Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure
Attackers disrupted US water utilities via exposed Rockwell controllers, alongside other industrial-control campaigns.
PolySwarm and prior reporting describe several campaigns abusing exposed industrial controllers, including attacks from July 27, 2026, on internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 controllers at US water and wastewater utilities in at least seven states. Intruders changed passwords and network settings and, in at least one case, modified controller logic; reported effects included flooding and lost water pressure. The FBI warned that sufficiently low pressure could let untreated groundwater into pipes, but contamination was not confirmed, and the July activity has not been publicly attributed. Separately, CyberAv3ngers compromised at least 75 Unitronics devices between November 2023 and January 2024 using default or absent passwords, while US agencies assess Volt Typhoon intrusions as access for possible future disruption.
- From July 27, 2026, water utilities in at least seven states reported attacks on exposed Rockwell MicroLogix 1100 and 1400 controllers.
- Attackers changed passwords and addresses; at least one site found altered project files and logic, with flooding and lost pressure.
- The FBI warned low pressure could allow untreated groundwater into pipes; contamination was not confirmed, and the campaign is unattributed.
- CyberAv3ngers previously hit at least 75 Unitronics devices using default or missing passwords; Volt Typhoon is assessed as pre-positioning.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498 | 39b87 Malware sample associated with CyberAv3ngers. SHA-256 1b39f9b2b96a6586c4a11ab2fdbff8fdf16ba5a0ac7603149023d73f33b84498 Malware sample associated with CyberAv3ngers. SHA-256 3e4bb |
| sha256 | 20215acd064c02e5aa6ae3996b53f5313c3f13625a63da1d3795c992ea730191 | de5c Malware sample associated with GRU Unit 29155. SHA-256 20215acd064c02e5aa6ae3996b53f5313c3f13625a63da1d3795c992ea730191 Malware sample associated with GRU Unit 29155. SHA-256 3fe9 |
| sha256 | 3e4bb8089657fef9b8e84d9e17fd0d7740853c4c0487081dacc4f22359bade5c | 84498 Malware sample associated with CyberAv3ngers. SHA-256 3e4bb8089657fef9b8e84d9e17fd0d7740853c4c0487081dacc4f22359bade5c Malware sample associated with GRU Unit 29155. SHA-256 2021 |
| sha256 | 3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642 | 0ae9c2 Malware sample associated with Volt Typhoon. SHA-256 3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d34807642 Malware sample associated with Volt Typhoon. SHA-256 f4dd44 |
| sha256 | 3fe9214b33ead5c7d1f80af469593638b9e1e5f5730a7d3ba2f96b6b555514d4 |
Full article881 words · extracted from cybersecuritynews.com · click to collapse
Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services.
Recent incidents show that poorly protected equipment can give attackers direct access to physical operations, with consequences ranging from lost monitoring to flooding and reduced water pressure.
The threat involves several campaigns rather than one newly discovered malware family. Attackers exploit exposed devices, weak passwords, insecure remote access, and legitimate engineering functions.
These weaknesses can let intruders change how equipment operates without deploying sophisticated industrial malware. Analysts from PolySwarm noted this growing risk in an assessment published October 5, 2026.
PolySwarm said in a report shared with Cyber Security News (CSN) that civilian infrastructure compromises can also affect military operations when bases depend on external utilities and suppliers.
The report separates confirmed controller attacks from reconnaissance and preparations for possible future disruption.
That distinction matters: some intrusions have already affected physical processes, while others establish access that could become dangerous during a crisis or conflict.
Hackers Exploit Exposed Industrial Controllers
Beginning July 27, 2026, water and wastewater utilities in at least seven states reported attacks against internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 controllers.
Previous reporting on exposed Rockwell industrial controllers illustrates why equipment reachable from public networks presents such a persistent concern.
Attackers changed passwords and network addresses, interfering with operators’ ability to monitor or control equipment.
At least one affected organization discovered modified controller project files and discrepancies in the programming logic used to manage physical processes.
Reported consequences included flooding and lost water pressure. The FBI warned that sufficiently reduced pressure could potentially allow untreated groundwater into distribution pipes.
This was a warning about possible contamination, not confirmation that contamination occurred during the reported incidents. Authorities have not publicly attributed the July campaign to Iran, Russia, or another named group.
PolySwarm cautioned against merging it with separate Iranian-affiliated activity simply because both involved exposed industrial controllers and disruptive changes.
Earlier attacks against Unitronics controllers demonstrate how basic security failures can produce serious consequences. Between November 2023 and January 2024, CyberAv3ngers compromised at least 75 devices, including at least 34 in the US water and wastewater sector, using default passwords or devices without password protection.
The attackers erased original control logic, installed replacement programming, renamed devices, and altered configurations and ports.
A separate Iranian-affiliated campaign reported in April 2026 disrupted controller operations and manipulated information shown to operators, but officials have not explicitly attributed that campaign to CyberAv3ngers.
Infrastructure Protection
The broader concern extends beyond individual utilities. US agencies assess that Volt Typhoon infrastructure intrusions are intended to establish access that could enable disruption during a future crisis.
The group often relies on legitimate administrative tools and stolen credentials rather than distinctive malware. Military installations depend on civilian electricity, water, communications, transportation, fuel, and industrial suppliers.
Disrupting those services could hinder missions without breaching military networks. The report does not establish that the July water attacks specifically targeted military operations.
Meanwhile, pro-Russian groups have been hijacking exposed VNC connections to reach industrial interfaces. Authorities warn that these actors sometimes exaggerate their achievements, yet have also caused actual harm. Limited technical skill does not eliminate the risks of manipulating unfamiliar equipment.
PolySwarm recommends removing unnecessary internet exposure, eliminating default credentials, restricting remote access to authorized users, and monitoring remote sessions.
Operators should also separate business networks from industrial environments and watch for intrusion paths that could bridge the two.
Recovery planning should preserve trusted controller configurations, project files, programming logic, firmware details, and network settings. Teams need tested manual operating procedures when remote control becomes unavailable or unreliable.
Utilities and military planners should map shared dependencies and rehearse cascading outages, coordinating cybersecurity, engineering, operations, and emergency management before disruption occurs.
The report also lists malware sample hashes associated with four featured threat actors. These indicators are reproduced below exactly as supplied; their inclusion does not establish that the samples were deployed in the July water attacks or every campaign discussed here.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.