505 - Server Software Component by altering PLC configurations. By changing passwords and IP addresses, they effectively cause a Denial of Service and lock out legitimate operators, a form of T0831 - Manipulation of Control in an OT context.Rockwell Automation has provided guidance for customers to recover locked MicroLogix 1400 controllers, indicating a known recovery path exists if physical access is possible.
The impact of these attacks is severe and directly affects public health and safety. The disruption of water treatment and distribution has led to boil water advisories, posing a direct risk to communities. Forcing facilities into manual operation increases the likelihood of human error and reduces efficiency. The financial impact includes the cost of emergency response, system recovery, potential regulatory fines, and the long-term investment required to re-architect networks for better security. The targeting of a foundational critical infrastructure sector like water demonstrates a significant threat to national security. The relatively low cybersecurity maturity and limited budgets of many smaller WWS utilities exacerbate this risk.
No specific file hashes, IP addresses, or domains were provided in the source articles.
Security teams may want to hunt for the following patterns to identify vulnerable systems or related malicious activity:
portportlog_sourcenetwork_traffic_patterncommand_line_patternRSLogixDetection:
44818/TCP and 2222/TCP within OT network segments. Utilize Network Traffic Analysis (D3-NTA) to baseline normal traffic patterns and identify anomalous connections.Response:
Immediate Actions:
Strategic Recommendations:
New intelligence suggests Iran-linked actors, specifically CyberAv3ngers, are behind the widespread cyberattacks on US water utilities, affecting states like Minnesota and Michigan.
New intelligence from U.S. officials now attributes the ongoing cyberattacks against the Water and Wastewater Systems (WWS) sector to actors linked to Iran, specifically mentioning groups like CyberAv3ngers. The FBI and EPA are investigating the widespread campaign, which continues to target internet-exposed Rockwell Automation PLCs in at least seven states, including newly identified Minnesota and Michigan. The attacks cause operational disruptions such as loss of water pressure and force utilities into manual operations. This attribution elevates the threat, highlighting potential state-sponsored involvement in critical infrastructure targeting.
Escalation of cyberattacks against WWS sector begins, with utility companies reporting incidents.
The FBI and CISA issue joint advisories warning of the attacks and providing mitigation guidance.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.