The lockout came from inside the equipment
On the nights of 26 and 27 July an operator in Minnesota went to change a setting on a water plant controller and found the password was no longer theirs. Across the state more than 30 municipal water and wastewater systems were hit in the same window. Minnesota was simply the first to say so publicly. By the end of the week the FBI had reports from utilities in at least seven states, and in its 30 July public service announcement with the Environmental Protection Agency it recorded that some of that activity degraded water operations.
What the actors did is worth stating precisely, because it is not what most people picture when they hear the word breach. Having reached internet-facing controllers, they changed the devices' IP addresses and then turned on and set passwords. The FBI describes the result as a loss of view, and in some cases a loss of function, of connected equipment. Nothing was encrypted and no ransom was demanded. The utilities kept every file they had. What they lost was the ability to talk to their own machines. Operational effects reported to the FBI included loss of pressure and flooding, and operators fell back to running plants by hand.
Read the second instruction, not the first
The first instruction in both agencies' guidance is the obvious one: take the controllers off the public internet, immediately. CISA, which issued its own alert to the water and wastewater sector on 30 July and said it was seeing a significant escalation in activity aimed at programmable logic controllers, adds air-gapping and the removal of any publicly exposed device. That advice is correct and almost nobody will argue with it.
The second instruction is the one that decides how long a plant is down. The FBI tells operators to make sure they hold a known clean backup of the controller image, in case they are locked out by a modified password. CISA's route to the same place is to power cycle the device in a way that clears its addressing and its program. Both are restores, not patches. The recommended fix removes the attacker by removing everything, and the plant comes back only when somebody puts the program back.
Recovery is a file, and you may not be holding it
This is where a water plant differs from an office network, and where the guidance quietly assumes something most operators have never checked. Restoring a controller does not mean reinstalling software from a vendor. It means loading the specific program written for that specific plant: the ladder logic that knows this site has two wells and one lift station, that this pump must not run below that pressure, that this valve interlocks with that alarm. That program exists as a project file, and it is unique to the site.
In most European water plants the current version of that file does not sit with the utility. It sits with the systems integrator that commissioned the line, sometimes years ago, occasionally with an engineer who has since left. The utility owns the hardware, pays for the maintenance and carries the regulatory duty, while the artefact that makes the hardware work is held by a contractor under no explicit obligation to keep it current or to hand it over on demand. That arrangement is invisible for as long as nothing needs restoring. The whole of the FBI's second instruction depends on it.
So the honest version of the question is not whether you are patched. It is this: if a controller were cleared to factory state this afternoon, who would send you the file, how long would that take, and has anyone ever confirmed the file they hold actually loads onto the hardware you are running now? A project file that has drifted out of step with three years of undocumented site changes is not a backup. It is an archive.
A backup with a date on it is not the same as a clean one
There is one detail in the FBI notice that changes how you should treat the copies you do hold. At least one organisation reported modified PLC project files, having noticed ladder logic discrepancies across several of its sites. Someone compared what was running against what should have been running, at more than one site, and found a difference. That is not a lockout. That is an edit.
Once program files are in scope, having a backup stops being sufficient, because a copy taken after the intrusion restores the attacker's version faithfully. The controlling question becomes the date. You need a copy you can date to before the earliest plausible access, and a way to compare it against what is on the device today. For utilities running the Allen-Bradley MicroLogix 1100 and 1400 families the FBI names, or the Siemens and Schneider Electric equipment CISA also flags, that comparison is a routine engineering task. It is only difficult because almost nobody has a reference copy to compare against.
NIS2 already asks you this, in a clause nobody reads
Drinking water and waste water are Annex I essential sectors under NIS2, so European operators are inside the strictest tier of the regime. The clause that bites here is not the reporting clock. It is Article 21(2)(d), which requires supply chain security including the security-related aspects of the relationship between an entity and its direct suppliers and service providers. An integrator holding the only working copy of the program that runs a drinking water plant is precisely that relationship, and the fact that it is a filing arrangement rather than a network connection does not put it outside the article.
Three things are worth doing this week, and none of them require knowing who was behind this. Write down, per controller, who holds the current project file and under what contract term. Take your own copy, store it offline, and record the date you took it. Then test that one copy loads onto one controller during a planned outage, because an untested restore is a belief rather than a capability. Braham, a Minnesota town of about 1,700 people, was back inside two hours because its crews could run the plant by hand. Manual operation buys you hours. Getting the plant back on its controls is what the file buys you, and only if it exists.
Read next: Patching SharePoint No Longer Closes the Door | CISA's First AI Agent Platform Is Now a Must-Patch



