On the weekend of July 26, more than 30 community water systems in Minnesota were hit in a coordinated attack on their control equipment. Braham's water treatment plant was temporarily taken offline. Within days, the FBI and EPA issued a joint public service announcement: since July 27, water and wastewater utilities in at least seven states had reported similar incidents.
What happened
The attackers are not using an exotic exploit. They are finding programmable logic controllers (PLCs) reachable from the internet, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 models, and logging in. Once in, they change the device's IP address and password. Operators lose the ability to monitor or control the equipment.
What happens next depends on what that controller runs. Reported effects include loss of pressure and flooding. The FBI notes that pressure loss could let untreated groundwater seep into pipes. In at least one case, attackers also tampered with the controller's operating logic.
The FBI has only seen this activity on the Rockwell models so far, but warns that other brands deserve the same scrutiny. The agencies put the root cause plainly: these devices are targeted because they are internet accessible and often use default credentials.
Why it matters for Texas
Texas has thousands of public water systems, and many are run by cities, counties and special districts with small staffs. The same is true of university central plants, which run chilled water, steam and power for entire campuses on PLCs that were often installed by a contractor and connected for remote support.
These devices rarely show up in the IT asset inventory. They may sit on a cellular modem, a vendor VPN or a forgotten public IP. If nobody in IT knows a controller is there, nobody is watching who logs into it.
What your organization should do
- Find what is exposed. Scan your public address space for PLC and HMI interfaces, including industrial protocols, not just web ports.
- Pull controllers off the internet. Put them behind a firewall or secure gateway, and use an access control list so only expected systems can talk to them.
- Change default passwords. Use strong, unique credentials on every controller and HMI.
- Set the physical key switch to Run. On MicroLogix and similar PLCs, this blocks remote program changes.
- Practice manual operation. Make sure staff can run critical processes by hand if the controls go dark.
- Plan for end-of-life hardware. Older controllers that cannot be patched or secured should be on a replacement schedule.
RSOC is here to help
RSOC can scan your external address space for exposed industrial devices and help you build a plan to close them off. Contact rsoc@utexas.edu. Water utilities that experience an OT outage should also report it to their local FBI field office and IC3.
Sources: FBI and EPA PSA · Smart Water Magazine · ESE Magazine · Cyber Advisors