# Exposed Industrial Controllers (Rockwell MicroLogix 1100/1400, Unitronics) Hijacked in July 2026 Campaign Against US Water Utilities

> Attackers logged in to internet-exposed PLCs, mainly Rockwell Automation/Allen-Bradley MicroLogix 1100/1400, using default or weak credentials and legitimate engineering functions. They changed IP addresses and passwords to lock operators out of water systems. FBI/EPA and press reporting describe incidents in at least 7 states from 26-27 July 2026, with 30+ Minnesota systems affected, pressure loss and flooding. A PolySwarm report (5 Oct 2026) groups this with CyberAv3ngers, Volt Typhoon, GRU Unit 29155 and NoName057(16) OT activity.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2972
- **ID:** TL-2026-2972
- **Severity:** HIGH
- **Category:** ICS_SCADA
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Beginning the evening of 26 July 2026, attackers reached internet-facing programmable logic controllers at US water and wastewater utilities. Minnesota IT Services disclosed a coordinated attack on 30+ municipal systems on 27-28 July, with confirmed operational impact in Braham (plant offline), Plymouth, South St. Paul and Maple Plain. The FBI and EPA issued a joint public service announcement on 30 July. It reports incidents in at least 7 states (NBC cites Minnesota, Michigan, Wisconsin and South Dakota; later reporting cites 12+ states). Targeted devices were Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers. Attackers remotely changed controller IP addresses and passwords, which locked operators out, caused loss of monitoring and control, pressure loss and flooding, and carried an FBI-identified risk of untreated groundwater entering distribution pipes. No confirmed contamination was reported in Minnesota.

The tradecraft is opportunistic and uses the controllers' own legitimate functions rather than malware or a novel exploit. Sources describe unauthorized logins using default or weak credentials, modification of controller configuration (IP, password, parameters), and use of vendors' engineering software. The CSA note characterizes this as 'opportunistic, at-scale exploitation'. Avertium additionally reports modified project files, disabled alarms and false SCADA/HMI readings, and project-file/SCADA exfiltration. This is a single secondary source, and the primary FBI/EPA text was not retrieved. No CVE is cited as exploited. Forescout notes that 19 of 22 exposed hosts in the attacked cities appear susceptible to CVE-2017-16740 (MicroLogix 1400 Series B/C firmware 21.002 or earlier, Modbus TCP). Forescout identified 4,407 devices exposing EtherNet/IP port 44818 (about 65% in the US, about 70% of US devices behind cellular routers), and 19 of 22 hosts in the attacked cities sat on one mobile carrier network. This is a susceptibility finding, not evidence of exploitation.

Attribution of the July water incidents is unconfirmed. NBC reports 'hallmarks of Iranian meddling' but no official attribution. CISA joint advisory AA26-097A (7 April 2026) attributes a broader campaign against internet-exposed Rockwell PLCs to Iranian-affiliated CyberAv3ngers (IRGC Cyber-Electronic Command), listing ports 44818, 2222, 102 and 502 and reporting PLC project-file extraction and HMI/SCADA manipulation. Secondary reporting says Unitronics devices were not specifically targeted in the July wave. The Unitronics link is the Nov 2023-Jan 2024 CyberAv3ngers campaign, in which it compromised Unitronics controllers, erased original control logic and installed replacement programming. The PolySwarm report (5 Oct 2026, 'Targeting the Systems Behind the Mission: OT Threats to US Critical Infrastructure and Military Operations') lists 17 SHA-256 hashes against Volt Typhoon, CyberAv3ngers, GRU Unit 29155 and NoName057(16) and notes pro-Russian VNC hijacking of OT HMIs. The hashes are context for those actors, not confirmed artifacts of the July water incidents. Their file types are not given in the sources.

Defensive priorities from the sources: remove PLCs from direct internet exposure; block 44818/Modbus except from allow-listed sources; use secure remote-access gateways with MFA and session logging; move cellular gateways to private APNs; eliminate default credentials; upgrade MicroLogix 1400 Series B/C firmware to 21.003 or later; plan replacement of end-of-life MicroLogix 1100 units; preserve known-good project files and rehearse manual operations.

## MITRE ATT&CK

- T0859 Valid Accounts
- T1021.005 VNC

## Sources

- [Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure](https://cybersecuritynews.com/hackers-exploit-exposed-industrial-controllers/)
- [CISA AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- [PolySwarm: Iran-Linked PLC Exploitation Expands Across US Critical Infrastructure](https://blog.polyswarm.io/iran-linked-plc-exploitation-expands-across-us-critical-infrastructure)
- [Forescout Vedere Labs: OT Security Analysis of Exposed Devices Attacked in US Water Systems](https://www.forescout.com/blog/ot-security-analysis-exposed-devices-attacked-in-us-water-systems/)
- [CSA Research Note: Exposed Rockwell PLCs Fuel Ongoing Water Utility Attacks](https://labs.cloudsecurityalliance.org/research/csa-research-note-rockwell-plc-water-utility-attacks-2026080/)
- [Avertium: Coordinated Attack on Rockwell MicroLogix PLCs Disrupts Water Systems Across 7 States](https://www.avertium.com/flash-notices/coordinated-attack-on-rockwell-micrologix-plcs-disrupts-water-systems-across-7-states)
- [NBC News: Hackers targeted municipal water systems in 7 states, FBI says](https://www.nbcnews.com/tech/security/hackers-targeted-municipal-water-systems-7-states-week-fbi-says-rcna590210)
- [Industrial Cyber: FBI and EPA warn hackers target internet-connected PLCs at US water utilities](https://industrialcyber.co/utilities-energy-power-water-waste/fbi-and-epa-warn-hackers-target-internet-connected-plcs-at-us-water-utilities-leading-to-operational-disruptions/)
- [LevelBlue SpiderLabs: Review of the July 2026 Cyberattacks Against U.S. Water and Wastewater Systems](https://www.levelblue.com/blogs/spiderlabs-blog/review-of-the-july-2026-cyberattacks-against-u.s.-water-and-wastewater-systems)
- [The Hacker News: Over 4,400 Rockwell PLCs Exposed Online](https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html)
- [CBS Minnesota: Cyberattack, malware at Braham water plant causes outage](https://www.cbsnews.com/minnesota/news/cyberattack-malware-braham-water-plant-outage/)
- [CISA ICSA-18-009-01: Rockwell Automation (advisory against direct internet connection of controllers)](https://www.cisa.gov/news-events/ics-advisories/icsa-18-009-01)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2972
