Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales

    September 23, 2026

    UK to fight Russian disinformation and push new global AI standards, Burnham says

    September 23, 2026

    Data centres: Developers hope fibre optics will cut power use

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • UK to fight Russian disinformation and push new global AI standards, Burnham says
    • Data centres: Developers hope fibre optics will cut power use
    • ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
    • $161 Million in Decade-Old Bitcoin Has Moved in Just Two Weeks
    • Curiosity Blog, Sols 5010-5015: Checking out the Bands
    • Keeping billionaires and the taxman happy | The super-rich
    • Jamaica hails King’s decision to refer slavery reparations petition to privy council as ‘really big deal’ | Jamaica
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 06, 2026OT Security / Vulnerability

    Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.

    Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims.

    Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment.

    Neither the government alerts nor Forescout’s analysis explains how the attackers found, selected, or initially accessed their targets.

    Cybersecurity

    Water and wastewater utilities in at least seven states have reported incidents since July 27, the FBI and EPA said in a July 30 public service announcement. The Hacker News found on August 6 that Forescout’s post says the announcement confirmed at least 12 states, while the FBI page says seven. No agency has attributed the campaign.

    Whatever the final count, defenders can act now by taking the controllers off the public internet.

    Exposing EtherNet/IP on port 44818 creates an unauthenticated path that, depending on device configuration, lets an attacker identify a controller or write settings to it, Forescout said.

    Forescout found more than 70% of the US-based exposed controllers on large mobile carrier networks. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture.

    A July 30 Censys snapshot found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%. The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not directly comparable. Forescout’s historical series hit a June 2026 low of 4,169, down 47% from 7,814 in March 2020; its August 3 snapshot was 4,407.

    Cybersecurity

    MicroLogix 1400 devices made up 50% of Forescout’s results and MicroLogix 1100 devices 8%. The FBI and EPA named both families. Forescout said 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740 (Rockwell CVSS score: 8.6).

    The flaw is a Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier; Rockwell fixed it in revision 21.003. Exploitation requires Modbus TCP to be enabled, which Forescout could not verify on those hosts. Firmware updates address specific bugs but “do not make direct public exposure of PLCs acceptable,” the researchers wrote.

    Rockwell discontinued the MicroLogix 1100 on April 30, 2022. Advisory SD1790 tells operators locked out by an attacker-set password how to reset a MicroLogix 1400 or 1100 to factory defaults and redownload a known-good project file. The notice carries no CVE because it is recovery guidance, not a vulnerability disclosure.

    That recovery path requires a current offline copy of the controller logic. The FBI said at least one victim found modified PLC project files after spotting ladder logic discrepancies across several sites. It also warned that similar third-party network setups may let attackers repeat successful compromises across customers sharing vulnerable configurations.

    attack Cities exposed online PLCs Rockwell water
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales

    September 23, 2026

    UK to fight Russian disinformation and push new global AI standards, Burnham says

    September 23, 2026

    Data centres: Developers hope fibre optics will cut power use

    September 23, 2026

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales

    September 23, 2026

    UK to fight Russian disinformation and push new global AI standards, Burnham says

    September 23, 2026

    Data centres: Developers hope fibre optics will cut power use

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.