A new report from cybersecurity company Forescout has revealed that 4,407 internet-connected Rockwell Automation Programmable Logic Controllers (PLCs) are publicly accessible around the world. Out of these, 2,844 are located in the United States. Researchers also identified 22 exposed PLCs in cities that recently experienced cyberattacks targeting water and wastewater facilities. However, there is no evidence that these exposed devices have been compromised.

The investigation found that 19 of the 22 exposed PLCs were connected through the same mobile carrier network. According to Forescout, these controllers were directly reachable from the internet, making them easier targets for attackers if proper security measures were not in place. The report highlights that internet exposure alone creates unnecessary risk for critical infrastructure systems.
The findings come after a series of cyber incidents affected water and wastewater utilities across several U.S. states. Federal agencies reported that attackers targeted internet-facing Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 PLCs. In some cases, the attacks disrupted water operations by locking operators out of their own systems and forcing them to switch to manual control.

Researchers explained that the attackers did not need to exploit a software vulnerability to cause damage. Instead, they simply accessed PLCs that were already exposed online. Once connected, the attackers changed device IP addresses and configured passwords, causing operators to lose visibility and, in certain cases, control over connected equipment. This shows how dangerous direct internet exposure can be.
The report also notes that investigators still do not know how the attackers selected their targets or gained their initial access. While government agencies have confirmed multiple attacks against water utilities, no official attribution has been made for the campaign. Researchers believe understanding the attackers’ initial access methods remains an important part of the ongoing investigation.

Forescout observed that more than 70 percent of the exposed U.S. Rockwell PLCs were connected through major mobile carrier networks. Devices using cellular connections can be useful for remote operations, but they also require strong security controls. Without proper protection, these internet-connected systems may become entry points into operational technology environments.
To reduce the risk of future attacks, the FBI, EPA, and cybersecurity experts recommend removing PLCs from direct internet exposure whenever possible. They also advise using secure gateways, firewalls, VPNs, strong authentication, unique passwords, access control lists, and continuous logging to protect industrial control systems from unauthorized access.

Although thousands of exposed Rockwell PLCs were discovered, researchers stressed that exposure does not mean the devices have been hacked. The report serves as a warning that critical infrastructure operators should identify publicly accessible systems and secure them before attackers take advantage of them. Strengthening operational technology security remains essential to protecting water utilities and other critical services from future cyber threats.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news