Strategy & OperationsLegislative AffairsManufacturing & Materials

CISA Warns of Multi-State Cybersecurity Attacks on Utilities

Water utilities are told to disconnect, not to patch.

Josh LynwoodFounder
Published
Read time
15 min
Share
Where Things Stand

No Vulnerability, No Patch, and a Remedy Made of Labor

Between July 26 and 27, more than 30 Minnesota community water systems were targeted at once, and by July 30 the FBI had reports from utilities in at least seven states. The devices involved are small programmable logic controllers, the boxes that decide when a pump starts and when a valve opens. Nobody broke them. Someone changed the network address each controller answers on and switched on a password that had never been set, using services the industrial protocol these devices speak is specified to provide. Everything downstream follows from that: no identifier, no software update, and a remediation made of architecture and labor.

  • The Federal Instruction. The FBI and EPA public service announcement and CISA's alert, both dated July 30, tell utilities to take the controllers off the public-facing internet and broker any remote access through a secure gateway or jump host, with allowlisted sources and cellular modems secured, updated and logged. Neither document cites a A public identifier assigned to a specific software or hardware defect. Its absence from the documents here is the point: a device doing what its specification says it does is not a defect., a severity score or a weakness class, and neither cross-references CISA's April advisory on Rockwell A programmable logic controller, the small industrial computer that runs a physical process, deciding when a pump starts, when a valve opens and when an alarm sounds. targeting.
  • Where the Missing Patch Came From. The sentence that a Rockwell vulnerability cannot be mitigated with a patch is real, and it belongs to ICSA-21-056-03, the 2021 advisory for CVE-2021-22681. That advisory's affected-products list is seventeen Logix-family controllers reached through the Studio 5000 and RSLogix 5000 toolchain. MicroLogix appears nowhere in it. MicroLogix controllers are programmed with RSLogix 500 instead.
  • The Manufacturer Rules It Out. Rockwell Automation's notice SD1790, published July 30, is the document CISA points MicroLogix owners toward. It states that no CVE is associated with the notice and that it is operational recovery guidance rather than a vulnerability disclosure, and it describes actors turning on and setting passwords where no passwords were previously set.
  • What the April Advisory Actually Says. AA26-097A, the advisory that carries the CVE reference, does not cite it as the access method. Its initial-access technique is internet-accessible device, and its own account is that actors used configuration software to create an accepted connection to controllers deployed without sufficient network and hardening security controls. Its named targets are CompactLogix and Micro850, and Micro850 is a Micro800-family controller that is not on the CVE's affected-products list either.
  • Recovery Is Physical. Per the vendor notice, a locked MicroLogix 1400 is recovered by powering it down and removing its battery to clear memory; a locked 1100 needs a firmware update over a serial connection. The procedure erases the program, so it also requires a trusted offline copy of the project file, and the FBI and EPA warn that at least one organization found modified project files after noticing The rung-by-rung control program a PLC runs, held in a project file. Changing it changes the rules the plant obeys without changing what the operator's screen shows. discrepancies across several sites.
Sources7See all 46
Why is the only federal instruction to unplug it?

There Is No Patch Because There Is No Defect

The July 30 documents name no public vulnerability identifier, no severity score and no weakness class, and the manufacturer's own notice of the same date says outright that none is associated with it and that the document is operational recovery guidance rather than a vulnerability disclosure. That is not an omission. A controller's network address is a settable attribute of a standard object in the industrial protocol, and the controller password on this product line is an opt-in feature nobody had switched on. Querying a device for what it is happens to be a service the protocol is specified to provide. Firmware that refused a well-formed request on a service it is specified to offer would break commissioning, which is why the federal mitigation lists carry no software update.

The patch sentence in circulation belongs to a different advisory and a different product. "Cannot be mitigated with a patch" comes from the 2021 Rockwell advisory for CVE-2021-22681, whose affected-products list is seventeen Logix-family controllers reached through the Studio 5000 and RSLogix 5000 toolchain. MicroLogix appears nowhere on it, because MicroLogix controllers are programmed with RSLogix 500 instead. Even the April advisory that carries that identifier does not name it as the access method: its initial-access technique is an internet-accessible device, and one of its two named targets is not on the affected-products list either.

What is left is architecture and labor. Authentication, message integrity and encryption reach the base protocol only through a security extension present where a device implements it, so the only lever anyone has is who can reach the port: controllers off the public internet, remote access brokered through a gateway or jump host, allowlisted sources, cellular modems secured and logged. Recovery is physical too. A locked MicroLogix 1400 is cleared by powering it down and pulling its battery; an 1100 needs a firmware update over a serial connection. The procedure erases the program, so it also requires a trusted offline copy of the project file.

Sources18See all 46
Intersections

The exposure runs through who can reach the port

Cybersecurity & Privacy. A controller's network address is a settable attribute of a standard object in the industrial protocol, and the controller password on this product line is an opt-in feature that had not been set. The same standard object carries mandatory read-only attributes including vendor ID, device type, product code and revision, and the protocol's founding design paper states that this data can be queried from a target node without knowing physically what that device is before the message is issued. Enumeration is a specified service, not a discovered weakness, which is why the exposure claim here does not rest on a scan. Authentication, message integrity and encryption reach the base EtherNet/IP protocol only through CIP Security, which ODVA describes as a network extension, present only where a device implements it. Firmware that refused a well-formed request on a service it is specified to offer would break commissioning, which is why the federal mitigation lists contain no software update.

Manufacturing & Materials. CISA's sharpest sentence is about assets nobody knows they own: the targeting includes cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans. A modem at an unstaffed well gives the controller a second path that never crosses the utility's firewall. Censys counted 4,148 hosts self-identifying as Rockwell or Allen-Bradley on EtherNet/IP in a July 30 snapshot, with cellular carriers accounting for 59.0% of them, and states plainly that this is an exposure characterization and not a list of victims.

What would make this wrong

A vulnerability identifier issues for the July activity on this controller line, or the vendor ships firmware that refuses the request. There would have been a defect to patch after all.

Open question

On the security side: enumeration is a service the protocol is specified to offer, so which layer decides who may ask, the device, the network or the integrator who specified it?

Sources5See all 46
The Weave

The Weave maps a single development across domains and across time. Each row follows one domain from where things stand now through the next eighteen months, and expands for the reasoning behind that trajectory.

Wiiver
SECTOR / DOMAINclick a domain to expand
As It Standsthe current status
Immediate0–6 months
Near-Term6–18 months
Business + Markets
Disconnection withdraws the remote path that stood in for staff. Manual operation is a staffed shift, not a setting.
Remediation is payroll
Taking controllers off the internet withdraws the remote path that let thinly staffed plants run without a person present.
Capex funded, opex is not
Gateways and network redesign can be borrowed against; log review, drills and site visits land in the operating budget.
Government + Policy
State revolving funds already cover the hardware. Log review, drills and site visits have no financing term at all.
The authority already exists
Federal loan programs already cover this work, so no new authority is needed to finance a gateway or controller replacement.
Two bills, no motion
Both pending water-cybersecurity bills were introduced in spring 2025, and neither has recorded committee action since referral.
The July 30 instruction is advice. AWIA requires a system to assess and plan, not to fix, and EPA receives a certification.
Advice, not orders
The July 30 documents recommend rather than require, so compliance is a local budget and staffing decision, utility by utility.
Attestations, not findings
Systems certify that an assessment was done rather than filing it, so no federal record can be queried for exposed controllers.
Technology + Engineering
Recovery is physical and per site. Clearing a locked controller erases its program, so a trusted offline copy must exist.
Recovery needs a truck
Restoring a locked controller is an on-site procedure that erases the program, so recovery scales with trucks and technicians.
Undeclared interfaces
Federal responders flagged cellular modems that never appear in a utility's attack-surface scan, so inventory gates remediation.
wiiver.co · 4 impacted domains shownWiiverv1 · August 3, 2026
Looking Forward

Gateways Are Easy to Buy. The Capability Is What Decides

One dated federal certification requirement sits inside the forward window. Everything else in this story is a signal that either appears or does not, and each of the following can be checked against a published record.

  • The December Certification. Community water systems serving 3,301 to 49,999 people must certify an emergency response plan by December 31, 2026, six months after the risk-assessment certification date that passed about four weeks before the attacks. Individual systems run on a five-year clock from their own prior certification, so this is a class-wide date rather than a universal one, and what it certifies is a written plan, not a controller's exposure.
  • A Follow-On Federal Product. Whether CISA, EPA or the Water Sector Coordinating Council publishes anything that characterizes the shared third-party network setups the FBI and EPA flagged. Such a document would convert a stated mechanism into a documented cause. Its absence is why the propagation finding remains a hypothesis the agencies themselves wrote as may, and why no federal program currently measures the market that produces the builds.
  • Whether States Keep Outrunning EPA. The sharpest instrument in the sector is Idaho's. Its environmental quality department awards revolving-fund scoring points for Cyber-Informed Engineering, an approach EPA's own paper on revolving-fund projects describes as emphasizing the design of engineered cyber controls into the infrastructure. That is a funding lever that pays for engineering rather than paperwork. The same paper records that Indiana requires all community water systems to fold cybersecurity risk assessments into their asset management plans, and that New York requires systems serving 3,301 or more people to file a five-year emergency plan carrying a cybersecurity vulnerability analysis. States are already requiring what the federal record cannot collect, and whether others copy Idaho is checkable.
  • Whether the Vendor List Grows. The FBI says it has only observed this behavior with the referenced Rockwell controllers but that similar considerations should be made with other branded PLCs, and CISA's July 22 update had already widened observed targeting to Schneider Electric and Siemens. Any product name treated as the boundary of the problem is a snapshot with an expiry date, and so is any state count.
  • The Tell. If the sector's answer is gateways and the operating budgets do not move, the exposure returns the first time a utility needs to see a remote site and has nobody to send. If utilities instead start holding verified offline project files, practicing manual operation at unstaffed sites and inventorying the modems installed on their behalf, the capability that decides the next event was actually built. The first is easier to buy. The second is what the federal documents ask for.
Sources5See all 46

Every issue

  1. 01Intersection of the week
  2. 02Impact of the week
  3. 03The week in review

Wiiver Weekly

One free email, Saturdays at 7:00 AM ET.

Unsubscribe anytime.

Sources and Verification
39 of the 46 sources cited here are primaryfilings, opinions, statutes and agency releases read directly
Primary sources39
Secondary sources, by sector7
Business + Markets2
Technology + Engineering3
Other2
v2 · Reviewed by Josh Lynwood · August 3, 2026
Back to top