Treasury
3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp
US Treasury par yield curve · Jul 31 · Source: U.S. Treasury
Sunday, August 2, 2026
U.S. Edition
Water and Wastewater Systems Sector

A federal alert names cyber intrusion as a cause of boil water notices, and utilities in at least seven states have reported incidents since 27 July

A close overhead photograph of an industrial steel floor plate, the right half raised in a repeating diamond tread pattern with orange corrosion spread through the channels between the studs, the left half a flat panel finished in worn green paint and meeting the tread along a straight seam. No object, person, place, marking or lettering is in view.
Photo: Nothing Ahead / Pexels

One sentence in Thursday's CISA alert will read differently to anybody who has spent a week boiling water. The activity, it says, has resulted in boil water notices and sustained manual operations.

The Federal Bureau of Investigation and the Environmental Protection Agency issued a public service announcement the same day. Since 27 July, water and wastewater utilities in at least seven states have reported incidents to the FBI, and the announcement says some of that activity degraded water operations. The equipment named is narrow. Rockwell Automation and Allen-Bradley programmable logic controllers, the MicroLogix 1100 and 1400 series, reached over the internet, with the intruders changing IP addresses and setting passwords so that operators lost both the view of the plant and, in some cases, control of it.

Operational effects reported to the FBI have included loss of pressure and flooding. The announcement adds a line that explains why a pressure reading is a public health number rather than an engineering one: pressure loss in water systems could potentially allow untreated ground water to seep into pipes.

This desk is two days late to both documents, and they run because the campaign they describe is current rather than closed. The FBI and EPA state they are engaging with victim organisations, and CISA describes the increase as something it is observing now.

What the documents do not say

Neither document names a state, a utility, or an actor.

That last absence is worth stating precisely, because the surrounding advisory does name one. Both alerts point back to joint advisory AA26-097A, titled for Iranian-affiliated cyber actors exploiting programmable logic controllers across United States critical infrastructure. It was published on 7 April and updated on 22 July by seven agencies, among them the FBI, CISA, the National Security Agency, the EPA, the Department of Energy, Cyber Command's Cyber National Mission Force and the Treasury. The 30 July announcement attributes nothing. It says malicious cyber actors, and it stops there, and a reader who takes the title of the older advisory as the attribution for this week is doing work the agencies have not done.

The update landed five days before the incidents

The 22 July revision of AA26-097A widened the manufacturer scope. Where the advisory had been about Rockwell equipment, the update recorded observed targeting of Schneider Electric and Siemens controllers as well, and said potentially any internet-exposed programmable logic controller of any brand. It told defenders to search their logs for traffic on ports 44818, 2222, 102 and 502, with particular attention to traffic originating from foreign hosting providers.

The first incidents in the current wave were reported five days later.

The undocumented modem

CISA's alert contains one paragraph that does more work than the rest of it. Water organisations with mature cybersecurity processes should still validate their external connections, it says, because the targeting includes cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans.

A modem nobody recorded cannot be scanned for, and a plant that has been audited is not therefore covered. The FBI and EPA version of the same point is longer and more operational: secure the modems with strong authentication, turn on their logs and read them, and consider putting field connectivity behind a private access point name, a zero trust arrangement or a site-to-site tunnel rather than leaving it addressable.

There is a related finding in the FBI document that should worry anybody who buys integration services. Across several victims, it says, similarities in network setup provided by third parties may give the actors the opportunity to multiply successes where the same vulnerable network and hardware pattern has been sold to more than one customer. One organisation reported modified controller project files, noticed because the ladder logic did not match across several of its sites.

The document: Federal Bureau of Investigation and Environmental Protection Agency, Public Service Announcement, Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions, dated 30 July 2026, issued through the FBI National Press Office, Washington DC, (202) 324-3691. The complete page was downloaded and the text extracted and read here; no fetch-tool summary was relied on. Facts as verified verbatim in that document: the FBI and EPA issue the PSA to warn critical infrastructure asset owners and operators that malicious cyber actors are conducting cyber attacks targeting operational technology devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers, specifically MicroLogix 1100 and 1400 series; 'Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations'; while the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs; after remotely accessing internet-facing devices the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality; the actors tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities; 'At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites'; across several victims, similarities in network setup provided by third parties may provide the actors the opportunity to multiply successes when vulnerable network and hardware setups exist across customers; 'Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes'; the extent of impact depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations; the FBI and EPA state they are engaging with victim organizations. Recommendations as verified in the same document: disconnect the PLC from the public-facing internet; remove inbound port exposure and mediate access through a secure gateway or jump host; ensure cellular modems used for remote field connectivity are secured with strong authentication and updated; enable and review modem logs; consider isolated architectures including private Access Point Name, 5G Public Network Integrated Non-Public Network, cellular Software-Defined Wide Area Network, Zero Trust Network Access or a site-to-site VPN; use complex unique device passwords; configure firewall rules or access control lists to allow only authorized communications between expected control system devices and block hosting-provider addresses; place physical and software key switches into the run position and validate project files before switching to run mode; practice and maintain the ability to operate operational technology systems manually; review project files for unauthorized changes using vendor integrity checking tools and visual comparison against known good logic; verify backups do not contain malicious logic before deployment; review logs and configurations on connected devices including modems, HMIs and workstations and reimage devices showing lateral movement; plan for end-of-life replacements. Second document, read in full and cited in the body: Cybersecurity and Infrastructure Security Agency, Alert, CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs, Release Date 30 July 2026, https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs. Verified verbatim in that document: CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers in the Water and Wastewater Systems Sector; 'Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations'; these threat actors are targeting water entities of all sizes; 'Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans'; operational technology assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and in severe cases physical damage; mitigations listed are to disconnect the PLC from the internet with remote access through a VPN or gateway device rather than directly to the PLC, enable password protection and change default passwords, allowlist IPs to permit remote access only from known engineering laptops or other critical OT assets, and after disconnecting ensure a known clean backup of the PLC image exists in case of lockout by a modified password; the alert carries a note directing owners of Rockwell Automation MicroLogix 1400 PLCs to Rockwell's notice on restoring access to a MicroLogix 1400 controller when the password is unknown; the alert points readers to the EPA's Cybersecurity Technical Assistance Program for the Water Sector. Third document, read in full and cited in the body: joint Cybersecurity Advisory AA26-097A, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure, https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a. Verified on both the CISA page and independently in the co-sealed PDF at https://www.ic3.gov/CSA/2026/260722.pdf, which was downloaded and extracted with PyMuPDF: Product ID AA26-097A; Publication 7 April 2026; Last Update 22 July 2026; marked TLP:CLEAR; co-authored by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, National Security Agency, Environmental Protection Agency, Department of Energy, United States Cyber Command Cyber National Mission Force, and Department of the Treasury, which is seven agencies. Verified in that advisory: the update adds guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs and 'expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs'; affected products are potentially all internet exposed PLCs; key actions include querying logs for suspicious traffic on the ports associated with OT devices, 'including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers', and placing the physical mode switch on Rockwell controllers into the run position; the named sectors are Government Services and Facilities, Water and Wastewater Systems, and Energy. Neither 30 July document attributes the incidents reported since 27 July 2026 to any named actor or state; that absence was checked against the full text of both..