Threat reportICS/SCADATL-2026-2972

Exposed Industrial Controllers (Rockwell MicroLogix 1100/1400, Unitronics) Hijacked in July 2026 Campaign Against US Water Utilities

highACTIVE

Exposed Industrial Controllers (Rockwell MicroLogix (TL-2026-2972), also tracked as July 2026 US water utility PLC attacks, is a high-severity ICS/SCADA threat, first published 2026-10-06. It is linked to a Iran-nexus actor with low confidence, affects Rockwell Automation / Allen-Bradley MicroLogix 1100, maps to 2 MITRE ATT&CK techniques (T0859, T1021.005), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
2MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-2972

Threat ID
TL-2026-2972
Also known as
July 2026 US water utility PLC attacks
Severity
HIGH
Status
ACTIVE
Category
ICS_SCADA
First published
Last reviewed
Attribution confidence
LOW
Nation-state nexus
Iran
Motivation
UNKNOWN
Target sectors
water-and-wastewater, critical-infrastructure, government administration, energy, defense
Target regions
united states of america
Detection rules
9
Indicators of compromise
21

How Exposed Industrial Controllers (Rockwell MicroLogix works

Attackers logged in to internet-exposed PLCs, mainly Rockwell Automation/Allen-Bradley MicroLogix 1100/1400, using default or weak credentials and legitimate engineering functions. They changed IP addresses and passwords to lock operators out of water systems. FBI/EPA and press reporting describe incidents in at least 7 states from 26-27 July 2026, with 30+ Minnesota systems affected, pressure loss and flooding. A PolySwarm report (5 Oct 2026) groups this with CyberAv3ngers, Volt Typhoon, GRU Unit 29155 and NoName057(16) OT activity.

Beginning the evening of 26 July 2026, attackers reached internet-facing programmable logic controllers at US water and wastewater utilities. Minnesota IT Services disclosed a coordinated attack on 30+ municipal systems on 27-28 July, with confirmed operational impact in Braham (plant offline), Plymouth, South St. Paul and Maple Plain. The FBI and EPA issued a joint public service announcement on 30 July. It reports incidents in at least 7 states (NBC cites Minnesota, Michigan, Wisconsin and South Dakota; later reporting cites 12+ states). Targeted devices were Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. Attackers remotely changed controller IP addresses and passwords, which locked operators out, caused loss of monitoring and control, pressure loss and flooding, and carried an FBI-identified risk of untreated groundwater entering distribution pipes. No confirmed contamination was reported in Minnesota.

The tradecraft is opportunistic and uses the controllers' own legitimate functions rather than malware or a novel exploit. Sources describe unauthorized logins using default or weak credentials, modification of controller configuration (IP, password, parameters), and use of vendors' engineering software. The CSA note characterizes this as 'opportunistic, at-scale exploitation'. Avertium additionally reports modified project files, disabled alarms and false SCADA/HMI readings, and project-file/SCADA exfiltration. This is a single secondary source, and the primary FBI/EPA text was not retrieved. No CVE is cited as exploited. Forescout notes that 19 of 22 exposed hosts in the attacked cities appear susceptible to CVE-2017-16740 (MicroLogix 1400 Series B/C firmware 21.002 or earlier, Modbus TCP). Forescout identified 4,407 devices exposing EtherNet/IP port 44818 (about 65% in the US, about 70% of US devices behind cellular routers), and 19 of 22 hosts in the attacked cities sat on one mobile carrier network. This is a susceptibility finding, not evidence of exploitation.

Attribution of the July water incidents is unconfirmed. NBC reports 'hallmarks of Iranian meddling' but no official attribution. CISA joint advisory AA26-097A (7 April 2026) attributes a broader campaign against internet-exposed Rockwell PLCs to Iranian-affiliated CyberAv3ngers (IRGC Cyber-Electronic Command), listing ports 44818, 2222, 102 and 502 and reporting PLC project-file extraction and HMI/SCADA manipulation. Secondary reporting says Unitronics devices were not specifically targeted in the July wave. The Unitronics link is the Nov 2023-Jan 2024 CyberAv3ngers campaign, in which it compromised Unitronics controllers, erased original control logic and installed replacement programming. The PolySwarm report (5 Oct 2026, 'Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations') lists 17 SHA-256 hashes against Volt Typhoon, CyberAv3ngers, GRU Unit 29155 and NoName057(16) and notes pro-Russian VNC hijacking of OT HMIs. The hashes are context for those actors, not confirmed artifacts of the July water incidents. Their file types are not given in the sources.

Defensive priorities from the sources: remove PLCs from direct internet exposure; block 44818/Modbus except from allow-listed sources; use secure remote-access gateways with MFA and session logging; move cellular gateways to private APNs; eliminate default credentials; upgrade MicroLogix 1400 Series B/C firmware to 21.003 or later; plan replacement of end-of-life MicroLogix 1100 units; preserve known-good project files and rehearse manual operations.

MITRE ATT&CK techniques used in TL-2026-2972

Lateral Movement

T0859 Valid Accounts; T1021.005 VNC

Affected products and versions in Exposed Industrial Controllers (Rockwell MicroLogix

  • Rockwell Automation / Allen-Bradley — MicroLogix 1100
    Vulnerable versions: internet-exposed units with default or weak credentials
  • Rockwell Automation / Allen-Bradley — MicroLogix 1400
    Vulnerable versions: internet-exposed units with default or weak credentials; Series B/C firmware 21.002 and earlier (CVE-2017-16740 susceptibility)
    Fixed in: firmware 21.003 or later
  • Unitronics — Vision/UniStream PLC/HMI (controllers)
    Vulnerable versions: internet-exposed units with default or weak credentials

Remediation for Exposed Industrial Controllers (Rockwell MicroLogix

Patches

  • Upgrade MicroLogix 1400 Series B/C to firmware 21.003 or later (CVE-2017-16740)

Immediate actions

  • Remove PLCs and cellular/remote-access gateways from direct internet exposure; verify TCP/44818 and Modbus/502 are not publicly reachable
  • Reset default and weak credentials on every internet-reachable controller
  • Restrict remote access to authorized users via secure remote-access gateways with MFA and session logging; monitor remote sessions
  • Validate controller project files and configuration against known-good backups

Workarounds

  • Disable unused SNMP, Modbus TCP and management services
  • Block 44818 with allow-lists at the perimeter

Longer-term hardening

  • Separate business and industrial networks and allow-list OT ports
  • Move cellular gateways to private APNs or VPN tunnels
  • Plan replacement of end-of-life MicroLogix 1100 units
  • Preserve controller configurations and project files; develop manual operating procedures and rehearse cascading outages

Weaknesses (CWE) in Exposed Industrial Controllers (Rockwell MicroLogix

CWE-1392, CWE-521

Timeline of Exposed Industrial Controllers (Rockwell MicroLogix

  • Rockwell Automation first advised customers against connecting controllers directly to the internet (CISA ICSA-18-009-01); exposure peaked at 7,814 devices in March 2020 (CSA).
  • CyberAv3ngers began compromising Unitronics controllers (Nov 2023 - Jan 2024; month-level precision), erasing original control logic and installing replacement programming.
  • CISA joint advisory AA26-097A attributes a campaign against internet-exposed Rockwell PLCs (ports 44818, 2222, 102, 502) to Iranian-affiliated CyberAv3ngers.
  • Evening attack wave begins on internet-exposed MicroLogix controllers at Minnesota water systems (CSA).
  • Minnesota IT Services discloses a coordinated attack on 30+ municipal water systems; Braham plant offline, Plymouth, South St. Paul and Maple Plain disrupted.
  • FBI and EPA joint PSA: attackers changed IP addresses and passwords on exposed MicroLogix controllers, causing pressure loss and flooding; incidents in at least 7 states.
  • Forescout publishes scan findings: 4,407 devices exposing port 44818, 19 of 22 hosts in attacked cities susceptible to CVE-2017-16740.
  • PolySwarm publishes 'Targeting the Systems Behind the Mission', with 17 SHA-256 hashes tied to Volt Typhoon, CyberAv3ngers, GRU Unit 29155 and NoName057(16).
  • Cybersecurity News publishes coverage of exposed-controller exploitation against US water and critical infrastructure.

Sources cited for Exposed Industrial Controllers (Rockwell MicroLogix

Detection coverage for TL-2026-2972

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2972 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats