The FBI Little Rock Field Office is sharing a nationwide warning for water and wastewater utilities following cyberattacks targeting operational technology devices.

The FBI and Environmental Protection Agency issued the public service announcement after water and wastewater utilities in at least 7 states reported cyber incidents beginning July 27, 2026. Federal officials have not publicly identified the affected states, and the FBI has not announced that an Arkansas utility was among the victims.
According to investigators, malicious cyber actors are remotely accessing internet-facing programmable logic controllers, commonly known as PLCs. These industrial devices help utilities monitor and control pumps, pressure systems and other equipment used in water and wastewater operations.
The reported attacks have primarily targeted Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series controllers. The FBI says operators using other brands of PLCs should take similar precautions.
After gaining remote access, attackers reportedly changed device IP addresses and passwords. Those changes caused affected utilities to lose monitoring and control capabilities.
Operational disruptions reported to the FBI have included pressure loss and flooding. Federal officials warn that a loss of pressure in a water system could potentially allow untreated groundwater to enter pipes.
At least 1 organization also discovered that its PLC project files had been modified after officials identified discrepancies in the system’s control programming.
The FBI and EPA recommend removing PLCs from direct exposure to the public internet. Any necessary remote access should be routed through secure gateways, firewalls and other monitored security systems.
Utility operators should replace default passwords with strong, unique passwords and configure firewalls or access-control lists to allow communication only between authorized devices.
Officials also recommend placing physical and software switches in “Run” mode after reviewing and validating PLC project files. Devices should remain in programming or remote-access modes only while authorized updates are being completed.
Water and wastewater facilities should maintain the ability to operate essential equipment manually. Emergency plans, backups, fail-safe systems and manual controls should be regularly tested to ensure operations can continue during a cyber incident.
Operators are also encouraged to review PLC project files for unauthorized changes, examine logs from connected modems and workstations and verify that system backups do not contain malicious programming before restoring them.
The FBI recommends developing plans to replace equipment that has reached the end of its supported life. Older systems that no longer receive software updates or security patches are frequently targeted by malicious cyber actors.
Water and wastewater utilities experiencing similar operational technology outages should contact their local FBI field office and file a complaint with the Internet Crime Complaint Center at IC3.gov.
Incidents may also be reported to the Cybersecurity and Infrastructure Security Agency’s 24-hour Operations Center at 1-844-729-2472.
Federal officials recommend including PLC model numbers, serial numbers, IP addresses and information about any unusual network activity when reporting an incident.
















Leave a Reply