The FBI and Environmental Protection Agency issued an urgent warning this week that malicious cyber actors are actively targeting America’s water and wastewater systems, successfully causing “operational disruptions” in multiple states.
According to the federal alert, attackers are zeroing in on internet-facing programmable logic controllers — specifically certain Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series devices that help manage critical water infrastructure. These are not sophisticated military-grade systems. They are the mundane controllers that keep your tap running and your sewage moving.
The hackers have been able to remotely access vulnerable devices, change passwords, modify IP addresses, alter controller settings, and in some cases, interrupt normal operations entirely. Foreign actors — or whoever is behind this — now have the capability to mess with the systems that deliver clean water to American homes.
Why is this happening? The agencies were blunt: “Cyber actors exploit these devices because they are internet accessible and often use default credentials or outdated software.” In other words, basic negligence. Critical infrastructure was plugged into the public internet with factory-default passwords, and now we are paying the price.
The FBI and EPA are urging utilities to take immediate action — disconnect these devices from the public internet “whenever possible,” update software, and change default credentials. But one has to wonder: why wasn’t this done years ago? How many other sectors are running on similarly vulnerable setups?
This is not theoretical. Water systems in multiple states have already been affected. When basic infrastructure becomes a playground for cybercriminals — or worse, state-sponsored actors — the margin for error disappears. The question is not whether a major attack will happen. It is whether we will fix these vulnerabilities before something catastrophic does.
Providence watches over the bold.