Rockwell Automation: Water Utilities in Seven States Report Cybersecurity Incidents

Rockwell Automation: Water Utilities in Seven States Report Cybersecurity Incidents

Cyberattacks Target U.S. Water Utilities, Disrupting Operations in Multiple States

Since late July, U.S. water and wastewater utilities across at least seven states have faced cyberattacks targeting Internet-facing programmable logic controllers (PLCs), according to a joint alert from the FBI and Environmental Protection Agency (EPA). The incidents, which began on July 27, involved threat actors remotely accessing PLCs primarily Rockwell Automation/Allen-Bradley models to alter IP addresses and passwords, locking operators out of critical monitoring and control systems.

The attacks caused temporary disruptions, including loss of automated functions at some facilities. In some cases, the interference led to pressure loss and flooding, raising concerns that untreated groundwater could contaminate water supplies. The severity of impact varied based on PLC configurations and whether utilities could switch to manual operations.

The FBI and EPA warned that while the alert focused on Rockwell devices, other PLC brands could also be vulnerable. Attackers modified device programming to manipulate pumps, valves, and other equipment, further compromising operational integrity.

In Minnesota, state officials reported that at least 30 community water systems experienced similar cyber incidents on July 26 and 27, though no public health risks or service disruptions were confirmed. Four cities Braham, Plymouth, South St. Paul, and Maple Plain publicly acknowledged impacts, including temporary system outages and disruptions to automated controls at water towers and lift stations. Investigators have not attributed the attacks to a specific threat actor or determined whether a single group was responsible.

Federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), have previously warned that Iranian-affiliated hackers have targeted U.S. industrial control systems, including PLCs, across critical infrastructure sectors. However, Minnesota officials have not linked the state’s incidents to any known group.

The FBI, EPA, and Minnesota IT Services (MNIT) urged utilities to secure Internet-accessible operational technology (OT), including PLCs and human-machine interfaces (HMIs), by removing unnecessary Internet exposure, enforcing strong passwords, implementing multifactor authentication, and maintaining offline backups. Additional recommendations included network segmentation, log reviews, and incident response testing to mitigate future risks.

Source: https://www.govtech.com/security/water-utilities-in-seven-states-report-cybersecurity-incidents

Rockwell Automation cybersecurity rating report: https://www.rankiteo.com/company/rockwell-automation

"id": "ROC1785536869",
"linkid": "rockwell-automation",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Braham',
                        'type': 'Water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Plymouth',
                        'type': 'Water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'South St. Paul',
                        'type': 'Water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'Minnesota, USA',
                        'name': 'Maple Plain',
                        'type': 'Water utility'},
                       {'industry': 'Water and wastewater',
                        'location': 'At least seven U.S. states',
                        'type': 'Water and wastewater utilities'}],
 'attack_vector': 'Remote access to Internet-facing PLCs',
 'date_detected': '2024-07-27',
 'description': 'U.S. water and wastewater utilities across at least seven '
                'states faced cyberattacks targeting Internet-facing '
                'programmable logic controllers (PLCs). Threat actors remotely '
                'accessed PLCs to alter IP addresses and passwords, locking '
                'operators out of critical monitoring and control systems. The '
                'attacks caused temporary disruptions, including loss of '
                'automated functions, pressure loss, and flooding, raising '
                'concerns about water supply contamination.',
 'impact': {'downtime': 'Temporary disruptions, loss of automated functions',
            'operational_impact': 'Pressure loss, flooding, potential water '
                                  'supply contamination, manual operation '
                                  'required',
            'systems_affected': 'PLCs (Rockwell Automation/Allen-Bradley '
                                'models), water and wastewater control '
                                'systems'},
 'investigation_status': 'Ongoing',
 'post_incident_analysis': {'corrective_actions': 'Network segmentation, '
                                                  'enhanced monitoring, '
                                                  'incident response testing, '
                                                  'offline backups',
                            'root_causes': 'Insecure Internet-facing PLCs, '
                                           'weak passwords, lack of '
                                           'multifactor authentication'},
 'recommendations': 'Secure Internet-accessible OT (PLCs, HMIs) by removing '
                    'unnecessary Internet exposure, enforcing strong '
                    'passwords, implementing multifactor authentication, '
                    'maintaining offline backups, network segmentation, log '
                    'reviews, and incident response testing.',
 'references': [{'source': 'FBI and EPA joint alert'},
                {'source': 'Minnesota state officials'},
                {'source': 'CISA warnings'}],
 'response': {'containment_measures': 'Removing unnecessary Internet exposure, '
                                      'enforcing strong passwords, '
                                      'implementing multifactor '
                                      'authentication, maintaining offline '
                                      'backups',
              'enhanced_monitoring': 'Recommended (log reviews)',
              'law_enforcement_notified': 'FBI, EPA, CISA, Minnesota IT '
                                          'Services (MNIT)',
              'network_segmentation': 'Recommended'},
 'stakeholder_advisories': 'FBI, EPA, CISA, and MNIT urged utilities to secure '
                           'OT systems.',
 'title': 'Cyberattacks Target U.S. Water Utilities, Disrupting Operations in '
          'Multiple States',
 'type': 'Cyberattack',
 'vulnerability_exploited': 'Insecure Internet-facing operational technology '
                            '(OT), weak passwords, lack of multifactor '
                            'authentication'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.