Article Read Time

Hackers reached critical infrastructure in at least a dozen states in under two weeks. Kentucky’s small utilities should assume they are on the same list.
In late July, the Clayton County Water Authority outside Atlanta watched its water pressure fall. The authority serves about 300,000 people. It issued a boil water advisory. A broken main or failed pump wasn’t the cause. Cyber activity on the plant’s control systems caused it.
Around the same time, more than 30 community water systems in Minnesota were hit over two days. Operators were locked out of their own controls. At least one facility went offline. Crews shut down the control computers and sent people into the field to operate the equipment by hand, as they had before any automation.
On July 30, the FBI and the Environmental Protection Agency issued a joint public service announcement. By the first week of August, water and wastewater utilities in at least 12 states had reported incidents, including Michigan, Georgia, New Jersey, and South Dakota. Federal officials have not formally named the culprit. Multiple reports point toward Iran-linked actors, who have been probing this same category of equipment since 2023.
No contamination of drinking water has been confirmed at any affected utility. That is worth saying plainly, and it is also not the same thing as saying nothing happened.
What the attackers actually did
The target was a programmable logic controller, or PLC. That is the small computer that tells a pump when to start and a valve when to open. The FBI named a specific family of them, the Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series, though the same reasoning applies to other brands.
These controllers were sitting on the open internet. The attackers reached them, changed their IP addresses, and set passwords. That was enough. The utility lost visibility into the equipment and, in some cases, lost the ability to control it. The FBI reports that the operational effects included pressure loss and flooding. Pressure loss matters more than it sounds. When pipe pressure drops far enough, untreated groundwater can seep in.
Notice what is missing from that description. There is no exotic malware. There is no zero-day. There is no team of geniuses. A small industrial computer answers when the internet calls, and no one ever changed the password.
That is the part that should bother every board and every city council in Kentucky.
Why this is not a surprise
I have spent more than 30 years in cyber security and critical infrastructure protection, in the U.S. Navy, with the FBI, and through InfraGard. I served as president of the InfraGard National Members Alliance, and I helped develop the process the FBI uses to coordinate domestic security information across the country.
InfraGard exists for exactly this moment. It is a partnership between the FBI and the people who run American infrastructure: plant operators, utility managers, and engineers. The idea is simple. The government cannot defend what it doesn’t own, and operators cannot see the threat picture without help. So you put them in the same room. Membership is free, and any water or sewer operator in the Commonwealth can apply at infragard.fbi.gov.
For years, the message coming out of those rooms has been consistent, and I have repeated it to anyone who would sit still for it. Water is the softest target in American critical infrastructure. This country has roughly 50,000 community water systems. Most of them serve small towns. Most of them have no full-time IT staff, let alone anyone whose job is security. The equipment lasts 20 or 30 years, which is a virtue in a pump and a liability in a computer.
Nobody wanted to hear it, because the fix costs money and the threat felt theoretical. It is not theoretical anymore. It is a boil water advisory in a county of 300,000 people.
What to do this week
The FBI and EPA recommendations are not complicated, and most of them cost more attention than money.
Get the controller off the public internet. It should sit behind a secure gateway and a firewall, with no inbound port exposed. If you use a cellular modem for remote field access, secure it with strong authentication, keep it updated, and enable logging.
Replace default and shared passwords with strong, unique ones. Restrict which devices can talk to the controller, using firewall rules or an access control list.
Put the physical and software key switches in the run position, and leave them there except when you are actively loading a program.
Practice running the plant manually. The Minnesota utilities got through this because their people could go out and do the job by hand. Test that capability before you need it.
Review the project files on your controllers against a known good copy. At least one organization in this campaign found its ladder logic had been altered across several sites.
And know what you are running. If a device is past end of life, the manufacturer is no longer patching it. Track those, set retirement dates, and isolate what you cannot replace yet.
If you see something that looks like this, call your local FBI field office, file at ic3.gov, and contact CISA at 1-844-729-2472.
A free assessment, while the funding lasts
Commonwealth Sentinel has received a grant to provide free cyber security assessments to publicly owned water and sewer organizations. No cost. No obligation. We will walk your systems, tell you plainly what we find, and hand you the findings whether or not you ever hire us for anything else.
Funding is limited, and we will schedule assessments in the order requests come in. When it is spent, it is spent. Contact us at 502-234-5554 or schedule a no-obligation meeting here.
A water system does not have to be large to be worth attacking. It only has to be reachable.
