I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up, but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level. These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work on limited budgets [0], it seems hard to get all 148,000 [1] system operators to afford to care—much less to check their work.
Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.
They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.
Wasn't there a Defcon or Derby talk about this years back? (The insecurity, not the Persian angle)
Struggling for a source.
Guy had the energy of that one Simcity 2000 character who bugs out if you cut back on funding that you'll regret it. Early twenty aughts IIRC?
Not sure about defcon, but Buckminster Fuller wrote waay back in the sixties about the New York's vulnerability to a fresh water supply attack.
If you haven't read it Operating Manual For Spaceship Earth is one of my favorite books.
https://archive.org/details/operatingmanualforspaceshipearth...
I think this landscape is littered with simulated systems as honeypot. Once you have it a normal adversary would stop searching, besides regular checks that the gun still works.
https://archive.is/fa2Xj
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.
https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...
Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!
Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
I mean
Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…
It’s probably not how you or I would set things up, but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level. These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work on limited budgets [0], it seems hard to get all 148,000 [1] system operators to afford to care—much less to check their work.
[0] https://www.gao.gov/assets/d24106576.pdf
[1] https://www.epa.gov/dwreginfo/information-about-public-water...
Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.
https://news.ycombinator.com/item?id=39243560
https://web.archive.org/web/20240409155326/https://www.awwa....
(cybersecurity practitioner is a component of my professional persona)
Is this the true reason for the cyclosporasis outbreaks?
Nah. Cyclospora is a parasite, not a virus.
[Riffing on the gag, not an actual misunderstanding, just to be clear.]
Can we still blame Mexico, Taylor Farms and Taco Bell as well?
They always point to a state actor to skirt liability for their own shitty IT work. Then the dim evil journalists swallow it whole, later regurgitating it for their eager little baby bird subscribers.
If there were actual penalties for rawdogging a PLC (or any other control system) on the internet, shit like this wouldn’t happen.
<adjustsTinFoilHat> The Trump plan in Iran is not working. Gotta make them look like the evil bogeyman to get people to support further action.
Iran is beside the point. There is always a convenient bogeyman: China, Russia, North Korea… They sow discord between peoples to cover-up the ineptitude of domestic institutional assholes.
Blacks.
Homosexuals.
Communists.
Islamics.
Hispanics.
Liberals.
Intellectuals.
There’s always an other. That’s what the Republicans have been doing for decades.
This conspiracy theory would make more sense if he wasn’t working so hard to divert blame away from Iran: https://www.politico.com/news/2026/07/31/trump-minnesota-wat...
> “I blame it on Minnesota because they are grossly incompetent,” Trump said at a cabinet meeting at Camp David on Friday, adding that Walz is “corrupt” and “Iran has bigger problems than worrying about Minnesota.” Asked later if he could rule out Iranian responsibility, Trump said, “ I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”
As if it were only Minnesota. But his base doesn’t pay attention to details.
> “I think Minnesota is behind it,” Mr. Trump said on Friday in response to a reporter’s question about Iran’s possible involvement,
What a coward and a traitor to the American people.
He knows he brought these attacks with his war, but he doesn’t take the blame for anything.
Either he knows and doesn't want to take the blame, or he doesn't know. I'm not sure which one is worse.
He stopped going to security briefings before, maybe he simply doesn't care to know.
> he brought these attacks with his war
I'm no Trump supporter and this war was a big mistake, but justifying a nation poisoning another's civilian water supply is a bit upside down.
Yeah, what could we possibly have done[0] to justify an attack on our water supply????
[0]: https://www.commondreams.org/news/iran-water-desalination-pl...
Ask the people of Flint, Michigan?
We don't follow "rules" in war anymore, according to "Secretary of War" Pete Hegseth. We show no quarter and take no prisoners, we pursue "maximum lethality, not tepid legality."
That's American policy now. The gloves are off, no holds barred, everything and everyone is on the table. So I guess we reap what we sow.
I hope it gets bad enough people wake tf up and do something with me about it.
It was probably the same (imaginary) people who damaged the lining of the Reflecting Pool.
I think we should think about making blatant lies by politicians a crime.
What's one more crime compared to all of the ones they've already committed?
If I was in a power position, I could theoretically channel this water into my own private reservoirs and locations like private land, bunkers, etc to weather a disruption, and blame Iran and it would be really hard to validate.
I mean if I was in a power position I would have also disrupted those in positions who would be validating me, made journalism much harder and have algorithms with LLM-enhanced astroturf accounts running to label any questioning of the official narrative as conspiratorial or tin-foil hat.
I would probably be on sites like this downvoting people who said things like this. Yes. That's how I would do it. edit: Oh I might even consider channeling that water to my data center friends!
You know water is kind of big right?
I understand being mad, I also get mad.
This is a bit unhinged.
We used to say that about some things before Snowden. And then there was Snowden.
But they wouldn't need to false-flag an excuse to capture and privatize resources, they could and would just do that openly. The government can just take whatever it wants through eminent domain.
In this war initiated by USA and Israel, it isn't Iran who's attacking civil targets.