Coordinated Attacks on U.S. Water Systems: Controller Lockout via Internet-Exposed PLCs
TLP:CLEAR | Version 1.0 | August 14, 2026 Sectors: Water and Wastewater Systems, Energy, Government Services Active incident. Confirmed scope has expanded three times since July 30. This advisory will be revised as primary sources update.

TL;DR
Threat actors disrupted OT at water utilities in at least 12 U.S. states between July 26 and August 10, 2026.
No exploit was required. Controllers were reachable from the public internet, and the protocols they speak do not authenticate.
Most exposed devices sit on cellular carrier networks, outside the network your IT team administers. This is the layer most utilities have never inventoried.
Two things happened under one campaign: loud lockouts (IP and password changes) and quiet logic tampering (modified Add-On Instructions, falsified HMI values). The second is the dangerous one.
If you were locked out and recovered quickly, you are not finished. Verify controller logic integrity.
Vendor recovery procedures erase your evidence. Capture device state before you reset.
21 actor IP addresses are published with actor-association windows. Query logs historically. Vet before blocking.
Highest-value action this week: determine whether any controller is internet-reachable, including via a carrier network.
What Happened
Between July 26 and 27, coordinated activity disrupted OT at more than 30 Minnesota water systems, including Braham, Plymouth, South St. Paul, and Maple Plain. Incidents followed in New Jersey, Alabama, Georgia, and Michigan. The FBI and EPA issued PSA I-073026-PSA on July 30, CISA published a sector alert the same day, and Rockwell published recovery guidance in SD1790.
Impact varied and should not be collapsed. Minnesota reported no water quality impact and no boil-water advisories. Childersburg confirmed an attack with no service disruption. Clayton County (GA) had a pressure drop and a boil-water advisory affecting roughly 300,000 customers. The FBI states some activity degraded water operations, with effects including pressure loss and flooding.
Attribution. Neither federal document names a country or group. A WaterISAC communication referencing a Minnesota Fusion Center alert attributes the activity to Iran-affiliated actors, which WIRED reports is the first official document drawing that link. Researchers cited by WIRED identify Handala as a plausible alternative. Treat attribution as unresolved. It changes nothing defensively.
How the Attacks Worked
Access. No CVE exploitation has been confirmed. The reported impacts are achievable against an exposed MicroLogix without exploiting any vulnerability. Observed traffic targets 44818/TCP (EtherNet/IP explicit messaging), 2222/UDP (EtherNet/IP implicit I/O, often mislabeled as SSH in secondary reporting), 502/TCP (Modbus), 102/TCP (S7comm), and 22/TCP against cellular modems, where Dropbear SSH was deployed for persistence.
The cellular blind spot. Roughly 4,400 Rockwell/Allen-Bradley controllers answered on 44818 from the public internet in early August 2026, about 65 percent in the U.S., a substantial majority of them inside large mobile carrier networks. Plymouth's remediation was to disconnect cellular-connected equipment at two water towers and multiple lift stations. Braham reported attackers reached plant controls over a wireless connection. These were not enterprise-network compromises.
Two tiers of tradecraft.
Tier 1, denial by configuration change. Against MicroLogix 1100 and 1400 controllers, actors changed IP addresses and enabled password protection where none had been set, producing loss of view and sometimes loss of control. Loud, immediately visible, recoverable in hours. No exploit or process knowledge required.
Tier 2, manipulation of logic and view. Against CompactLogix and Micro850, Schneider BMX P34/Modicon M340, and Siemens S7-1200, CISA advisory AA26-097A (full text, IC3 mirror) documents actors exfiltrating project files using the vendors' own engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal) on leased hosting infrastructure, then modifying Add-On Instructions to disable shutdown and alarm logic while falsifying HMI and SCADA displays. At one victim the malicious project file retained downstream ladder logic while added logic overrode the instruction sets maintaining safe operating parameters.
The two tiers target different controller families. That is not incidental. Tier 1 is designed to be noticed. Tier 2 is designed not to be. If you were locked out, restored service, and closed the incident, you have not answered whether the lockout was the objective or the cover.
The password inversion. Actors are enabling authentication on devices that previously had none. A controller that now requires a password, where your records say none was configured, is an indicator of compromise, not evidence of hardening. Rockwell revised SD1790 on August 10 to state that setting a password is not the primary mitigation.
The integrator multiplier. The FBI notes that similar third-party network configurations across victims may let actors repeat successes across customers. The unit of compromise is the integrator's standard build, not the utility. If you share an integrator with a confirmed victim, assume you share the exposure.
Two Findings That Change Your Runbook
Private APN is not a finish line. CERT.PL has published analysis of a December 2025 attack on a Polish CHP plant in which attackers pivoted from an internet-facing firewall to a cellular router, tunneled into the distribution operator's private APN, scanned it, and reached PLCs at a separate facility, setting them to STOP mode with passwords applied. CERT.PL assesses this as the first observed use of a private APN as an attack vector and has not attributed the incident (reported by SecurityWeek). The FBI correctly recommends private APN as an isolation architecture, but a private APN is a flat trust zone shared across every connected site. Segment inside it, deny east-west traffic between sites by default, and terminate at a monitored gateway rather than on a controller.
Recovery destroys your evidence. Rockwell's recovery procedures for a locked MicroLogix 1400 (battery removal to force a fault) and 1100 (ControlFLASH over DF1 serial) both erase the program, data, and network configuration. The fastest path to restoring service is the fastest path to destroying your only artifacts. Before touching the controller, where safety permits, record firmware version, IP configuration, mode and fault state, and photograph the LCD. Preserve modem, carrier, VPN, firewall, and historian logs separately, since these survive the reset. Then restore, and validate the backup does not itself contain modified logic.
Indicators of Compromise
Foreign IP addresses observed by the FBI communicating with U.S. PLCs, from AA26-097A Table 1 (published July 22, 2026). Defanged.
Indicator | Actor association |
185.82.73[.]175 | Sep 2025 to Feb 2026 |
141.11.164[.]153 | Jan 2026 to Jul 2026 |
175.110.121[.]39 | Feb 2026 to Mar 2026 |
175.110.121[.]41 | Feb 2026 to Mar 2026 |
175.110.121[.]42 | Feb 2026 to Mar 2026 |
175.110.121[.]107 | Feb 2026 |
84.200.205[.]165 | May 2026 to Jun 2026 |
192.142.54[.]79 | May 2026 to Jun 2026 |
185.225.17[.]225 | Jun 2026 to Jul 2026 |
79.133.46[.]209 | Jul 2026 |
88.80.150[.]199 | Jul 2026 |
88.80.150[.]200 | Jul 2026 |
88.80.150[.]202 | Jul 2026 |
Analyst notes.
185.82.73.0/24 is the durable block. Nine addresses across both the April and July indicator sets span January 2025 to March 2026. Hunt the range historically, not just the individual addresses.
88.80.150[.]199, .200, .202 were active in July 2026, overlapping the water incident window. This is the highest-priority cluster for current log review.
175.110.121.0/24 produced four addresses in a six-week window. Treat adjacency as a signal that neighbouring addresses in these ranges merit review.
Vet before blocking. The FBI observed these addresses in the stated windows only. Several are leased hosting infrastructure that may since have been reassigned to unrelated tenants. Historical log matching is high value. Prospective blocking without verification creates availability risk. The eight historical indicators from the April 7 release, plus the authoritative STIX XML and JSON bundles, are in the companion hunt guide and on the CISA advisory page.
These are supporting indicators, not the primary control. No IOC list detects a legitimate engineering session from an expected tool against a controller that should never have been internet-reachable. Exposure removal is the control. The IOCs tell you whether you were already found.
Recommended Actions
Within 72 hours
Remove all controllers from direct internet reachability, including via cellular carrier networks. See Secure Connectivity Principles for OT and CISA's Stuff Off Shodan guide. This addresses the access path in every reported case.
Place physical and software key switches in RUN. Validate the loaded project first, since the mode change locks in what is resident.
Verify offline backups of every controller project exist and are restorable. Test one.
Confirm and rehearse manual operating capability. The FBI ties impact severity directly to it.
Ask your integrator in writing what remote access paths they maintain into your environment.
Within 30 days
Broker remote access through a secure gateway with MFA enforced at the gateway, since controllers cannot enforce it.
Allowlist 44818 and 502 explicitly, deny by default, and disable unused SNMP, HTTP server (Rockwell PN641), Telnet, FTP, RDP, and VNC. Apply vendor hardening guidance: Rockwell SD1771, Schneider's Modicon controller cybersecurity guide, and Siemens Security Bulletin 104599.
Segment enterprise, engineering, vendor, SCADA, and controller networks.
On MicroLogix 1400 Series B, apply FRN 21.002 or later and enable Enhanced Password Security.
Within 90 days
Migrate cellular connectivity to a private APN or equivalent, and segment inside it.
Build a rolling 12-month EOL forecast. The MicroLogix 1100 was discontinued April 30, 2022.
Move CVE-2021-22681 from your patch queue to your architectural risk register. It is in CISA KEV, exploitable without authentication against internet-reachable Logix controllers, and cannot be fixed by a patch. Patch-then-close workflows can never retire it.
Exercise a controller lockout end to end, including evidence capture and backup validation.
Sources
Primary: FBI/EPA PSA I-073026-PSA | CISA AA26-097A (PDF) | CISA WWS sector alert | Rockwell SD1790 and SD1771 | CERT.PL follow-up report | AA23-335A (2023 Unitronics precedent) | MITRE ATT&CK T0883 | MNIT statement
Reporting: WIRED | The Record | SecurityWeek | CyberScoop | WECT, Fox29, WVTM13, CBS News, ABC News
Report an incident: IC3 or your local FBI field office | CISA Operations Center, 1-844-729-2472 | EPA Cybersecurity Technical Assistance for the Water Sector
Exposure figures: Shodan, queried early August 2026.