Skip to content
Security Article

Internet-Facing PLCs Are Still Running America's Water

The Minnesota attacks reran the 2023 Aliquippa playbook at scale, and the exposure numbers explain why.

Emeka Okafor
Emeka Okafor
Security Editor · Aug 2, 2026 · 5 min read
Internet-Facing PLCs Are Still Running America's Water

Over the last weekend of July, someone methodically locked water utility operators out of their own control systems. More than 30 community water systems across Minnesota — Plymouth, South St. Paul, Maple Plain, and Braham among the cities that went public — had internet-exposed PLCs hijacked on July 26 and 27. The attackers didn't deploy malware or ransom anything. They changed device passwords so operators couldn't log in, then changed the controllers' IP addresses so the devices dropped off the network entirely. Utilities fell back to manual operations; at least one boil-water notice followed.

By July 30, CISA had published an urgent alert, and the FBI and EPA issued a joint PSA reporting incidents at utilities in at least seven states since July 27, some of which degraded water operations. The named hardware: Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, with Siemens SIMATIC S7-1200 and Schneider Electric gear flagged in the broader advisory.

If this feels familiar, it should. It's the November 2023 Aliquippa playbook, rerun at scale.

We already ran this experiment

In 2023, the Iran-linked CyberAv3ngers group defaced Unitronics PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania, and a string of other small utilities. The devices were reachable from the public internet, many still using the vendor default password. CISA issued an advisory, the Treasury Department sanctioned IRGC officers over the campaign, and the State Department put a $10 million reward on the group. The lesson — don't put PLCs on the internet — could not have been delivered more loudly.

Two and a half years later, Censys counted the sector's homework: as of July 30, 2026, roughly 4,148 Rockwell/Allen-Bradley EtherNet/IP hosts sit exposed on the public internet, 71% of them in the US, alongside about 4,117 exposed Siemens S7-1200 hosts and over 2,000 Schneider Electric devices. The MicroLogix 1100 and 1400 are aging small-form controllers — the 1100 line dates back to the mid-2000s — that were never designed to authenticate hostile traffic. Nothing about the attack surface meaningfully changed between the warning shot and the follow-through.

That's the real story here, and it's why "patch your PLCs" is the wrong headline. There's no patch in the FBI's mitigation list, because there's nothing to patch. Changing an exposed controller's password and IP address doesn't require an exploit chain; it requires reaching the management interface. The vulnerability is architectural: the device is on the internet at all.

How the exposure actually happens

Almost nobody at a water utility decides to put a PLC on the public internet. It happens through the supply chain. Both CISA and Censys single out cellular modems installed by vendors, integrators, and operators for remote support — a $200 LTE gateway wired into the control cabinet so the integrator can troubleshoot without a two-hour drive. Those modems routinely don't appear in the utility's asset inventory, don't show up in routine attack-surface scans keyed to the utility's known IP ranges, and terminate directly on the OT network with no firewall in between. Iran-linked actors used exactly this path against Israeli water infrastructure back in 2020.

That's what makes this a systems-integration problem more than a security-operations one. The people best positioned to fix it are the integrators and controls engineers who build these installations, not the two-person utility staff who inherit them.

What to actually do this week

If you build, maintain, or integrate water-sector control systems, the checklist is short and concrete:

  • Find your own exposure before someone else does. Query Shodan or Censys for your utility's IP ranges and — critically — for the carrier-assigned ranges of any cellular modems. EtherNet/IP on port 44818, S7comm on 102, Modbus on 502. If a controller answers, that's the incident waiting to happen.
  • Get PLCs off the internet, full stop. Remote access goes through a VPN or gateway with IP allowlisting to known engineering workstations. This is CISA's first recommendation, verbatim, and it was CISA's first recommendation in 2023 too.
  • Turn the key. MicroLogix and most Rockwell controllers have a physical mode switch; in RUN, remote logic modification is blocked. It's the cheapest control in all of OT security and it's routinely left in REMOTE.
  • Back up ladder logic offline, now. The utilities recovering fastest from the Minnesota incidents were the ones that could re-image a controller from a known-good project file rather than reverse-engineer their own plant.
  • Audit every cellular connection against the asset inventory. If a modem exists that the inventory doesn't know about, treat it as compromised until proven otherwise.

On attribution: US investigators are examining Iranian involvement, and researchers note the pattern fits CyberAv3ngers precisely — small utilities, internet-facing PLCs, disruption over destruction. But neither CISA nor the FBI has formally attributed the activity, and preliminary assessments have been wrong before. The defensive guidance doesn't change either way.

Why it will happen again

Here's the uncomfortable editorial judgment: expect a rerun, because none of the structural incentives moved. The US has roughly 50,000 community water systems, most serving small towns with no dedicated IT staff, let alone OT security engineering. The EPA's 2023 attempt to fold cybersecurity into sanitary surveys was withdrawn within months after states and industry groups sued. What's left is voluntary guidance — and the Censys numbers are a measurement of exactly how far voluntary guidance goes.

The durable fix isn't another advisory. It's procurement: utilities and their integrators refusing remote-access setups that expose management interfaces, and vendors shipping remote connectivity that's secure by default rather than bolted on through a modem in the cabinet. Rockwell, Siemens, and Schneider all sell managed secure remote access today; the gap is that a decades-old MicroLogix installed in 2009 predates all of it, and replacement budgets at small utilities are measured in decades.

Until that changes, the honest reading of this alert is that it's not news about attackers getting more capable. It's a recurring audit of infrastructure that keeps failing the same test — and in 2026, the attackers graduated from defacing one Pennsylvania booster station to degrading operations in seven states in a single week.

Sources & further reading

  1. CISA Alert: Water Sector PLC Targeting — censys.com
  2. CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs — cisa.gov
  3. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing PLCs — fbi.gov
  4. CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs — securityweek.com
  5. U.S. investigating if Iran was behind cyberattack on water systems in 7 states — cbsnews.com
  6. Minnesota Water Cyber Attack and CISA Advisory AA26-097A — tenable.com
Emeka Okafor
Written by
Emeka Okafor · Security Editor

Emeka has spent over a decade tracking threat actors, vulnerability disclosures, and the evolving landscape of application security, bringing a sharp continent-spanning perspective to his reporting. He's known for translating dense CVE advisories into clear, actionable context that developers and security teams alike actually read.

Discussion 0

Join the discussion

Sign in or create an account to comment and vote.

No comments yet

Be the first to weigh in.

Related Reading