More than 30 municipal water utilities lost control of their systems
On 30 July 2026 the FBI and the United States Environmental Protection Agency reported that water and wastewater utilities in at least seven states had reported incidents since 27 July, and that some of the activity had degraded water operations. The attackers reached control devices facing the internet, and changed IP addresses and passwords so that the plants lost both visibility and control. The state of Minnesota reports that more than 30 municipal water utilities were affected on 26 and 27 July. CISA warned the same day of a significant increase in attacks on control devices in the water sector.
What happens technically
The devices in question are programmable logic controllers, in practice the small industrial computers that open valves, drive pumps and hold pressure. The FBI and EPA name the MicroLogix 1100 and 1400 models from Rockwell Automation and Allen-Bradley. The attack requires no new vulnerability. It is enough that the device is reachable from the internet and that the password is either left at its default or absent. Once the attacker is in, the address and password are changed, and the operator is locked out of their own plant. At least one utility also found modified project files in the controller, meaning the program governing the process had itself been changed. CISA additionally points to cellular modems installed by the operator, the supplier or the systems integrator as an attack surface that is often neither documented nor caught by routine scanning.
The physical consequences reported to the FBI are pressure loss and flooding. Contamination is described as a possibility rather than as something that happened. How badly a plant was hit depended on what the controller actually did, which model it was, and whether the plant could switch to manual operation. Four cities in Minnesota have gone public. Braham, with around 1700 inhabitants, had its well and treatment plant shut down. Maple Plain declared a local state of emergency, while Plymouth and South St. Paul moved to manual operation. Michigan confirms nine affected water systems with no known health consequences, and the only documented boil water notice came in Georgia and was lifted the following day. On attribution the sources are careful, and it is worth repeating precisely: the notice from the FBI and EPA names neither a state nor a group, and CISA's alert the same day does not either. The Iran connection sits in a different and older document, the CISA advisory AA26-097A of 7 April 2026, updated on 22 July, which uses the word assesses and writes Iran-affiliated rather than Iranian state. The number of states grew from seven in the federal document to at least twelve in the press, without any agency publishing the figure twelve.
What this means for you if you are responsible for water supply
It is easy to read this as an American story about old equipment. Look instead at what was actually exploited, because there is nothing particularly American about it. A control device reachable from outside, with a password nobody changed, is the same weakness in any country. Our assessment is that the most instructive part of the case is who was hit hardest. It was not the large plants. It was the small ones, with few staff, ageing equipment and a remote access path an integrator set up long ago. A place like Braham does not have a security team, it has an operations manager.
Do you know how your plant is actually reached from outside, and who set that up? That is the central question here, and CISA points straight at the weakest spot: the modem the supplier fitted, which nobody has on any list. The second question is whether you can run manually. That capability is exactly what separated the plants that kept producing water from those that did not. Water is one of the sectors NIS2 treats as particularly important, and you then have to show both that remote access is mapped and that manual operation is exercised. Obtain a clean backup of the program in each controller before anything happens, too. If you are locked out of your own device, that copy decides how long the downtime lasts.
Berigo recommends
- Disconnect the controllers from the internet. Where remote access is necessary, place it behind a solution with strong authentication and allow-listed addresses.
- Map cellular modems and other remote access fitted by suppliers and integrators. CISA points to precisely these as invisible to ordinary scanning.
- Change default passwords and enable password protection on each individual device, not only on the central system.
- Take a clean backup of the program in every controller now, and keep it outside the operational network.
- Exercise manual operation. That capability decided how severe the outcome became at the affected plants.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch