Following cyberattacks targeting more than 30 municipal water systems across Minnesota, the FBI and EPA have issued a warning to critical infrastructure asset owners and operators that malicious actors are targeting operational technology devices used in water and wastewater facilities.

Since July 27, water and wastewater companies in seven states have reported incidents to the FBI, some of them causing a degradation of service, the agencies said in a public service announcement.

Operational effects reported to the FBI have included loss of pressure and flooding, the announcement added. Pressure loss in water systems could potentially allow untreated groundwater to seep into pipes, it explained.

A primary target is Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), particularly the MicroLogix 1100 and 1400 series. When those PLCs are exposed to the internet, attackers can remotely tamper with the devices' configurations.

Once the attackers have access to a PLC, they can change its IP address and password, resulting in a loss of view and, in some cases, function of connected equipment in targeted facilities. The FBI also reported that one organization discovered modified PLC project files after identifying ladder logic discrepancies at multiple sites.