More Than 4,400 Rockwell PLCs Found Exposed Online Amid Water Sector Cyber Risks

More Than 4,400 Rockwell PLCs Found Exposed Online Amid Water Sector Cyber Risks

A global scan conducted by cybersecurity researchers has identified thousands of internet-facing Rockwell Automation programmable logic controllers (PLCs), revealing continued cybersecurity challenges for industrial control systems deployed across critical infrastructure environments.

According to cybersecurity firm Forescout, 4,407 exposed Rockwell controllers were discovered worldwide during an August 3, 2026 scan, including 2,844 devices located in the United States. Among those devices, 22 Rockwell PLCs were identified in cities affected by recent cyber incidents targeting U.S. water and wastewater utilities.

The findings do not confirm that exposed controllers were compromised. However, researchers warned that directly connecting industrial controllers to the public internet creates significant security risks, especially when remote access protections and network segmentation are insufficient.

Rockwell Automation PLC platforms are widely used across manufacturing, energy, water treatment, and infrastructure applications. These systems provide real-time control over industrial processes, making cybersecurity protection essential for maintaining operational reliability. Industrial automation components such as Rockwell Automation ControlLogix and CompactLogix systems are commonly deployed in production environments where secure network architecture is a critical requirement.

Security analysts noted that recent attacks against water utilities may not have required advanced software exploits. Instead, attackers could potentially gain access through exposed controllers, modify network settings, change passwords, or disrupt communication between operators and industrial equipment.

The main concern involves PLCs that are accessible through public networks without sufficient authentication barriers. Forescout highlighted that exposing EtherNet/IP services, particularly through commonly used communication ports such as TCP 44818, can provide attackers with opportunities to identify industrial devices or modify controller configurations depending on system settings.

The cybersecurity firm reported that more than 70% of exposed Rockwell controllers located in the United States were connected through large mobile carrier networks. Many industrial operators use cellular communication for remote monitoring and distributed infrastructure management, but these connections require additional security controls to prevent unauthorized access.

Federal agencies, including the FBI and Environmental Protection Agency (EPA), have recommended stronger cybersecurity practices for organizations operating internet-connected PLC systems. Recommended measures include implementing multi-factor authentication, updating firmware, maintaining detailed logging, and isolating remote connections through private APN networks, VPN solutions, or equivalent secure architectures.

A separate analysis from Censys identified more than 4,100 exposed Rockwell and Allen-Bradley EtherNet/IP hosts, with major telecommunications providers accounting for a significant portion of identified connections. While different scanning methods produced slightly different results, both studies indicate that thousands of industrial controllers remain visible from the public internet.

The most frequently identified devices included Rockwell MicroLogix 1400 controllers, which represented approximately half of Forescout’s findings, followed by MicroLogix 1100 controllers. These product families were also referenced in government cybersecurity guidance related to recent industrial security incidents.

Researchers identified that some MicroLogix 1400 devices located in affected cities were running firmware versions associated with CVE-2017-16740, a vulnerability involving Modbus TCP buffer overflow conditions. Rockwell Automation rated the vulnerability with a CVSS score of 8.6.

The vulnerability affects certain MicroLogix 1400 Series B and C controllers running firmware version 21.002 or earlier when Modbus TCP functionality is enabled. Rockwell released a firmware update addressing the issue, but cybersecurity experts emphasized that firmware updates alone cannot eliminate the risks created by direct internet exposure.

Industrial cybersecurity specialists continue to stress that PLC systems should not be placed directly on public networks. Even fully patched controllers can become targets if attackers discover exposed communication paths or weak remote access configurations.

Rockwell Automation has also provided recovery guidance for operators affected by unauthorized password changes on MicroLogix controllers. The recovery process requires access to verified offline backups of controller programs, allowing organizations to restore known-good configurations.

The importance of maintaining offline project backups has become increasingly clear as cyber incidents targeting operational technology environments continue to evolve. In industrial facilities, a compromised PLC can affect production visibility, equipment control, and overall process safety.

The recent findings demonstrate the growing importance of OT cybersecurity management, especially as manufacturers and infrastructure operators continue expanding remote monitoring, cloud connectivity, and digital transformation initiatives.

Modern industrial environments require a balance between connectivity and security. While network integration improves operational efficiency and enables advanced analytics, improperly protected access points can create vulnerabilities across entire production ecosystems.

Organizations operating Rockwell PLC systems and other industrial automation platforms are increasingly adopting cybersecurity frameworks based on network segmentation, zero-trust principles, secure remote access, and continuous monitoring.

As industrial automation becomes more connected, protecting PLCs, SCADA systems, and field-level devices will remain a fundamental requirement for reliable and secure operations.

Written by: Andrew Mitchell. Andrew is an industrial automation and cybersecurity analyst with more than 12 years of experience covering PLC systems, OT security, industrial networks, and critical infrastructure protection. His research focuses on the intersection of automation technology and cybersecurity resilience.

Комментировать

Your email address will not be published. Required fields are marked *

Обратите внимание, что комментарии проходят одобрение перед публикацией.