Aug 7, 2026
Policy

Water system PLC attacks prompt former NSA chief to urge internet isolation

The FBI says attacks on water and wastewater PLCs disrupted operations in at least seven states, while Iran has not been officially blamed.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Water system PLC attacks prompt former NSA chief to urge internet isolation
Photo: The Register

Water system PLC attacks reported in at least seven states have prompted retired Gen. Paul Nakasone, the former National Security Agency director, to call for controllers at water utilities to be kept off the internet. The FBI and Environmental Protection Agency said on July 30 that malicious actors had targeted internet-facing control equipment since July 27, disrupting some water operations.

The agencies said their confirmed cases involved Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers, or PLCs. These industrial computers can monitor processes and control connected equipment. The FBI said it had observed the behavior on those models but advised operators of other PLC brands to apply similar safeguards.

According to the FBI and EPA alert, attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and left utilities without monitoring and control functions. Reported effects included flooding and loss of water pressure. The agency said a pressure loss can create a risk that untreated groundwater enters pipes.

Speaking to reporters at DEF CON, Nakasone said PLCs should not be connected to the internet and that utilities need higher security standards. The former NSA chief, now founding director of Vanderbilt University’s Institute of National Security, also argued that water-system defense requires more partnerships among operators, government and security practitioners, The Register reported.

What should water utilities do after the PLC attacks?

The FBI and EPA did not call for abandoning remote access altogether. Their guidance is to remove direct inbound internet exposure and route any necessary remote connection through a secure gateway, or jump host, that brokers, monitors and controls access.

The alert also recommends unique, complex passwords; firewall rules or access-control lists restricting communications to authorized systems; and secured cellular modems with logging enabled. The agencies said the effect of a compromise depends on the controller’s role and a utility’s ability to shift to manual operations.

That is a narrower operational distinction than a blanket “air gap” prescription: internet-connected industrial-control equipment should not accept direct public access, while remote administration, if required, should be controlled and monitored. It is also the kind of layered work described in an enterprise security program, rather than a product decision.

Has the US attributed the water system PLC attacks to Iran?

No. The FBI and EPA alert did not identify a country or group. The Register reported that private-sector researchers suspect Iranian involvement and that Nakasone pointed to Iran’s history and capability in attacks against water infrastructure. But neither the FBI nor the Trump administration had officially blamed Iran at the time of his remarks.

Reports have cited a higher number of affected states, including at least 12 in The Register’s reporting. The federal baseline remains at least seven states, based on incidents reported to the FBI as of July 30. For utilities and industrial vendors, the immediate finding is less about attribution than an exposed class of controllers and the operational consequences when their configuration and access are altered.

This story draws on original reporting from The Register.

More from Policy

All Policy →