Over 4,400 Rockwell PLCs Exposed Online, Threatening Water Systems

Recent cyberattacks targeting U.S. water and wastewater utilities have highlighted the persistent vulnerability of industrial control systems directly accessible from the internet. Research from Forescout has identified 4,407 internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) exposing port 44818, the EtherNet/IP engineering protocol. Of these, 65% are located in the United States, followed by Canada at 12% and Spain at 3%.

Although this figure represents a 47% decline from a peak of 7,814 exposed devices in March 2020 to a low of 4,169 in June 2026, the substantial number of exposed PLCs continues to pose significant risks to critical infrastructure.

Recent Cyberattacks on Water Systems

On July 28, Minnesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems statewide. While no city reported degraded water quality, operational disruptions were confirmed in Plymouth, South St. Paul, Maple Plain, and Braham. In Braham, attackers used malware delivered through a wireless connection to shut down water plant controls. Plymouth reported that its affected equipment, including two water towers and 14 sewer lift stations, was connected via cellular routers.

Two days later, the FBI and EPA issued a joint advisory confirming similar incidents across at least 12 states since July 27, with Michigan, South Dakota, and Georgia among the affected states. The advisory revealed that threat actors specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, in some cases modifying PLC logic or remotely changing IP addresses and passwords to lock out legitimate operators. Reported effects included pressure loss and flooding, raising concerns about untreated groundwater entering drinking water pipes.

Vulnerable Devices and Network Configurations

Among the exposed devices, the MicroLogix 1400 accounts for roughly 50%, followed by CompactLogix 1769 at 22%, and MicroLogix 1100 and ControlLogix 5590 each at 8%. Notably, over 70% of U.S.-based controllers are within large mobile carrier networks, connected through cellular routers—a setup that mirrors the access vector described in the FBI/EPA advisory. Among 22 exposed hosts identified in cities targeted during the current campaign, 86% shared the same mobile carrier network. While no specific CVE has been confirmed as the exploitation vector in this campaign, 19 of those 22 hosts were susceptible to CVE-2017-16740, a Modbus TCP denial-of-service flaw, based on firmware analysis.

Forescout researchers also uncovered expired certificates, abandoned remote-access hostnames, and forgotten servers tied to municipal utilities, indicating incomplete asset visibility that compounds the risk beyond PLCs alone.

Recommended Mitigation Measures

Security experts urge utilities to disconnect PLCs from the public internet, disable unused services such as SNMP, and restrict Modbus TCP and port 44818 with strict allowlists. Cellular gateways should be moved to private carrier APNs or protected VPNs with disabled public administration, and all remote access should require individual accounts with multi-factor authentication. Organizations should also plan firmware upgrades for MicroLogix 1400 devices and prioritize replacement of the end-of-life MicroLogix 1100 line, as Rockwell discontinued it in April 2022. Secure remote access (SRA) gateways, which isolate user sessions from direct protocol access, offer a practical layer of protection while enabling necessary remote operations.

The exposure of over 4,400 Rockwell PLCs underscores the critical need for robust cybersecurity measures in industrial control systems. As cyber threats targeting critical infrastructure become more sophisticated, organizations must proactively secure their systems by implementing comprehensive asset management, regular vulnerability assessments, and stringent access controls. The recent attacks serve as a stark reminder of the potential consequences of inadequate security practices in essential services.