00:00→The Water Attacks Reached 12 States, and Controllers Are Still Exposed
highthreats2026-08-04 → 2026-08-103 min read

The Water Attacks Reached 12 States, and Controllers Are Still Exposed

BySurucka

Somebody scanned on 3 Aug 26 and found 22 controllers still reachable in the same towns that had just been knocked into manual operation. The attacks have reached at least 12 states.

Summary

Somebody scanned the internet on 03 Aug 26. In the same towns that had just been knocked into manual operation, 22 industrial controllers were still reachable. Greg Otto reported it at CyberScoop on 06 Aug 26. He worked from research by Vedere Labs, the research arm of the security company Forescout.

Last week this report said getting those controllers off the internet is about a day of work on a small system. It also said to watch whether more states started reporting. They did. The Federal Bureau of Investigation (FBI) joined the Environmental Protection Agency in a joint advisory. It confirms attacks at water and wastewater utilities in at least 12 states since 27 Jul 26.

Findings

Forescout's scan turned up more than 4,000 Rockwell Automation and Allen-Bradley controllers answering on the open internet, 2,844 of them on American soil. The MicroLogix 1400 made up half of them, and the CompactLogix 1769 another 22 percent.

Then the researchers compared that list against the cities that had been hit. In those cities, 22 devices were still exposed. Forescout did not say those particular devices were attacked. It did not say they belong to the affected utilities either, and neither does this report.

19 of the 22 look open to a flaw in the MicroLogix 1400 that lets an attacker run his own commands on the device. It was disclosed in 2017 and catalogued as CVE-2017-16740. Using it requires an older industrial communication setting called Modbus TCP to be turned on. The researchers could not confirm whether it was.

The spread filled in over the week. Michigan had nine systems. South Dakota had one wastewater lift station, the pump station that moves sewage to higher ground. In Georgia, the Clayton County Water Authority issued a precautionary boil water advisory and lifted it after testing. A second Georgia authority reported an incident of its own.

The scan found more than controllers. It found expired security certificates, the credentials that prove a server is what it claims to be. It found remote-access addresses nobody had renewed in months or years. One abandoned server has shown a default Microsoft page since 2019.

On the question of who did this, the news moved the other direction this week. Sai Molige of Forescout declined to name anybody. He said the evidence supports "opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices." He added that the scale and the speed look more like mass scanning than a long, patient break-in. Several news outlets have pointed at Iran. Both of those readings are on the record, and neither one is settled.

Impact

If this was mass scanning, then the thing that put a town on the list was being reachable. Nobody studied these utilities and chose them. Being small protected nobody, because nothing about the target mattered except that it answered.

Sean Tufts works at Claroty, another industrial security firm. He told Dark Reading the small systems "are being asked to defend industrial technology with municipal budgets while keeping water running around the clock." Patrick Gillespie of GuidePoint Security, a security services company, put the number of American public drinking water systems above 148,000.

Tufts raised a question nobody has answered yet. More than 30 Minnesota systems went down at nearly the same time. That might mean those utilities share one controls contractor or one remote-access path. Nobody knows.

The 22 exposed devices belong to somebody's account. Whoever holds the service contract on that equipment is the one who could have found them, and is the one who still can.

Recommendations

The general version of this ran last week. Here is the narrow one. If you hold a service contract on any of this equipment, pull your site list and check which devices answer from outside. Get those behind a gateway device that blocks outside connections, and change the passwords on them.

Then ask the owner two things. Who renews the security certificates, and who owns the remote-access address. The scan found plenty of both with nobody home.

Watch whether the count moves past 12 states, and whether anybody names the attacker officially.

Works Cited

  1. Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online (CyberScoop)
  2. Cyberattacks on water systems expand to 12 states as South Dakota, Georgia announce incidents (The Record)
  3. Water Sector Cyberattacks Reportedly Hit at Least 12 States (SecurityWeek)
  4. Minnesota Water Utility Attacks Expose Sector's Cyber-Risks (Dark Reading)
  5. US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices (SecurityWeek)
#water#ot#plc#ics#exposure#remediation#forescout#attribution
90A LLC

Need CMMC help?

90A LLC works in the CMMC trenches with defense contractors every day. We do readiness assessments, gap analysis, and SSP development for the supply chain.