TL;DR
Attackers are hijacking internet-exposed MicroLogix 1400 controllers at U.S. water utilities. They change device IP addresses and set unknown passwords, so operators lose their view of equipment. Rockwell Automation published recovery guidance, and the FBI confirms the MicroLogix 1400 attacks are active.
Why it matters
Water and wastewater plants rely on these controllers for daily operation. When a controller locks out its operator, monitoring and control can stop. Notably, attackers do not need a software exploit here. Instead, they simply reach a device that should never face the open internet. The FBI reports that utilities in at least seven states have already seen incidents. In some cases, the disruption degraded water operations, including loss of pressure and flooding.
How the attack works
The attackers first find MicroLogix 1400 units that sit directly on the internet. These controllers offer a web server and network features that ease remote management. However, that same exposure gives intruders an easy path in. Next, they connect to the device and change its configuration. Specifically, they alter the IP address and enable a password that the owner does not know. As a result, the operator loses view, and sometimes control, of connected equipment.
Rockwell describes the pattern plainly: threat actors are “changing IP addresses and turning on and setting passwords.” Furthermore, one utility found modified project files after spotting ladder logic differences across several sites.
Affected controllers
The activity targets the MicroLogix 1400 series A, B, and C. Rockwell lists catalog numbers such as 1766-L32AWA, 1766-L32BWA, and 1766-L32BXB. Additionally, the related MicroLogix 1100 line faces similar risk, according to federal alerts.
Recovery and mitigation
Rockwell’s notice is recovery guidance, not a vulnerability disclosure, so no CVE applies. To regain access, owners power off the unit and remove the 1747-BA battery to clear memory. After a fault appears, they reconnect the battery, reset the IP through the LCD panel, and redownload the project with RSLogix 500. A current offline .RSS backup is essential, because the reset erases the program. Therefore, keep that backup somewhere separate from the plant network.
Reduce the risk of repeat MicroLogix 1400 attacks
First, keep controllers off the public internet. Rockwell tells owners to “not connect the controller directly to the internet.” Next, place each device behind a firewall on an isolated OT network. Then set the controller to RUN mode using the LCD keypad. On Series B, apply firmware FRN 21.002 or later and enable Enhanced Password Security. For more detail, review Rockwell’s full advisory and the CISA’s public warning.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.