(TLP:CLEAR) Ongoing Threat Activity Targeting PLCs – Rockwell Automation Important Notice Update
Created: Thursday, August 6, 2026 - 8:29
Categories: Cybersecurity, OT-ICS Security, Security Preparedness
Summary: WaterISAC is aware that the current threat activity targeting PLC devices is still ongoing and expanding. Additionally, Rockwell Automation recently released an updated notice titled “IMPORTANT NOTICE: Restoring Access to MicroLogix 1400 and MicroLogix 1100 Controllers When the Password is Unknown, and Hardening Guidance.” The notice responds to threat actor activity targeting internet-exposed MicroLogix™ 1400 and MicroLogix 1100 programmable logic controllers (PLCs).
CISA’s recent July 30 alert, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” already directed owners, operators, and integrators to this Rockwell notice. However, since that alert published, Rockwell has revised the notice. Members who reviewed the earlier version are encouraged to review the new information.
What’s new in Rockwell’s updated notice:
- Recovery guidance now covers MicroLogix 1100. The original advisory notice addressed only the MicroLogix 1400. Rockwell has added a recovery procedure for the MicroLogix 1100, which uses a different method (including placing the controller in Program mode among others).
- Expanding hardening guidance. Rockwell has added further steps to strengthen OT security posture and reduce the likelihood of a future unauthorized lockout.
For Situational Awareness: On July 31, it was reported that the CyberAv3ngers Telegram channel claimed responsibility for “attacks on U.S. infrastructure” and warned that the group had only revealed “a small fraction” of its capabilities. The post also suggested that future operations could target mobile phone service, water, and electricity in the United States, saying, “How bad would it be if mobile phone signals in America were disrupted or cut off, or if water and electricity supplies were interrupted.” Please note: The Telegram post should be read as a public claim by a threat group, not as an attribution statement. In the current geopolitical climate, it is common for threat actors to publicly claim responsibility – whether or not the claim is accurate – as a way to amplify fear, shape perceptions, or project capability (perceived or real).
As a reminder, the underlying activity involves threat actors remotely changing PLC IP addresses and enabling passwords on devices where none had been configured, locking out operators and forcing a loss of operator view.WaterISAC strongly encourages members follow CISA’s mitigation recommendations in its alert, including removing PLC devices from the public internet.
If your utility notices activity related to this information, please report to WaterISAC or CISA.
Additional Reading:
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
- Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions
Related WaterISAC PIRs: 6-12
