Executive Summary
In late July 2026, a series of cyberattacks targeted water and wastewater systems across at least 12 U.S. states, including Michigan, South Dakota, and Georgia. Attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), specifically the MicroLogix 1100 and 1400 models, to remotely alter configurations, leading to operational disruptions such as pressure loss and flooding. Despite prior federal warnings, over 4,000 such controllers remained accessible online, with 2,844 located in the United States.
This incident underscores the persistent vulnerabilities in critical infrastructure due to inadequate cybersecurity measures. The exploitation of known vulnerabilities in widely used industrial equipment highlights the urgent need for enhanced security protocols and the removal of operational technology from direct internet exposure to prevent future attacks.
Why This Matters Now
The recent cyberattacks on U.S. water systems reveal critical vulnerabilities in essential infrastructure, emphasizing the immediate need for robust cybersecurity measures to protect public health and safety.
Attack Path Analysis
Attackers exploited internet-exposed Rockwell Automation controllers in U.S. water systems, leveraging known vulnerabilities to gain unauthorized access. They escalated privileges by exploiting CVE-2017-16740, allowing remote code execution. Lateral movement was achieved by accessing interconnected systems within the control network. Command and control were established through persistent access to compromised devices. Data exfiltration involved unauthorized extraction of sensitive operational data. The impact included operational disruptions such as pressure loss and flooding.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited internet-exposed Rockwell Automation controllers in U.S. water systems, leveraging known vulnerabilities to gain unauthorized access.
Related CVEs
CVE-2017-16740
CVSS 10A stack-based buffer overflow vulnerability in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier, may allow remote code execution.
Affected Products:
Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers – Series B and C Versions 21.002 and earlier
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Wireless Compromise
Unauthorized Command Message
Device Restart/Shutdown
Loss of Safety
Loss of View
Loss of Control
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Boundary Protection
Control ID: SC-7
NIST SP 800-53 – Cryptographic Key Establishment and Management
Control ID: SC-12
NIST SP 800-53 – Cryptographic Protection
Control ID: SC-13
NIST SP 800-53 – Protection of Information at Rest
Control ID: SC-28
NIST SP 800-53 – Heterogeneity
Control ID: SC-29
NIST SP 800-53 – Concealment and Misdirection
Control ID: SC-30
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water and wastewater utilities face direct exposure to industrial controller attacks, with 4,000+ Rockwell devices vulnerable to remote code execution and operational disruption.
Government Administration
Municipal water systems under government oversight vulnerable to Iranian-linked attacks targeting programmable logic controllers, causing pressure loss and flooding in multiple states.
Industrial Automation
Critical infrastructure relies on exposed EtherNet/IP controllers susceptible to CVE-2017-16740 exploitation, enabling attackers to modify configurations and compromise operational technology systems.
Environmental Services
Wastewater treatment facilities exposed through internet-connected Allen-Bradley controllers, with attackers demonstrating capability to remotely change passwords and disrupt environmental protection operations.
Sources
- Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed onlinehttps://cyberscoop.com/exposed-rockwell-controllers-water-system-attacks/Verified
- NVD - CVE-2017-16740https://nvd.nist.gov/vuln/detail/CVE-2017-16740Verified
- Rockwell Automation Security Advisoryhttps://rockwellautomation.custhelp.com/app/answers/detail/a_id/1070883Verified
- ICS-CERT Advisory ICSA-18-009-01https://ics-cert.us-cert.gov/advisories/ICSA-18-009-01Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it enforces strict segmentation and identity-aware policies, which would likely limit unauthorized access and lateral movement within the network, thereby reducing the attacker's reach and potential impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF would likely limit unauthorized access by enforcing strict segmentation and identity-aware policies, reducing the attacker's ability to exploit exposed controllers.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the scope of privilege escalation by enforcing least-privilege access controls, reducing the attacker's ability to gain elevated privileges.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain lateral movement by enforcing strict segmentation and monitoring, reducing the attacker's ability to access interconnected systems.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the establishment of command and control channels by providing centralized monitoring and control, reducing the attacker's ability to maintain persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely constrain data exfiltration by enforcing strict egress policies, reducing the attacker's ability to extract sensitive data.
With Aviatrix Zero Trust CNSF, the operational impact would likely be constrained, reducing the scope of disruptions such as pressure loss and flooding.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Wastewater Management
- SCADA System Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Operational data related to water treatment processes and system configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to critical systems based on identity and context.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities like CVE-2017-16740.
- • Utilize East-West Traffic Security to monitor and control lateral movement within the network.
- • Establish Multicloud Visibility & Control to detect and respond to unauthorized command and control activities.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and mitigate impact.



