US officials warn of cyber attacks: Hackers are targeting essential services; say that since July 27, Water utility companies in at least seven states have …

US officials warn of cyber attacks: Hackers are targeting essential services; say that since July 27, Water utility companies in at least seven states have ...
US officials warn hackers are going after essential services (Representative image)

US officials have warned against hackers targeting essential services like water utilities. In a press release shared by the Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA), the agencies warned critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. “Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations,” the release said.

US officials warn hackers are going after essential services

Explaining how the hackers target and breach essential services system, the FBI said that the threat actors first gain remote access to internet-facing devices. Having accessed them, the actors change the IP addresses and passwords, resulting in a loss of monitoring and control functionality. “MCAs are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities,” the agency said.Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.

FBI shares tips to protect from cyber attack targeting water utilities and other essential services

To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices. The FBI and EPA recommend individuals take the following precautions:

  • Disconnect PLC from the public-facing internet. Follow the joint guidance Secure connectivity principles for OT to safely allow remote access. Specifically, “remove inbound port exposure,” so the OT system is never directly exposed to the internet or external networks, and to ensure all access is mediated, monitored, and controlled. Do this through a secure gateway (jump host) that brokers the connection.
  1. Ensure cellular modems, used for remote field connectivity and access, are secured with strong authentication and updated.
  2. Enable logs for connected modems and regularly review for suspicious activity to detect intrusions and improve incident response speed.
  3. To mitigate unauthorized access to OT via cellular modems, organizations should consider implementing isolated architectures, such as private Access Point Name (APN), 5G Public Network Integrated Non-Public Network (PNI-NPN), cellular Software-Defined Wide Area Network (SD-WAN), Zero Trust Network Access (ZTNA), or a site-to-site virtual private network (VPN)
  • Ensure device passwords are complex, unique combinations of letters, numbers, and symbols that are not easily guessable. Implementing robust password practices remains a critical security measure that can help prevent unauthorized access and strengthen the overall security posture of OT devices.
  • Strictly control network access to PLC devices. Configure firewall rules or access control list (ACL) security features on PLCs or programmable controllers to allow only authorized communications between expected control system devices. Block access from unauthorized or threat actor-controlled IP addresses, such as those associated with hosting providers
  • Place physical and software key switches into the run position to block unauthorized changes to logic, configuration, and firmware. Devices should only be in the program or remote position when updating or downloading software online and immediately switched back to the run position when complete. (See Rockwell Automation’s System Security Design Guidelines for manufacturer’s instructions.)
  1. Prior to switching the device to run mode, review and validate project files, as changing modes will lock in the current project file downloaded to the device.
  • Practice and maintain the ability to operate OT systems manually. The capability for organizations to revert to manual controls to quickly restore operations is vital in the immediate aftermath of an incident. Business continuity and disaster recovery plans, fail-safe mechanisms, islanding capabilities, software backups, and standby systems should all be routinely tested to ensure safe manual operations in the event of an incident.
  • Review project files running on PLCs for unauthorized changes. Use vendor provided integrity checking tools and visually compare the running program to known good logic. Ensure reusable logic and input/output configurations are valid.
  1. If restoring backups, verify the backup does not contain malicious logic before deployment.
  2. Review logs and configurations on all connected devices, including modems, HMIs, and workstations, to assess potential lateral movement by threat actors. If it appears the actors connected to additional devices, reimage these devices to remove any potential malicious changes or access tools.
  • Plan for end-of-life (EOL) replacements when possible. When a hardware device is EOL, the manufacturer no longer sells the product and is not actively supporting the hardware, which also means they are no longer releasing software updates or security patches for the device. Since EOL devices no longer receive security updates, they are routinely targeted by MCAs.
  1. Maintain a rolling 12-month EOL forecast, reviewed quarterly with owners and procurement.
  2. Track EOL systems by product, owner, location, and retirement date.
  3. Replace or isolate EOL assets; if delays occur, apply compensating controls with firm decommission dates.

Leave a Reply

Your email address will not be published. Required fields are marked *