ICS/OT SECURITY

4,407 Rockwell PLCs Sit on the Public Internet, 22 in Cities Hit by Water Utility Attacks

Forescout's August 3 scan counted 4,407 internet-facing Rockwell controllers worldwide, 2,844 of them in the US, including 22 in cities where water utilities reported cyberattacks.

Matt Lucas  |  August 6, 2026  |  5 min
4,407
Exposed Rockwell PLCs (Aug 3 scan)
2,844
In the United States
22
In cities with reported water attacks
70%+
US devices on mobile carrier networks
TL;DR
  • What: Forescout's August 3 scan found 4,407 internet-facing Rockwell PLCs worldwide, including 22 in US cities where water utilities reported attacks since July 27.

Forescout scanned the internet on August 3 and counted 4,407 exposed Rockwell Automation programmable logic controllers. 2,844 of them are in the United States. Twenty-two sit in cities where water utilities have reported cyberattacks since July 27, and 19 of those 22 ride the same mobile carrier network. Forescout could not confirm that any of the 4,407 were compromised, and the number counts controllers, not utilities or victims.

The part that should change your Monday: the effects described publicly in those water incidents did not require a vulnerability exploit. Attackers changed IP addresses and set passwords on controllers that were already reachable from the internet. Operators lost visibility, and in some cases control, of connected equipment. No CVE, no memory corruption, no zero-day. Just a device answering unauthenticated requests on a routable address.

What the exposure actually looks like

The reachable surface is EtherNet/IP on TCP port 44818. Depending on device configuration, an unauthenticated connection to that port lets an attacker identify the controller (vendor, product code, firmware revision, sometimes the project name) or write settings to it. That identification step is what makes mass scanning viable: an attacker does not need to guess what they hit, the device tells them.

Two independent snapshots agree on the scale. A July 30 Censys pull found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts. Forescout's August 3 pull found 4,407. Different platforms, different queries, different days, so the figures are not directly comparable, but both clear 4,100. Forescout's historical series puts the June 2026 low at 4,169, down 47% from 7,814 in March 2020. Six years of ICS security advocacy cut the exposed population roughly in half and then flattened out.

Device breakdown from Forescout's results:

The cellular modem is the real attack surface

More than 70% of the US-based exposed controllers are on large mobile carrier networks. Censys attributed 59% of its 4,148 hosts to Verizon Business, AT&T Mobility, and T-Mobile USA. This is the classic small-utility remote-site pattern: a lift station or a well house with no fiber, a cellular router dropped in for SCADA polling and remote troubleshooting, and a public IP handed out by the carrier with nothing filtering inbound traffic.

Nineteen of the 22 controllers found in affected cities were on the same carrier network. That clustering matters more than the raw count. It suggests a shared integrator, a shared modem deployment template, or a shared APN configuration, and the FBI warned explicitly that similar third-party network setups may let attackers repeat a successful compromise across every customer sharing the vulnerable configuration. One integrator's default becomes a target list.

Federal guidance, in one line

The FBI and EPA recommend strong authentication, current firmware, and logging on cellular modems, with remote access isolated behind a private APN, a VPN, or an equivalent architecture. If your remote sites answer on a public carrier IP today, a private APN from the same carrier is usually a support ticket, not a capital project.

CVE-2017-16740 is a footnote, not the story

Forescout found that 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow rated 8.6 by Rockwell. It affects MicroLogix 1400 Series B and C on firmware revision 21.002 and earlier, and Rockwell fixed it in revision 21.003. That patch has been available since 2017.

Two caveats keep this from being the headline. Exploitation requires Modbus TCP to be enabled, which Forescout could not verify on those hosts. And nothing in the reported attacker behavior needed the flaw. Forescout's own framing is the right one: firmware updates fix specific bugs but do not make direct public exposure of a PLC acceptable. Patch to 21.003 because nine-year-old known-vulnerable firmware on a control device is indefensible, not because it closes this campaign.

Recovery if you are already locked out

Rockwell advisory SD1790 covers the specific scenario operators are hitting: an attacker set a password on the controller and the owner can no longer connect. The procedure resets a MicroLogix 1400 or 1100 to factory defaults, after which you redownload a known-good project file. SD1790 carries no CVE because it is recovery guidance, not a vulnerability disclosure.

The recovery path assumes a backup you may not have

Factory reset wipes the controller logic. SD1790 only works if you hold a current offline copy of the project file. The FBI reported that at least one victim discovered modified PLC project files after noticing ladder logic discrepancies across several sites, which means the on-device copy cannot be trusted as your restore source. Pull and hash offline copies of every controller program now, before you need them.

Open questions the advisories do not answer

Neither the government alerts nor Forescout's analysis explains how attackers found, selected, or initially accessed their targets. No agency has attributed the campaign. Even the scope is unsettled: the FBI and EPA July 30 public service announcement covers utilities in at least seven states, and as of August 6 the FBI page still says seven while Forescout's writeup describes the announcement as confirming at least 12. Treat the state count as unresolved, not as a bound on who is affected.

Do this week

The 4,407 number will move with the next scan. The underlying condition will not, until someone takes the controllers off the public internet.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us