Threat reportICS/SCADATL-2026-2972
Exposed Industrial Controllers (Rockwell MicroLogix 1100/1400, Unitronics) Hijacked in July 2026 Campaign Against US Water Utilities
Exposed Industrial Controllers (Rockwell MicroLogix (TL-2026-2972), also tracked as July 2026 US water utility PLC attacks, is a high-severity ICS/SCADA threat, first published 2026-10-06. It is linked to a Iran-nexus actor with low confidence, affects Rockwell Automation / Allen-Bradley MicroLogix 1100, maps to 2 MITRE ATT&CK techniques (T0859, T1021.005), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 2MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-2972
- Threat ID
- TL-2026-2972
- Also known as
- July 2026 US water utility PLC attacks
- Severity
- HIGH
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- Last reviewed
- Attribution confidence
- LOW
- Nation-state nexus
- Iran
- Motivation
- UNKNOWN
- Target sectors
- water-and-wastewater, critical-infrastructure, government administration, energy, defense
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 21
How Exposed Industrial Controllers (Rockwell MicroLogix works
Attackers logged in to internet-exposed PLCs, mainly Rockwell Automation/Allen-Bradley MicroLogix 1100/1400, using default or weak credentials and legitimate engineering functions. They changed IP addresses and passwords to lock operators out of water systems. FBI/EPA and press reporting describe incidents in at least 7 states from 26-27 July 2026, with 30+ Minnesota systems affected, pressure loss and flooding. A PolySwarm report (5 Oct 2026) groups this with CyberAv3ngers, Volt Typhoon, GRU Unit 29155 and NoName057(16) OT activity.
Beginning the evening of 26 July 2026, attackers reached internet-facing programmable logic controllers at US water and wastewater utilities. Minnesota IT Services disclosed a coordinated attack on 30+ municipal systems on 27-28 July, with confirmed operational impact in Braham (plant offline), Plymouth, South St. Paul and Maple Plain. The FBI and EPA issued a joint public service announcement on 30 July. It reports incidents in at least 7 states (NBC cites Minnesota, Michigan, Wisconsin and South Dakota; later reporting cites 12+ states). Targeted devices were Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. Attackers remotely changed controller IP addresses and passwords, which locked operators out, caused loss of monitoring and control, pressure loss and flooding, and carried an FBI-identified risk of untreated groundwater entering distribution pipes. No confirmed contamination was reported in Minnesota.
The tradecraft is opportunistic and uses the controllers' own legitimate functions rather than malware or a novel exploit. Sources describe unauthorized logins using default or weak credentials, modification of controller configuration (IP, password, parameters), and use of vendors' engineering software. The CSA note characterizes this as 'opportunistic, at-scale exploitation'. Avertium additionally reports modified project files, disabled alarms and false SCADA/HMI readings, and project-file/SCADA exfiltration. This is a single secondary source, and the primary FBI/EPA text was not retrieved. No CVE is cited as exploited. Forescout notes that 19 of 22 exposed hosts in the attacked cities appear susceptible to CVE-2017-16740 (MicroLogix 1400 Series B/C firmware 21.002 or earlier, Modbus TCP). Forescout identified 4,407 devices exposing EtherNet/IP port 44818 (about 65% in the US, about 70% of US devices behind cellular routers), and 19 of 22 hosts in the attacked cities sat on one mobile carrier network. This is a susceptibility finding, not evidence of exploitation.
Attribution of the July water incidents is unconfirmed. NBC reports 'hallmarks of Iranian meddling' but no official attribution. CISA joint advisory AA26-097A (7 April 2026) attributes a broader campaign against internet-exposed Rockwell PLCs to Iranian-affiliated CyberAv3ngers (IRGC Cyber-Electronic Command), listing ports 44818, 2222, 102 and 502 and reporting PLC project-file extraction and HMI/SCADA manipulation. Secondary reporting says Unitronics devices were not specifically targeted in the July wave. The Unitronics link is the Nov 2023-Jan 2024 CyberAv3ngers campaign, in which it compromised Unitronics controllers, erased original control logic and installed replacement programming. The PolySwarm report (5 Oct 2026, 'Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations') lists 17 SHA-256 hashes against Volt Typhoon, CyberAv3ngers, GRU Unit 29155 and NoName057(16) and notes pro-Russian VNC hijacking of OT HMIs. The hashes are context for those actors, not confirmed artifacts of the July water incidents. Their file types are not given in the sources.
Defensive priorities from the sources: remove PLCs from direct internet exposure; block 44818/Modbus except from allow-listed sources; use secure remote-access gateways with MFA and session logging; move cellular gateways to private APNs; eliminate default credentials; upgrade MicroLogix 1400 Series B/C firmware to 21.003 or later; plan replacement of end-of-life MicroLogix 1100 units; preserve known-good project files and rehearse manual operations.
MITRE ATT&CK techniques used in TL-2026-2972
Lateral Movement
Affected products and versions in Exposed Industrial Controllers (Rockwell MicroLogix
- Rockwell Automation / Allen-Bradley — MicroLogix 1100
Vulnerable versions: internet-exposed units with default or weak credentials - Rockwell Automation / Allen-Bradley — MicroLogix 1400
Vulnerable versions: internet-exposed units with default or weak credentials; Series B/C firmware 21.002 and earlier (CVE-2017-16740 susceptibility)
Fixed in: firmware 21.003 or later - Unitronics — Vision/UniStream PLC/HMI (controllers)
Vulnerable versions: internet-exposed units with default or weak credentials
Remediation for Exposed Industrial Controllers (Rockwell MicroLogix
Patches
- Upgrade MicroLogix 1400 Series B/C to firmware 21.003 or later (CVE-2017-16740)
Immediate actions
- Remove PLCs and cellular/remote-access gateways from direct internet exposure; verify TCP/44818 and Modbus/502 are not publicly reachable
- Reset default and weak credentials on every internet-reachable controller
- Restrict remote access to authorized users via secure remote-access gateways with MFA and session logging; monitor remote sessions
- Validate controller project files and configuration against known-good backups
Workarounds
- Disable unused SNMP, Modbus TCP and management services
- Block 44818 with allow-lists at the perimeter
Longer-term hardening
- Separate business and industrial networks and allow-list OT ports
- Move cellular gateways to private APNs or VPN tunnels
- Plan replacement of end-of-life MicroLogix 1100 units
- Preserve controller configurations and project files; develop manual operating procedures and rehearse cascading outages
Weaknesses (CWE) in Exposed Industrial Controllers (Rockwell MicroLogix
Timeline of Exposed Industrial Controllers (Rockwell MicroLogix
- Rockwell Automation first advised customers against connecting controllers directly to the internet (CISA ICSA-18-009-01); exposure peaked at 7,814 devices in March 2020 (CSA).
- CyberAv3ngers began compromising Unitronics controllers (Nov 2023 - Jan 2024; month-level precision), erasing original control logic and installing replacement programming.
- CISA joint advisory AA26-097A attributes a campaign against internet-exposed Rockwell PLCs (ports 44818, 2222, 102, 502) to Iranian-affiliated CyberAv3ngers.
- Evening attack wave begins on internet-exposed MicroLogix controllers at Minnesota water systems (CSA).
- Minnesota IT Services discloses a coordinated attack on 30+ municipal water systems; Braham plant offline, Plymouth, South St. Paul and Maple Plain disrupted.
- FBI and EPA joint PSA: attackers changed IP addresses and passwords on exposed MicroLogix controllers, causing pressure loss and flooding; incidents in at least 7 states.
- Forescout publishes scan findings: 4,407 devices exposing port 44818, 19 of 22 hosts in attacked cities susceptible to CVE-2017-16740.
- PolySwarm publishes 'Targeting the Systems Behind the Mission', with 17 SHA-256 hashes tied to Volt Typhoon, CyberAv3ngers, GRU Unit 29155 and NoName057(16).
- Cybersecurity News publishes coverage of exposed-controller exploitation against US water and critical infrastructure.
Sources cited for Exposed Industrial Controllers (Rockwell MicroLogix
- Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure
- CISA AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers
- PolySwarm: Iran-Linked PLC Exploitation Expands Across US Critical Infrastructure
- Forescout Vedere Labs: OT Security Analysis of Exposed Devices Attacked in US Water Systems
- CSA Research Note: Exposed Rockwell PLCs Fuel Ongoing Water Utility Attacks
- Avertium: Coordinated Attack on Rockwell MicroLogix PLCs Disrupts Water Systems Across 7 States
- NBC News: Hackers targeted municipal water systems in 7 states, FBI says
- Industrial Cyber: FBI and EPA warn hackers target internet-connected PLCs at US water utilities
- LevelBlue SpiderLabs: Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems
- The Hacker News: Over 4,400 Rockwell PLCs Exposed Online
- CBS Minnesota: Cyberattack, malware at Braham water plant causes outage
- CISA ICSA-18-009-01: Rockwell Automation (advisory against direct internet connection of controllers)
Detection coverage for TL-2026-2972
As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2972 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.