08/07/2026 | News release | Distributed by Public on 08/07/2026 14:27
WASHINGTON, D.C. - The FBI and U.S. Environmental Protection Agency have issued an alert that specifies vulnerabilities and details cybersecurity measures for water and wastewater utilities following reports of cyberattacks in at least seven states since July 27.
The federal agencies announced that malicious cyber actors remotely accessed internet-facing devices, such as programmable logic controllers, or PLCs. Attackers then changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality.
The alert identifies specific products that are vulnerable and recommends removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list to allow only authorized communication between expected control system devices.
Cyberattacks against public water systems that diligently work to ensure a clean, safe water supply are increasing. Cyber threats continue to evolve, and water agencies remain critical infrastructure targets.
ACWA recommends reviewing and reinforcing member agencies' current security protocols - including system monitoring, access controls, employee training and incident response plans - to help prevent, detect, respond and recover from cyber incidents. ACWA also urges coordination with local, state and federal partners and to report any suspicious activity promptly.
More information and links to resources are available in an Aug. 7 ACWA Advisory. Member login is required.