Defcon Alerts Threat Monitor

Defcon Alerts Threat Monitor

Cyber/Tech

FBI and EPA Warn of Cyber Attacks on Internet-Facing Controllers in Water Systems

Since July 27, utility companies in at least seven states have reported incidents to the FBI, with some of the activity degrading water operations.

Defcon Level's avatar
Donald Standeford's avatar
Defcon Level and Donald Standeford
Jul 31, 2026
∙ Paid

WASHINGTON — The Federal Bureau of Investigation and the Environmental Protection Agency issued Public Service Announcement I-073026-PSA on July 30 stating that malicious cyber actors have conducted cyber attacks against Operational Technology devices, specifically Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series Programmable Logic Controllers, in the Water and Wastewater Sector.

Share

Anthropic Claude Models Breach Production Systems of Three Organizations

Anthropic Claude Models Breach Production Systems of Three Organizations

Defcon Level and Donald Standeford
·
4:37 AM
Read full story
UAE Thwarts Series of Sophisticated Cyberattacks Targeting Financial Sector

UAE Thwarts Series of Sophisticated Cyberattacks Targeting Financial Sector

Defcon Level and Donald Standeford
·
Jul 3
Read full story
Increase Of Cyberattacks On Critical US Water Infrastructure. Every Critical Infrastructure Sector Targeted

Increase Of Cyberattacks On Critical US Water Infrastructure. Every Critical Infrastructure Sector Targeted

Defcon Level and Donald Standeford
·
May 20, 2024
Read full story

More Cyber/Tech Alerts

Since July 27, utility companies in at least seven states have reported incidents to the FBI, with some of the activity degrading water operations. After remotely accessing internet-facing devices, the actors changed IP addresses and passwords, producing a loss of monitoring and control functionality.

Refer a friend

The Cybersecurity and Infrastructure Security Agency stated on July 30 that it is observing a significant increase in cyber threat actors targeting programmable logic controllers in the Water and Wastewater Systems Sector.

The activity has resulted in boil water notices and sustained manual operations. CISA noted that the targeting includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.

Observed Configuration Changes and Operational Effects

Defcon Alerts Threat Monitor is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

This post is for paid subscribers

Already a paid subscriber? Sign in
Donald Standeford's avatar
A guest post by
Donald Standeford
Founder of The Standeford Journal. I'm an American independent investigative journalist, intel/geopolitical analyst, and world traveler.
Subscribe to Donald
© 2026 Defcon Level · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture