Last week, unidentified malicious actors targeted water and wastewater systems across at least seven U.S. states. According to the FBI and EPA, the actors remotely accessed internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs), changed device configurations, and disrupted monitoring and control at some facilities.
What happened
On July 27, attackers hit the Clayton County Water Authority in Georgia—a system serving 300,000 customers. They caused a pressure drop that triggered a boil-water advisory. In Minnesota, over 30 community water systems were affected. The FBI reported flooding and pressure loss at targeted utilities. Operators were locked out of their own systems.
On July 30, the FBI and EPA issued a public service announcement urging critical infrastructure operators to protect internet-facing PLCs. The practical message was clear: directly exposing a PLC to the internet creates an immediate and serious risk.
If you operate a water utility, wastewater plant, manufacturing facility, or any industrial operation with remote-accessible SCADA systems in West Tennessee, this is not a distant problem. The same equipment and the same configuration mistakes may exist here.
What the Attackers Exploited
The FBI identified a recurring pattern across the reported incidents: malicious actors remotely accessed internet-facing PLCs and changed device configurations, including IP addresses and passwords. Several common security gaps can make this kind of activity possible or increase its impact:
- PLCs directly exposed to the internet. No firewall, no VPN, no jump host between the public internet and the controllers running physical processes. Attackers found them with basic internet scanning tools.
- Weak, default, or missing credentials. These remain a recurring risk in OT environments. In the separate 2023 Aliquippa, PA attack, Iranian-affiliated hackers accessed a Unitronics PLC using the default password "1111." The FBI has not said that default credentials were the entry point in every incident in the current wave.
- Insufficiently protected remote access. Remote connections without a secure gateway, tightly restricted access rules, strong authentication, and monitoring give operators fewer layers of defense against unauthorized access.
- No monitoring or alerting. In several cases, operators didn't know they'd been compromised until physical effects were visible—pressure drops, overflow alarms, locked-out interfaces.
As Joshua Corman told CBS News: "The bottom line is there's no one guarding these systems."
Why This Matters Beyond Water Utilities
Water utilities got the headlines, but the underlying risk—internet-exposed industrial controllers without sufficient access controls—can also exist in West Tennessee organizations such as:
- Municipal wastewater and stormwater systems using remote monitoring for lift stations and treatment processes
- Manufacturing plants with PLCs controlling production lines, HVAC, and environmental systems
- Agricultural operations with automated irrigation, chemical dosing, and grain handling systems
- Natural gas and propane distribution with remote pressure monitoring and valve control
- Building automation systems in hospitals, schools, and commercial properties
If your operation has a controller that someone can reach remotely—whether that's a Unitronics PLC, an Allen-Bradley, a Siemens S7, or an HMI panel with a web interface—the same attack pattern applies to you.
How to Secure Remote OT Access: 7 Steps You Can Take Now
You don't need a seven-figure budget. The attacks last week were not sophisticated—and neither are the defenses that would have stopped them. Start here:
1. Remove PLCs and HMIs from direct internet access immediately
No PLC should ever be reachable directly from the public internet. If you can reach your controller's web interface or programming port from outside your facility without a VPN, you are exposed right now. Disconnect it from the internet-facing network today. This is the single highest-impact action you can take.
2. Put all remote OT access behind a VPN with MFA
Every remote connection to your operational technology network should pass through a secure gateway, such as an appropriately configured VPN or jump host, that requires multi-factor authentication—something you know (password) plus something you have (authenticator app, hardware key). MFA could prevent or significantly complicate many credential-based attacks, but it should be combined with network segmentation, restricted access rules, monitoring, and removal of direct PLC exposure.
3. Change every default password and credential
Audit every PLC, HMI, switch, router, and gateway on your OT network. If anything still uses a factory-default password, change it now. Use unique, complex passwords for each device. Ideally, vault and rotate these credentials automatically so they can't be shared, written down, or reused.
4. Segment your OT network from your IT network
Your PLCs and SCADA systems should not be on the same network as your email, file shares, and workstations. A compromised office PC should never have a direct path to a controller. Use firewalls or managed switches to create a separate OT zone with strict rules about what traffic can cross the boundary.
5. Disable unused remote access services
Many PLCs ship with multiple remote access methods enabled by default: web servers, Telnet, SNMP, proprietary programming ports. If you're not using a service, disable it. Every open port is an attack surface.
6. Monitor and alert on OT network connections
You should know when someone connects to your SCADA systems—who, from where, and when. Set up logging on your VPN gateway at minimum. Ideally, deploy network monitoring that flags unexpected connections, new IP addresses, or access outside normal hours. Operators in last week's attacks didn't know they were compromised until physical damage was occurring. An alert on an unusual login would have given them minutes to hours of warning.
7. Have a manual operations plan
If your remote access is compromised, can your operators run the facility manually? The utilities that fared best last week were the ones whose staff could switch to manual control quickly. Know which valves, pumps, and processes need hands-on operation, and make sure your team practices it.
If steps 1–7 feel like more than your team can tackle internally, that's exactly the gap we fill.
Request a free consultationThis Is a Credential and Access Management Problem
At its core, every one of these attacks was a failure of credential and access management. Default passwords. Shared passwords. No password rotation. No access control beyond a single static credential.
This is one of the problems West Tennessee Software Solutions' Privileged Access Management (PAM) addresses. A PAM solution for OT environments vaults the credentials for your PLCs, HMIs, and network equipment; rotates them automatically; enforces who can access what and when; and logs every session for audit. Our Tennessee privileged-access playbook provides a broader starting point for inventory, ownership, least privilege, MFA, and review. PAM substantially reduces credential-based risk, but it must be part of a layered OT security program that also addresses internet exposure, segmentation, device configuration, patching, and monitoring.
You don't need the enterprise-scale PAM deployment that a Fortune 500 company runs. West Tennessee Software Solutions hosts a solution for municipal utilities or mid-market manufacturers that requires 0 additional staff and can be deployed rapidly to implement credential vaulting and rotation—the two controls that directly address how these attacks succeed.
PAM for OT — Without the Enterprise Price Tag
We deploy managed credential vaulting and rotation for PLCs, HMIs, and network equipment—hosted, monitored, and maintained so your team doesn't have to be.
See Our PAM ServicesThe Threat Is Not Going Away
This is not a one-time event. Nation-state actors—Iran, China's Volt Typhoon group, Russian hacktivists—have been targeting U.S. water and industrial infrastructure since at least 2021. The pace is accelerating. CISA's advisory was not a warning about a future risk. It was a response to active exploitation happening right now.
The FBI reported incidents in at least seven states, and the known cases may not represent the full scope. If your systems were probed or accessed, you might not know yet.
The question for every utility operator and plant manager in West Tennessee is not whether these attackers will scan your systems. They already have. The question is whether they'll find an open door—or a locked vault.
If the work spans policy, risk ownership, incident preparation, and remediation planning, fractional CISO support can help turn individual controls into a prioritized security program.
Secure Your Remote Access Before the Next Wave
We help utilities, manufacturers, and industrial operators in West Tennessee lock down remote access to SCADA and PLC systems—from emergency hardening to full PAM deployment. We'll identify which of your devices are internet-exposed and deliver a prioritized hardening plan within 48 hours. Free for local operators.
Request an OT Security Assessment