Blog

Water Week: July 2026
Three headlines, one sector, one week.

By Mary Gannon, Director of OT Resilience, Copia Automation

Water Week: July 2026 

This has been quite a week for the water and wastewater sector. Four cities in Minnesota state, all experienced different impacts from a coordinated cyber attack. A common thread: safe water was sustained. Days later, CISA and the FBI/EPA both laid out for the rest of the sector how exposure occurs in the first place, and what it takes to fix it. Minnesota shows what resilience looks like when it holds up during a real attack. The CISA and FBI/EPA releases signal that exposure is sitting out there for the rest of the sector to remediate before a threat actor exploits it. 

Without resilient infrastructure, unauthorized changes to PLC code can go unnoticed until an operational failure occurs. True preparedness goes beyond merely preventing an attack; it encompasses the capacity to rapidly detect and restore operations safely in the event of a compromise.

Resilience in Action: Minnesota Water Utilities 

On Sunday, July 26th and Monday, July 27th, 2026, a coordinated cyber attack hit more than 30 Minnesota community water systems, disrupting water and wastewater utility operations. Braham, Plymouth, South St. Paul, and Maple Plain have all publicly disclosed attacks.

The cyber attack triggered a plant-wide outage in Braham, specifically shutting down the operating controls which subsequently stopped the well and water treatment plant. Although the incident did not affect water safety, quality, or the physical plant itself, the city had to rely on the water stored in the water tower to supply its residents. In the City of Braham’s statement, they mention that the state of Minnesota is assisting “with information and resources to mediate any vulnerabilities, as well as investigating the source of malicious malware”. As of Monday, July 27th at 1125am local time, the water plant was back online and functioning as expected. 

The cyber attack affected the utilities in Plymouth and South St. Paul differently. In Plymouth, the incident impacted cellularly connected equipment within “two of the city’s water towers and multiple lift stations within the city.” Crews relied on manual operational procedures until water communications were successfully restored. In South St. Paul, the “incident affected certain automated controls,” but Public Works staff immediately executed established contingency procedures to ensure normal water and wastewater operations were maintained.

In Maple Plain, on July 27th, “the Mayor of the City of Maple Plain issued Proclamation No. 2026-1 declaring a Local Emergency due to malicious activity impacting the City’s public drinking water system.” The City Water Plant “continued operating the water and wastewater systems using established contingency procedures.” Drinking water service was not interrupted, and the city terminated the Local Emergency on July 29th. 

All four cities experienced different impacts simultaneously, which is exactly what makes this event significant from an OT resilience standpoint. Braham lost operating controls entirely and fell back on stored water tower capacity. Plymouth lost cellular connectivity to remote sites and returned to manual field operations. South St. Paul lost automated controls but kept normal operations running through existing contingency procedures. Maple Plain declared a full Local Emergency while manually sustaining plant operations. Four different attack surfaces, four different operational responses, and in every case, the same outcome: the water remained safe and service was never interrupted for the public. 

By having contingency plans in place, Braham, Plymouth, South St. Paul, and Maple Plain were able to maintain resilience as the incidents unfolded. This event is a reminder that resilience in OT comes down to whether the process keeps producing a safe outcome, even after a threat actor gets in.

CISA Water and Wastewater Systems Sector Alert

On Thursday, July 30th, 2026, CISA released a new alert specifically for the Water and Wastewater Systems (WWS) Sector, warning of a significant increase in threat actors targeting programmable logic controllers (PLCs) within the sector. CISA is urging owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Observed activity includes threat actors modifying passwords to lock out legitimate operators, and disconnect the PLCs by altering their IP addresses. This threat actor activity has already resulted in boil water notices and forced utilities into sustained manual operations.

What distinguishes this alert is the breadth of exposure it describes. CISA notes that threat actors are targeting water entities of all sizes, and even organizations with mature cybersecurity processes should validate their external connections. External exposure includes cellular modems installed by operators, vendors, or system integrators that may not be documented and fall outside routine attack surface scans. Without visibility into these connections, an organization’s actual internet exposure can differ from what its security team believes it to be, leaving a gap that goes unnoticed until a device has already been compromised. 

CISA Mitigation and Recovery Recommendations

CISA’s recommendations center on reducing exposure and preparing for recovery if a compromise occurs. Organizations should disconnect PLCs from the internet, routing any necessary remote access through a VPN or dedicated gateway device rather than directly to the PLC. Password protection should be enabled with default passwords changed. Allowlisting IPs should restrict remote access to only known engineering laptops or other trusted OT assets. Before disconnecting PLCs from the internet, CISA advises that “operators should ensure they have a known clean backup of the PLC image,” since a modified password could otherwise leave them locked out of their own equipment. Owners of Rockwell Automation MicroLogix 1400 PLCs should refer to Rockwell Automation’s guidance on restoring access when the password is unknown for this specific scenario.

Water and wastewater utilities are being targeted no matter their size or how mature their security program is, with exposure even sitting outside of what the internal teams can see. Taking PLCs off the internet addresses this specific activity, but it doesn’t remove the underlying risk of running critical infrastructure on internet-connected OT in the first place. A known-good backup won’t stop an attacker from getting in, but it’s often the difference between a quick recovery and an extended outage. The utilities that come out ahead here are the ones treating exposure reduction as ongoing work rather than a task to close out because of an alert.

FBI/EPA Joint Water and Wastewater Sector PSA 

The FBI and EPA issued a joint Public Service Announcement warning critical infrastructure asset owners and operators of malicious cyber actors targeting operational technology devices, including Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 series programmable logic controllers (PLCs). Since July 27, 2026, Water and Wastewater Sector utilities in at least seven states have reported incidents to the FBI, with some of the reported activity degrading water operations. The FBI has only observed this behavior with the referenced Rockwell PLCs, but the agencies advise that similar considerations should apply to other branded PLCs as well.

According to the PSA, the actors gained remote access to internet-facing devices and reset IP addresses and passwords, cutting off the ability to monitor and control the assets. At least one organization identified modified PLC project files after noticing ladder logic discrepancies across several sites. The agencies also noted that similarities in network configurations set up by third parties may give the actors an opportunity to repeat successful intrusions across other customers with comparable network and hardware setups.

Reported operational effects have included loss of pressure and flooding, with pressure loss creating the potential for untreated groundwater to seep into distribution pipes. The extent of impact at each victim site depended on the function the PLC was configured for, whether it was used for monitoring or controlling equipment, the specific device model, and the ability to switch to manual operations.

FBI/EPA Mitigation and Recovery Recommendations

The PSA recommends removing PLCs from direct internet exposure through a secure gateway or jump host, securing and logging cellular modems used for remote field connectivity, and enforcing strong, unique device passwords. Organizations are also advised to configure firewall rules or access control lists so that only authorized communications between expected control system devices are permitted, and to keep physical and software key switches in the run position except when actively updating logic, configuration, or firmware.

On recovery specifically, the FBI and EPA recommend that organizations practice and maintain the ability to operate OT systems manually, and routinely test business continuity plans, fail-safe mechanisms, islanding capabilities, software backups, and standby systems. Project files running on PLCs should be reviewed for unauthorized changes, comparing the running program against known good logic. If a backup is used to restore a device, the PSA specifies that the backup must be verified as free of malicious logic before deployment. Organizations should also review logs and configurations on connected modems, HMIs, and workstations to assess potential lateral movement, and reimage any device where unauthorized access is suspected.

The PSA closes with guidance on end-of-life (EOL) planning. “Since EOL devices no longer receive security updates, they are routinely targeted” by threat actors. The FBI and EPA recommend maintaining a rolling 12-month forecast of end-of-life devices, reviewed quarterly with system owners and procurement teams. Preparedness in OT extends beyond preventing initial access. It also requires the ability to quickly detect unauthorized changes and safely restore operations once a compromise has occurred. This PSA reinforces a consistent theme across recent OT guidance: exposure reduction and recovery readiness work together. A validated, malware-free backup and a tested recovery plan are what allow an organization to confirm the scope of a compromise and restore safe operations once actors have changed device passwords or configurations.