
The PLC cyberattacks targeting the Water and Wastewater Sector have prompted a joint warning from the , specifically the Allen-Bradley MicroLogix 1100 and 1400 series. The agencies warned that while the observed activity involved these devices, organizations using PLCs from other vendors should also review their attackers gained remote access to exposed PLCs connected directly to the internet and modified device settings, including IP addresses and operators to strengthen protections against similar attacks.
FBI and EPA Recommend Immediate Security Measures
To reduce the rules or access control lists (ACLs) so only authorized control system devices can communicate with PLCs.
Additional recommendations include placing hardware and software key switches in run mode to prevent unauthorized configuration changes, validating project files before returning devices to operation, reviewing PLC logic for unauthorized modifications, verifying backups before restoration, and examining connected devices for signs of incidents are encouraged to report them to their local FBI field office and submit a complaint through the Team.
The FBI, EPA, and partner agencies also referenced previously published guidance covering incident response, cybersecurity best practices for water systems, and secure connectivity principles for Operational Technology (OT) environments.
SOCIAL SHARE CARD GENERATOR