ctipilot.ch
← Back to Weekly 2026-W32
NOTABLEupdateNATOB2synthesis

Water-sector PLC lockout status: the FBI has now named the targeted controller family — Rockwell MicroLogix 1100 and 1400 — while still declining to name an actor, and a 300,000-customer boil-water advisory in Georgia is the largest disclosed population impact so far

discovered 2026-08-09 23:45 UTCrun 2026-08-09T2315Z-weekly2 sourcesmulti-source

UPDATE · originally covered Water-sector PLC lockouts went from one state to seven inside the week, and the European exposure got counted — 86% of 4,117 internet-facing Siemens S7-1200 units sit in four EU countries, reached through mobile carriers (2026-08-02)

the prior weekly consolidated this campaign for its European exposure, on the observation that the entry point is reachability plus credential control rather than any vulnerability, and that a scan had counted thousands of internet-exposed programmable logic controllers in EU countries concentrated behind mobile carriers. Three things changed inside 2026-W32, and only one of them is directly actionable outside the United States.

The actionable one is a device family. Per Tenable's tracking of the FBI and EPA joint public service announcement issued on 30 July, "the FBI stated that reported operational effects have included pressure loss and flooding, and identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as the targeted devices" (Tenable Research Special Operations, 2026-08-06). Until this week the campaign had been described to defenders in terms of what the attackers did — changing controller addresses and passwords, in at least one case modifying ladder logic — without a controller family to inventory against. A European water or wastewater operator now has a concrete, bounded question to answer about its own estate rather than a general exhortation about exposure.

The second is scale of consequence. The same source records that the "activity caused a pressure drop at the Clayton County Water Authority, prompting a boil-water advisory for the utility's 300,000 customers in the Atlanta area. The authority restored service within hours." The pipeline covered Clayton County's own confirmation on 6 August; the population figure is the part that was not carried, and it is the largest disclosed single-utility impact of the campaign. Tenable also records that CBS independently confirmed the twelve-state scope on 6 August, following the ABC report of 4 August that first put the count there.

The third is a gap that has now persisted long enough to be a finding in its own right. No US authority has publicly attributed the campaign: the joint announcement "does not attribute the activity to any specific actor, referring only to 'malicious cyber actors'," even as reporting describes a campaign allegedly linked to Iranian hackers and records that, while federal agencies have declined to publicly attribute the attacks, multiple sources pointed the finger at Iran (The Record, 2026-08-07). For a European defender the practical effect is that no sanctions listing, no joint advisory naming a cluster, and no attributed threat profile will arrive to trigger internal escalation processes keyed on those things — the exposure-reduction work has to be justified on the mechanism alone.

The FBI stated that reported operational effects have included pressure loss and flooding, and identified Rockwell Automation MicroLogix 1100 and 1400 series PLCs as the targeted devices. The PSA does not attribute the activity to any specific actor, referring only to "malicious cyber actors."

activity caused a pressure drop at the Clayton County Water Authority, prompting a boil-water advisory for the utility's 300,000 customers in the Atlanta area. The authority restored service within hours.

Tenable Research Special Operations 2026-08-06

Defender actions

  • Inventory Rockwell Automation MicroLogix 1100 and 1400 controllers across water, wastewater and energy estates and establish, per unit, whether it is reachable from outside the operator's own network — including over a mobile-carrier link — and whether it still carries vendor-default access credentials.

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

T1133External Remote Services

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

T1133External Remote Services

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1078.001Valid Accounts: Default Accounts

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.