ics-ottrade-pressNewsThe Broadside3 min read

4,000 Rockwell Controllers Remain Internet-Facing After Water Attacks

Three joint federal advisories in 90 days and manufacturer warnings dating to 2018 haven't closed the water sector's ICS exposure, because no regulation requires utilities to remove controllers from the public internet.


TL;DR

Forescout's scan found 4,000-plus Rockwell Automation controllers exposed on the public internet in the U.S., including 22 in cities recently hit by water-system cyberattacks. Nineteen of those 22 ran firmware vulnerable to a 2017 RCE flaw. The findings land amid an FBI/EPA investigation into attacks across 12-plus states that caused pressure loss, flooding, and operator lockouts. This is the third major exposure event in 90 days: Censys flagged 3,900 exposed Rockwell PLCs in April, then the attacks arrived, and now Forescout shows the surface hasn't shrunk. Manufacturers have warned since 2018. CISA's mitigations fact sheet says to remove OT from the public internet. No federal regulation requires it, so the controllers stay reachable.

Forescout's Vedere Labs published a scan Wednesday that found 4,000-plus Rockwell Automation and Allen-Bradley controllers sitting on the public internet in the U.S., including 22 devices in cities that were hit by cyberattacks on water and wastewater systems over the past month. The finding is the third time in roughly 90 days that researchers have mapped a sprawling exposure surface in the water sector's operational technology. The number hasn't budged.

The scan, run Monday through Shodan, identified controllers communicating over EtherNet/IP, the industrial protocol Rockwell uses for engineering workstations and control equipment. When that port faces the public internet, outside actors can fingerprint devices and, depending on configuration, write new settings or project files. The most common exposed model was the MicroLogix 1400, accounting for roughly half the devices. CompactLogix 1769 controllers made up 22%, with MicroLogix 1100 and ControlLogix 5590 devices each at about 8%.

Of the 22 exposed controllers in the recently attacked cities, 19 appeared to run firmware versions vulnerable to CVE-2017-16740, a 2017 remote code execution flaw in MicroLogix 1400 devices that Rockwell disclosed eight years ago. Exploitation requires Modbus TCP to be enabled on the target, and Forescout couldn't confirm that it was. But the condition necessary for the attack (an internet-facing industrial controller with known-vulnerable firmware) is present, and that alone is the story.

The 90-day arc

In April, after the FBI, NSA, CISA, EPA, and DOE issued a joint advisory warning that Iranian-affiliated actors were actively exploiting internet-connected PLCs across U.S. critical infrastructure, Censys ran its own scan. It found nearly 3,900 exposed Rockwell Automation/Allen-Bradley devices in the U.S. alone, most connected via cellular modems in field-deployed infrastructure like pump stations and substations, according to research published at the time (CyberScoop, April 2026). The agencies' advisory, updated in July, expanded the scope to Schneider Electric and Siemens PLCs and reiterated the core instruction: remove OT devices from direct internet exposure (CISA AA26-097A).

Then the attacks came. The FBI and EPA confirmed last week that water and wastewater utilities in at least 12 states had been hit since July 27. Attackers reached Rockwell MicroLogix 1100 and 1400 controllers remotely and changed IP addresses and passwords, cutting operators off from their own equipment. Pressure loss and flooding followed. Michigan alone had nine systems hit.

Now Forescout's scan shows the exposure surface is effectively unchanged. That's the asymmetry: two joint federal advisories, an active attack campaign with physical consequences, and the same 4,000 controllers still reachable from anywhere with a browser.

The gap is enforcement, not awareness

Rockwell Automation has told customers not to put controllers on the public internet since at least 2018. CISA's primary mitigations fact sheet, co-signed by the FBI, EPA, and DOE, leads with "Remove OT connections to the public internet" as its first recommendation (CISA, May 2025). None of this is obscure. None of it requires advanced threat intelligence to act on.

What's missing is a federal requirement. The water and wastewater sector operates under a patchwork of state, local, and tribal authorities, as CISA's own incident response guide acknowledges (CISA, January 2024). Cybersecurity maturity across the sector is "disparate" and utilities face resource constraints. The EPA has authority to require cybersecurity measures through sanitary surveys but has encountered legal challenges when it tried to exercise that authority. No regulation currently compels a municipal water utility to take its internet-facing PLC offline, and the scan results reflect that regulatory vacuum with precision.

For the engineers and municipal IT staff at the affected utilities, Monday looks the same as last Monday. They can disconnect the controllers, segment the network, put a secure gateway in front of the PLC, or do nothing. The federal government will advise, attribute, and investigate. It won't mandate. And 4,000 controllers will still answer a Shodan query.


Published ·Updated ·Deep Fathom