Critical Infrastructure Threat: FBI and EPA Issue Urgent Advisory on Attacks Targeting Rockwell Water PLCs
Executive Summary
The Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA), and CISA issued a joint Public Service Announcement on July 30, 2026, warning critical infrastructure operators of widespread, malicious cyber attacks targeting Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 series Programmable Logic Controllers (PLCs). Since July 27, water and wastewater utility companies across at least seven U.S. states have reported active operational disruptions caused by threat actors exploiting internet-exposed Ethernet/IP ports and weak authentication mechanisms on legacy industrial control devices.
Technical Breakdown of the Rockwell MicroLogix Attack Campaign
The joint advisory details a systematic, automated campaign targeting legacy industrial controllers in municipal water networks:
1. Exploitation of Unauthenticated Ethernet/IP (Port 44818)
The attack vector targets legacy Rockwell Automation MicroLogix 1100 and 1400 controllers operating with direct public internet visibility:
* Protocol Vulnerability: The controllers utilize the EtherNet/IP (CIP) protocol over TCP port 44818. Legacy firmware builds lack cryptographic session authentication or access control lists (ACLs) at the network layer.
* Reconnaissance & Scan: Threat actors utilize automated Shodan and Censys queries to scan public IPv4 blocks for active port 44818 responses, identifying vulnerable water treatment plant controllers.
2. Ladder Logic Overwriting & Operational Disruption
Once connected to the exposed EtherNet/IP socket, attackers send raw CIP commands to alter controller memory:
* PLC State Manipulation: Threat actors force the MicroLogix controller into Program mode, corrupting active ladder logic programs and halting real-time chemical dosing algorithms.
* Fault Injection & Display Lockout: Attackers write malicious register values to overwrite controller memory, displaying political messages on physical LCD screens and forcing hard fault locks that require physical manual reset.
Category
Impact Details
Issuing Agencies
FBI, EPA, CISA
Target Infrastructure
Water and Wastewater Systems (WWS) Sector across 7+ States
Impacted Hardware
Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 Series PLCs
Target Protocol / Port
EtherNet/IP (CIP) over TCP Port 44818
Attack Impact
Ladder Logic Corruption, Operational Downtime, Forced Manual Control
Acute Cyber Risks Facing Legacy Operational Technology (OT)
The FBI and EPA advisory underscores the systemic danger of legacy OT devices operating on critical infrastructure networks. Rockwell MicroLogix 1100 and 1400 PLCs, while widely deployed across thousands of municipal utilities, were designed decades ago without modern zero-trust security architecture.
Exposing unauthenticated industrial controllers directly to the public internet allows low-skilled threat actors to threaten municipal public health.
Recommendations and Mitigations
Water utilities and industrial plant operators must implement immediate OT security hardening measures:
1. Remove MicroLogix PLCs from Direct Public Internet Egress: Immediately disconnect all Allen-Bradley MicroLogix controllers, cellular modems, and HMIs from direct public IP exposure. Place remote monitoring channels behind encrypted industrial VPNs.
2. Enforce Strict IT/OT Network Micro-Segmentation: Firewall OT control networks, blocking inbound TCP port 44818 and CIP traffic from administrative IT subnets.
3. Upgrade Firmware & Enable Secure CIP Extensions: Transition legacy MicroLogix units to modern CIP Security-enabled controllers that enforce TLS encryption and cryptographic message authentication.
4. Conduct Regular Physical Dosing Metrics & Manual Override Drills: Ensure water plant personnel physically verify water quality telemetry and maintain tested manual operational procedures during cyber outages.