A federal alert names cyber intrusion as a cause of boil water notices, and utilities in at least seven states have reported incidents since 27 July
One sentence in Thursday's CISA alert will read differently to anybody who has spent a week boiling water. The activity, it says, has resulted in boil water notices and sustained manual operations.
The Federal Bureau of Investigation and the Environmental Protection Agency issued a public service announcement the same day. Since 27 July, water and wastewater utilities in at least seven states have reported incidents to the FBI, and the announcement says some of that activity degraded water operations. The equipment named is narrow. Rockwell Automation and Allen-Bradley programmable logic controllers, the MicroLogix 1100 and 1400 series, reached over the internet, with the intruders changing IP addresses and setting passwords so that operators lost both the view of the plant and, in some cases, control of it.
Operational effects reported to the FBI have included loss of pressure and flooding. The announcement adds a line that explains why a pressure reading is a public health number rather than an engineering one: pressure loss in water systems could potentially allow untreated ground water to seep into pipes.
This desk is two days late to both documents, and they run because the campaign they describe is current rather than closed. The FBI and EPA state they are engaging with victim organisations, and CISA describes the increase as something it is observing now.
What the documents do not say
Neither document names a state, a utility, or an actor.
That last absence is worth stating precisely, because the surrounding advisory does name one. Both alerts point back to joint advisory AA26-097A, titled for Iranian-affiliated cyber actors exploiting programmable logic controllers across United States critical infrastructure. It was published on 7 April and updated on 22 July by seven agencies, among them the FBI, CISA, the National Security Agency, the EPA, the Department of Energy, Cyber Command's Cyber National Mission Force and the Treasury. The 30 July announcement attributes nothing. It says malicious cyber actors, and it stops there, and a reader who takes the title of the older advisory as the attribution for this week is doing work the agencies have not done.
The update landed five days before the incidents
The 22 July revision of AA26-097A widened the manufacturer scope. Where the advisory had been about Rockwell equipment, the update recorded observed targeting of Schneider Electric and Siemens controllers as well, and said potentially any internet-exposed programmable logic controller of any brand. It told defenders to search their logs for traffic on ports 44818, 2222, 102 and 502, with particular attention to traffic originating from foreign hosting providers.
The first incidents in the current wave were reported five days later.
The undocumented modem
CISA's alert contains one paragraph that does more work than the rest of it. Water organisations with mature cybersecurity processes should still validate their external connections, it says, because the targeting includes cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans.
A modem nobody recorded cannot be scanned for, and a plant that has been audited is not therefore covered. The FBI and EPA version of the same point is longer and more operational: secure the modems with strong authentication, turn on their logs and read them, and consider putting field connectivity behind a private access point name, a zero trust arrangement or a site-to-site tunnel rather than leaving it addressable.
There is a related finding in the FBI document that should worry anybody who buys integration services. Across several victims, it says, similarities in network setup provided by third parties may give the actors the opportunity to multiply successes where the same vulnerable network and hardware pattern has been sold to more than one customer. One organisation reported modified controller project files, noticed because the ladder logic did not match across several of its sites.