Municipal Water System Attacks Spotlight Insecure Industrial Systems
Article excerpt
Highlighted: the sentence this signal was extracted from
By Bill Curtis, Contributor. Municipal water systems in at at least 12 states faced cyberattacks starting July 27, 2026, with hackers altering IP addresses and passwords on internet-exposed programmable logic controllers, disrupting operations. The vulnerable devices were Rockwell Automation MicroLogix PLCs, found by Forescout to be directly accessible via the internet without authentication, despite years of vendor warnings. This widespread vulnerability stems from a lack of clear responsibility for long-term security maintenance in industrial automation settings, especially for older systems in small utilities lacking IT staff. This issue extends to other critical infrastructure. Companies should define security ownership for new systems and immediately secure existing legacy equipment behind robust firewalls. Attackers hit municipal water systems in at least 12 states beginning July 27, 2026, interrupting critical monitoring and control functions at some utilities by changing IP addresses and passwords on internet-facing programmable logic controllers. The FBI reported that at least one victim's PLC programming was modified. The news about this had little technical detail, so I decided to dig deeper. Minnesota IT Services reported a coordinated attack against more than 30 water systems in that state on July 28. Two days later, the FBI and EPA identified the affected...
Keep reading with a free account
The rest of this article, and every signal for Rockwell Automation, is in your free account.
