4,400+ Rockwell PLCs Exposed Online; 22 Found in US Water Attack Cities
A new Forescout analysis has identified 4,407 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide as of August 3, including 2,844 located in the United States. Of those, 22 controllers were found in cities where US water and wastewater utilities have reported cyberattacks since July 27. Notably, 19 of the 22 ran on the same mobile carrier network, and Forescout found that more than 70% of US-based exposed controllers rely on large cellular providers — Verizon Business, AT&T Mobility, and T-Mobile USA together accounted for roughly 59% of a separate 4,148-host Censys snapshot taken July 30. The figures cannot be directly compared due to different query methodologies, but both confirm a persistent exposure footprint well above 4,100 hosts. Defenders can verify their own network exposure with a quick port scanner focused on EtherNet/IP port 44818, the unauthenticated path Forescout says can allow attackers to identify a controller or write settings to it depending on device configuration.
Forescout's researchers stressed that the publicly reported water utility incidents may not require any exploit at all. Attackers appear to have changed IP addresses and set passwords on already-reachable controllers, severing operator visibility and, in some cases, control of connected equipment. Nineteen of the 22 devices in affected cities were running firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C with firmware 21.002 and earlier (CVSS 8.6, fixed in revision 21.003). Exploitation requires Modbus TCP to be enabled — a condition Forescout could not verify remotely. MicroLogix 1400 devices made up 50% of Forescout's results and MicroLogix 1100 devices 8%; Rockwell discontinued the MicroLogix 1100 on April 30, 2022, leaving affected operators with no vendor patch path. For environments where attackers may have already set passwords, advisory SD1790 walks operators through credential recovery, and admins can audit credential strength with a password checker.
The FBI and EPA issued a joint public service announcement on July 30 confirming incidents in at least seven states, though The Hacker News noted on August 6 that Forescout's write-up references at least 12. No agency has attributed the campaign. Recommendations from both agencies include strong authentication on cellular modems, current firmware, and logging — with any remote access isolated through a private APN, VPN, or comparable architecture. Forescout added that even patched firmware does not make direct public exposure of PLCs acceptable. Forescout's own historical series hit a June 2026 low of 4,169 exposed hosts — down 47% from 7,814 in March 2020 — before ticking back up to 4,407 in August, suggesting that awareness campaigns have measurably reduced but not eliminated the problem. Organizations looking to inventory their own attack surface and ISP attribution can use a WHOIS lookup to confirm whether controllers are resolving on cellular or enterprise ranges.
The core remediation remains straightforward: take the controllers off the public internet. Forescout warned that exposing EtherNet/IP on TCP/44818 creates an unauthenticated path that can be reached from anywhere on the internet — exactly the condition that allowed the recent water sector incidents to occur. Until cellular gateways, modems, and routers are placed behind private APNs or VPN tunnels, and until exposed firmware is updated or devices replaced, the attack surface for opportunistic intrusions into operational technology (OT) environments will remain wide open.