Skip to main content
Rockwell AutomationSecurity incident

Municipal Water System Attacks Spotlight Insecure Industrial Systems

What happened

Vulnerabilities in Rockwell Automation's MicroLogix PLCs were exploited in cyberattacks against municipal water systems in at least 12 U.S. states, disrupting operations by altering IP addresses and passwords on the internet-exposed devices.

Source

forbes.comAug 11, 2026By Bill Curtis, Contributor

Municipal Water System Attacks Spotlight Insecure Industrial Systems

Article excerpt

Highlighted: the sentence this signal was extracted from

By Bill Curtis, Contributor. Municipal water systems in at at least 12 states faced cyberattacks starting July 27, 2026, with hackers altering IP addresses and passwords on internet-exposed programmable logic controllers, disrupting operations. The vulnerable devices were Rockwell Automation MicroLogix PLCs, found by Forescout to be directly accessible via the internet without authentication, despite years of vendor warnings. This widespread vulnerability stems from a lack of clear responsibility for long-term security maintenance in industrial automation settings, especially for older systems in small utilities lacking IT staff. This issue extends to other critical infrastructure. Companies should define security ownership for new systems and immediately secure existing legacy equipment behind robust firewalls. Attackers hit municipal water systems in at least 12 states beginning July 27, 2026, interrupting critical monitoring and control functions at some utilities by changing IP addresses and passwords on internet-facing programmable logic controllers. The FBI reported that at least one victim's PLC programming was modified. The news about this had little technical detail, so I decided to dig deeper. Minnesota IT Services reported a coordinated attack against more than 30 water systems in that state on July 28. Two days later, the FBI and EPA identified the affected...

Keep reading with a free account

The rest of this article, and every signal for Rockwell Automation, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
MicroLogix PLC
Takes effect
Jul 27, 2026
Location
United States

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Internet-exposed programmable logic controllers (PLCs) without authentication

Topics and mentions

Product tags

  • general technology

Extraction

Confidence
90%
Detected
Aug 11, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Rockwell Automation and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Rockwell Automation this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/026af98c-83b6-e7cd-62d4-e4541b41b3e2 returns this record as JSON. POST /v1/companies/enrich returns every signal for rockwellautomation.com.

{
  "signal_id": "026af98c-83b6-e7cd-62d4-e4541b41b3e2",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-11T19:14:28+00:00",
  "company": {
    "name": "Rockwell Automation",
    "domain": "rockwellautomation.com"
  },
  "data": {
    "url": "https://www.forbes.com/sites/moorinsights/2026/08/11/municipal-water-system-attacks-spotlight-insecure-industrial-systems/",
    "title": "Municipal Water System Attacks Spotlight Insecure Industrial Systems",
    "author": "Bill Curtis, Contributor",
    "excerpt": "By Bill Curtis , Contributor. Municipal water systems in at at least 12 states faced cyberattacks starting July 27, 2026, with hackers altering IP addresses and passwords on internet-exposed programmable logic controllers, disrupting operations. The vulnerable devices were Rockwell Automation MicroLogix PLCs, found by Forescout to be directly accessible via the internet without authentication, despite years of vendor warnings. This widespread vulnerability stems from a lack of clear responsibility for long-term security maintenance in industrial automation settings, especially for older systems in small utilities lacking IT staff. This issue extends to other critical infrastructure. Companies should define security ownership for new systems and immediately secure existing legacy equipment behind robust firewalls. Attackers hit municipal water systems in at least 12 states beginning July 27, 2026, interrupting critical monitoring and control functions at some utilities by changing IP addresses and passwords on internet-facing programmable logic controllers. The FBI reported that at least one victim’s PLC programming was modified. The news about this had little technical detail, so I decided to dig deeper. Minnesota IT Services reported a coordinated attack against more than 30 water systems in that state on July 28. Two days later, the FBI and EPA identified the affected...",
    "product": "MicroLogix PLC",
    "summary": "Vulnerabilities in Rockwell Automation's MicroLogix PLCs were exploited in cyberattacks against municipal water systems in at least 12 U.S. states, disrupting operations by altering IP addresses and passwords on the internet-exposed devices.",
    "location": "United States",
    "planning": false,
    "image_url": "https://imageio.forbes.com/specials-images/imageserve/6a7b71901bf6d4d921d8f92d/0x0.jpg?format=jpg&crop=1536,864,x0,y20,safe&height=900&width=1600&fit=bounds",
    "confidence": 0.9,
    "product_data": {
      "name": "MicroLogix PLC",
      "full_text": "Rockwell Automation MicroLogix PLCs",
      "fuzzy_match": false
    },
    "product_tags": [
      "general_technology"
    ],
    "published_at": "2026-08-11T19:14:28Z",
    "location_data": [
      {
        "region": "Northern America",
        "country": "United States",
        "continent": "Americas",
        "fuzzy_match": false
      }
    ],
    "vulnerability": "Internet-exposed programmable logic controllers (PLCs) without authentication",
    "effective_date": "2026-07-27",
    "article_sentence": "The vulnerable devices were Rockwell Automation MicroLogix PLCs, found by Forescout to be directly accessible via the internet without authentication, despite years of vendor warnings."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.