Water utility cyberattacks highlight OT cybersecurity risks:
What attacks on internet-accessible PLCs reveal about OT cybersecurity and operational resilience

 |   | 

Reading Time: 5 minutes
In brief:

Internet-accessible PLCs can provide direct access to critical OT processes. Recent attacks targeting U.S. water utilities underscore the growing urgency of OT cybersecurity and demonstrate why it has become a core component of operational resilience. Organizations that improve visibility, reduce exposure, and strengthen foundational security controls can better protect essential services from disruption.

Recent attacks against U.S. drinking water and wastewater utilities highlight a growing challenge across critical infrastructure. Operational technology (OT) environments were designed for reliability and availability, not protection from cyber threats.

As utilities modernize operations and increase connectivity, legacy systems and devices exposed to the public internet create pathways for unauthorized access and disruption.

Threats to internet-accessible OT

On July 30, 2026, the FBI and EPA issued a public warning after multiple utilities reported cyber incidents involving internet-accessible OT. The activity specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs), resulting in degraded water operations. These PLCs act as the digital brains of the facility, reading data from sensors and automatically controlling physical equipment such as pumps and valves.

The FBI has not publicly identified the utilities involved. However, at least 12 states have reported cyberattacks, targeted reconnaissance, or operational intrusions.

Although the incidents haven’t caused widespread impacts on water supplies or treatment, they underscore the importance of appropriate safeguards.

In “July 2026 Water System Cyber Incidents: Considerations for Congress,” the U.S. Congressional Research Service (CRS) reported that out of 49,500 community water systems in the U.S., smaller systems make up 81%. These facilities often lack dedicated IT personnel, making them particularly vulnerable.

OT security is now an operational resilience issue

OT cybersecurity has become a critical component of operational resilience.

The threat actors involved in these incidents interacted directly with equipment responsible for controlling physical water processes. According to the FBI, they accessed internet-facing PLCs and changed IP addresses and passwords, effectively locking out plant workers. Once in control, they altered pump cycles, disabled safety alarms, and manipulated system data. Media reporting also indicates that unauthorized changes were made to at least one facility’s automation software. Operational consequences included loss of water pressure and flooding.

This is significant because the incidents crossed the traditional boundary between an information security event and a physical process event.

For water utility leaders, the key takeaway is that cybersecurity risks quickly become operational risks when OT environments are involved. Manipulation of pumps, valves, tank levels, pressure, chemical processes, and other automated functions can affect equipment availability, environmental compliance, continuity of service, and public safety.

The America’s Water Infrastructure Act of 2018 (AWIA) requires systems serving populations greater than 3,300 to assess risks and resilience and maintain emergency response plans. It doesn’t apply to smaller utilities. The recent attacks on internet-accessible PLCs highlight the critical importance of incorporating OT cybersecurity into those efforts, regardless of system size.

How foundational security gaps created OT risk

The most concerning aspect of the FBI and EPA warning is also the most actionable: attackers gained access through poor cyber hygiene rather than sophisticated intrusion techniques.

They simply identified internet-exposed PLCs and accessed them remotely.

While the FBI identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs in the reported incidents, the underlying security concerns extend to PLCs manufactured by other vendors.

“The sad thing is, these aren’t unique vulnerabilities. They’re actually just basic cybersecurity controls we’ve known about for, honestly, decades.”

Michael Garcia, Vice President of Government Relations at Monument Advocacy

Threat actors don’t need to compromise a network, deploy sophisticated malware, or obtain domain administrator privileges to disrupt operations.

OT devices such as PLCs, actuators, and SCADA systems were designed to operate in isolated, physically secure environments. Internet-accessible OT devices can provide adversaries with a direct path to critical physical processes.

A compromised business IT workstation may create a confidentiality issue. A compromised OT PLC controlling critical systems can impact service delivery and potentially threaten public safety. Growing concern about these risks is driving attention at the federal level.

In July, a bipartisan U.S. Senate committee introduced the Water Resources Development Act. The act aims to authorize more than $35 billion in funding for water infrastructure programs over the next four years, with an explicit focus on OT cybersecurity and resilience.

Security fundamentals are non-negotiable

The FBI and EPA warning reinforces the importance of foundational OT security practices.
  • Disconnect OT assets from the public-facing internet. Internet-facing PLCs, HMIs, RTUs, engineering workstations, or SCADA interfaces should be treated as critical/high-risk findings requiring immediate remediation.
  • Eliminate default passwords. Shared, weak, or vendor-standard OT credentials represent an unacceptable pathway to physical-process compromise.
  • Control network access to PLC devices. Remote access into OT environments should terminate through controlled security gateways rather than directly at controllers.
  • Segment networks. IT and OT environments should be properly segmented to limit unauthorized access and restrict lateral movement between enterprise systems and process-control networks.
  • Inventory assets. Utilities require a complete inventory of PLCs, HMIs, RTUs, engineering workstations, servers, network equipment, remote-access systems, and externally exposed assets.
  • Exercise response and recovery. OT incident-response procedures should include rapid isolation, transition to manual operation, engineering validation, configuration restoration, forensic preservation, regulatory notification, and safe return to automated control.
  • Maintain backups. Known-good PLC programs, configurations, firmware, HMI applications, historian configurations, network-device configurations, and engineering files must be backed up and recoverable.
  • Monitor OT activity. Traffic should be continuously monitored for unauthorized programming commands, controller configuration changes, abnormal engineering-workstation communications, new remote sessions, authentication failures, and unexpected internet communications.

These practices align with earlier joint guidance from NIST, CISA, EPA, and the FBI.

Building operational resilience with OT cybersecurity

The recent attacks on U.S. water utilities demonstrate that OT cybersecurity is no longer just an IT concern. It is a key component of operational resilience, public trust, and service continuity.

As facilities work to modernize infrastructure and improve connectivity, foundational security controls need to be reinforced. Reducing exposure, improving visibility, and strengthening cyber hygiene can help teams prevent and respond to similar incidents.

Many water utilities, particularly smaller systems, face resource and staffing constraints that make maintaining effective cybersecurity challenging.

SHI works with organizations to evaluate the maturity of their security programs and develop practical roadmaps aligned with operational objectives. Through cybersecurity assessments, network architecture reviews, and tabletop exercises, we help strengthen resilience across IT and OT environments.

NEXT STEPS

Speak to an SHI expert to map out a security approach built for your goals.

Our Security Posture Review provides technical analysis paired with practical, risk-based recommendations.