Exposed Industrial Controllers Under Attack: U.S. Water Infrastructure at Risk

Internet-connected controllers used in U.S. water and wastewater systems have become a focal point for malicious actors exploiting exposed devices over public networks. These controllers, particularly Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 models, have been compromised across at least seven states in incidents that started in late July 2026. Intruders altered passwords and network settings, hampering operations and hampering oversight of critical infrastructure. Most concerning, the attacks led to real physical disruptions—loss of pressure and even flooding in utility systems. Investigators warn that compromised water systems can enable untreated water ingress under certain conditions, though no evidence yet confirms contamination. PolySwarm, the threat intelligence firm analyzing these intrusions, also stresses that these were not isolated hacker campaigns but reflected long-standing vulnerabilities in design and process.

Modus Operandi—From Weak Credentials to Infrastructure Disruption

In many of these attacks, attackers didn’t deploy custom malware; instead, they leveraged basic cybersecurity failures such as default or weak passwords and remote access tools left unsecured. In one case, not only were control files modified but the operational logic—the programming that determines how a device behaves—was rewritten. Physical consequences included flooding and low pressure. A key danger flagged by the FBI is that reduced pressure might allow untreated groundwater to seep into the system—effectively threatening water purity, even if no contamination has yet been confirmed.

Previous campaigns targeting Unitronics controllers show similar patterns: exploits through weak or missing password protection. Between November 2023 and January 2024, a single threat actor group—CyberAv3ngers—hit at least 34 U.S. water and wastewater entities this way. Attackers deleted original control logic, reprogrammed devices, and changed network configurations—actions that severely undermined system integrity and visibility.

Strategic Implications & Defensive Measures

Beyond immediate impacts to utilities, there is concern that these attacks could feed into broader strategic risks. Civil infrastructure—power, communications, water—is often shared between civilian and military systems. The group Volt Typhoon, identified in the latest findings, is believed to be seeking underground access that could be activated during times of conflict without ever directly breaching military networks. Other affiliated actors have also gained access through exposed services such as VNC—but with actions that occasionally oversell their own damage.

To counter these growing threats, PolySwarm recommends a multi-layered approach. Exposed devices should be removed from the open internet when possible. Default credentials must be replaced, and remote access should be gated to only necessary users. Separating business networks from operational technology environments is key. Maintaining trusted backups of configurations, firmware, and project files is essential. Finally, manual operational procedures should be prepped and validated in case automated or remote control becomes compromised.

At a systems level, utility operators and emergency planners are urged to map interdependencies with military and logistics networks, conduct joint rehearsals involving cybersecurity, operations, and emergency management, and simulate what happens when shared supplies fail or are disrupted. These exercises could reveal weak points and help ensure that response plans are effective before the next major incident.

What this means is clear: the gap between the digital and physical worlds is shrinking. Utilities that once saw cybersecurity as an IT concern now face it as an operational imperative. Pressure on infrastructure is more than literal—it’s systemic. Watch for further disclosures about attribution, improved detection tools tailored to industrial controllers, and policy shifts requiring utilities to harden exposed systems.