Key takeaways
- CRS published IF13298 on August 27, 2026, after water-system cyber incidents reported in at least seven states during July.
- The FBI and EPA said attackers targeted internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, changing IP addresses and passwords and disrupting monitoring or control at some sites.
- Federal Safe Drinking Water Act resilience-planning requirements apply to community water systems serving more than 3,300 people; comparable planning is voluntary for smaller systems and federal authorities are more limited for wastewater systems.
- CISA, the FBI, EPA and Rockwell Automation all emphasize removing direct PLC exposure from the public internet, using secure remote-access architecture, restricting authorized connections and maintaining known-good offline backups.
July incidents prompted a new congressional review
Congressional Research Service (CRS) In Focus report IF13298, published August 27, 2026, examines the federal framework for municipal water cybersecurity following reported July attacks on water systems in at least seven states. The report arrives as policymakers weigh whether the existing mix of planning obligations, enforcement, grants and technical assistance is sufficient for a sector made up of utilities with sharply different scales and capabilities. ([politically.com](https://politically.com/congress/crs-reports/IF13298/))
The timing is significant for operations teams. On July 30, the FBI and EPA warned that malicious actors had targeted internet-facing operational-technology devices, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers. The agencies said incidents had been reported to the FBI since July 27 and that some degraded water operations. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions))
The observed attack path was direct controller exposure
According to the FBI and EPA, attackers remotely accessed exposed PLCs and altered IP addresses and passwords, causing affected facilities to lose monitoring and control capability. The advisory describes reported operational effects including pressure loss and flooding; it also says the consequences varied with the controller’s role and whether a site could move to manual operations. At least one organization reported altered PLC project files after detecting ladder-logic discrepancies across multiple sites. ([fbi.gov](https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions))
CISA separately said the activity had produced boil-water notices and sustained manual operations. Its alert cautions that exposure can be missed when cellular modems or other external connections were installed by operators, vendors or integrators but were never included in routine attack-surface reviews. That point makes a current external-exposure inventory as important as an inventory of equipment within the plant network. ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/422e63c))
Requirements do not cover every utility equally
CRS describes a regulatory divide rooted in utility size. Under the Safe Drinking Water Act, community water systems serving more than 3,300 people must conduct risk-and-resilience assessments, develop emergency response plans and renew their self-certifications every five years. Small systems may receive guidance and assistance, but the comparable assessment and planning activities are voluntary. CRS reported that roughly 80.6% of community water systems fall into the small-system category. ([congress.gov](https://www.congress.gov/crs_external_products/R/PDF/R48556/R48556.2.pdf))
The gap is not limited to system size. GAO testified in May 2026 that EPA identified missing cybersecurity risk-assessment requirements for wastewater systems and for certain drinking-water systems, along with significant limits on EPA’s authority under federal drinking-water and clean-water laws to close those gaps. GAO also identified aging technology, staffing shortages and competing financial priorities as practical barriers to stronger cybersecurity. ([gao.gov](https://www.gao.gov/products/gao-26-109159?utm_source=openai))
Compliance and recoverability remain operational issues
The planning requirements that do apply have not always translated into complete compliance. EPA’s enforcement alert states that more than 70% of systems inspected since September 2023 were out of compliance with basic Safe Drinking Water Act Section 1433 requirements. The agency cited incomplete risk-and-resilience assessments or emergency response plans as well as basic access-control weaknesses, including unchanged default passwords, shared user accounts and access that had not been removed for former staff. ([epa.gov](https://www.epa.gov/enforcement/enforcement-alert-drinking-water-systems-address-cybersecurity-vulnerabilities?utm_source=openai))
For integrators and utility engineering teams, recoverability deserves the same attention as prevention. Rockwell Automation’s response guidance notes that recovery from an unknown password condition can erase controller program data and network configuration. It therefore calls for current offline project backups before reset and restoration work. The company also says a password change alone is not the primary mitigation. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html))
What water-sector teams can prioritize now
The immediate control objective is clear: eliminate direct public access to PLCs and other OT assets. CISA recommends that necessary remote operation pass through a VPN or gateway rather than a controller connected directly to the internet. It also recommends strong password protection, replacement of default credentials, IP allowlisting for known engineering devices and a known-clean PLC image backup after disconnecting exposed equipment. ([content.govdelivery.com](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/422e63c))
A practical modernization plan should start with validating every internet-facing address, port-forwarding rule, cellular connection and vendor-maintained path; then map each connection to an approved owner, purpose and access method. Facilities should segment plant and business networks, restrict controller communications to trusted systems, preserve tested offline logic and configuration backups, and exercise manual-operation and restoration procedures. These measures will not resolve the policy gaps identified by CRS and GAO, but they directly address the failure mode documented in the July incidents. ([rockwellautomation.com](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1790.html))
Sources
- July 2026 Water System Cyber Incidents: Considerations for Congress (IF13298) — Congressional Research Service / Congress.gov
- Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions — Federal Bureau of Investigation and U.S. Environmental Protection Agency
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs — Cybersecurity and Infrastructure Security Agency
- Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector (GAO-26-109159) — U.S. Government Accountability Office
- Enforcement Alert: Drinking Water Systems to Address Cybersecurity Vulnerabilities — U.S. Environmental Protection Agency
- SD1790: Security Advisory — Rockwell Automation
