CyberSecurityNews

4,400+ Internet-Exposed Rockwell PLCs Expose Water Systems to Cyberattacks


A wave of cyberattacks against U.S. water and wastewater utilities has renewed alarm over how many industrial controllers remain directly reachable from the public internet.

New research from Forescout has identified 4,407 internet-facing Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) exposing port 44818, the EtherNet/IP engineering protocol, with 65% located in the United States, followed by Canada at 12% and Spain at 3%.

While this figure marks a 47% decline from a peak of 7,814 exposed devices in March 2020 to a low of 4,169 in June 2026, the sheer scale of exposure continues to leave critical infrastructure vulnerable to compromise.

On July 28, Minnesota IT Services (MNIT) reported a coordinated cyberattack against more than 30 water systems statewide. Although no city reported degraded water quality, Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational disruptions.

Braham said attackers used malware delivered through a wireless connection to shut down water plant controls, while Plymouth reported that its affected equipment, two water towers and 14 sewer lift stations, was connected via cellular routers.

Two days later, the FBI and EPA issued a joint advisory confirming similar incidents across at least 12 states since July 27, with Michigan, South Dakota, and Georgia among the states later named.

The advisory revealed that threat actors specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, in some cases modifying PLC logic or remotely changing IP addresses and passwords to lock out legitimate operators. Reported effects included pressure loss and flooding, raising concerns about untreated groundwater entering drinking water pipes.

MicroLogix 1400 accounts for roughly 50% of exposed devices, followed by CompactLogix 1769 at 22%, and MicroLogix 1100 and ControlLogix 5590 each at 8%. Notably, over 70% of U.S.-based controllers sit within large mobile carrier networks, connected through cellular routers, a setup that mirrors the access vector described in the FBI/EPA advisory.

Among 22 exposed hosts identified in cities targeted during the current campaign, 86% shared the same mobile carrier network. No specific CVE has been confirmed as the exploitation vector in this campaign, but 19 of those 22 hosts were susceptible to CVE-2017-16740, a Modbus TCP denial-of-service flaw, based on firmware analysis.

Forescout researchers also uncovered expired certificates, abandoned remote-access hostnames, and forgotten servers tied to municipal utilities, evidence of incomplete asset visibility that compounds the risk beyond PLCs alone.

Security experts urge utilities to disconnect PLCs from the public internet, disable unused services such as SNMP, and restrict Modbus TCP and port 44818 with strict allowlists.

Cellular gateways should be moved to private carrier APNs or protected VPNs with disabled public administration, and all remote access should require individual accounts with multi-factor authentication.

Organizations should also plan firmware upgrades for MicroLogix 1400 devices and prioritize replacement of the end-of-life MicroLogix 1100 line, since Rockwell discontinued it in April 2022.

Secure remote access (SRA) gateways, which isolate user sessions from direct protocol access, offer a practical layer of protection while enabling necessary remote operations.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link