Federal alert highlights PLC and HMI exposure risks first seen in July Minnesota breach
August 10, 2026 – Bolivia, NC
By Coastal Carolina News Staff Writer
Federal cybersecurity officials are warning that a coordinated wave of intrusions targeting water‑system controls has affected at least 12 states, with only five states publicly identified – Minnesota, Michigan, Georgia, New Jersey, and South Dakota. While federal investigators say similar activity has been detected in additional, undisclosed locations.
The latest advisory builds on an incident previously reported in July by Coastal Carolina News, when more than 30 water systems experienced unauthorized access to programmable logic controllers. That earlier coverage, available to read here, outlined how operators in Minnesota were locked out of remote‑access screens and forced into manual operation to maintain pressure and flow.
No water‑quality impacts were reported, but the incident highlighted vulnerabilities in small and mid‑sized systems nationwide, including those in southeastern North Carolina.
Local systems rely on the same categories of equipment referenced in both the July advisory and the latest federal update. Brunswick County Public Utilities in Bolivia oversees countywide treatment operations and remote‑access controls, including facilities along the Southport Supply Road corridor that support distribution for the southern end of the county. Smaller municipal systems serving Boiling Spring Lakes, Northwest, and Navassa use compact control panels and remote‑monitoring tools similar to those targeted in other states
In Columbus County, the public utilities office in Whiteville manages treatment and distribution infrastructure that includes remotely controlled pump stations and tower systems. Rural water systems serving communities outside Chadbourn, Tabor City, and Hallsboro often operate with limited on‑site staffing, making remote access essential for daily monitoring. Federal officials note that these types of configurations are common nationwide and represent the same operational‑technology profile seen in the multi‑state intrusion pattern.
The federal alert recommends removing PLCs and human‑machine interfaces from public internet exposure, changing default passwords, reviewing remote‑access settings, and backing up operational‑technology configurations.
Local utilities are expected to follow these directives as part of routine compliance, though no incidents have been reported in Brunswick or Columbus counties.
CISA and the EPA say the investigation remains active, and additional states may be identified as forensic reviews continue. The agencies emphasize that the advisory applies broadly to water systems of all sizes, including those serving rural and coastal communities across southeastern North Carolina.
© 2026 CoastalCarolinaNews.com. All rights reserved.


Be the first to comment