4,400 Rockwell PLCs Exposed Online as Water Utility Cyberattacks Surge

4,400 Rockwell PLCs Exposed Online as Water Utility Cyberattacks Surge

Why It Matters Now

The industrial automation sector is confronting a cyber-physical security crisis of unprecedented scale. Forescout Research – Vedere Labs has identified more than 4,400 Rockwell Automation programmable logic controllers (PLCs) sitting unprotected on the public internet, exposing critical water infrastructure to remote manipulation. The discovery comes as the FBI and EPA confirm that malicious actors have already breached water and wastewater utilities across at least seven U.S. states, triggering pressure loss, flooding, and complete loss of operational visibility.

For asset owners and systems integrators across the global industrial automation market, this is no longer a theoretical risk. The exposed devices—primarily communicating over EtherNet/IP on port 44818—represent a direct gateway for nation-state-affiliated threat groups to compromise physical processes. With Rockwell controllers forming the operational backbone of thousands of water treatment plants, manufacturing facilities, and energy installations, the findings demand immediate architectural remediation.

Analyst Insight: The persistent exposure of industrial controllers online reflects a structural failure in OT network segmentation—not a lack of available tools. Despite Rockwell Automation publishing internet-disconnection advisories as early as September 2018, and again in May 2024 and March 2026, thousands of devices remain directly reachable. The gap between vendor guidance and field implementation remains dangerously wide.

The Numbers: A Persistent Exposure Crisis

Forescout's latest analysis, leveraging Shodan telemetry, reveals that 4,407 internet-facing controllers currently expose EtherNet/IP port 44818 globally. Critically, 65% of these devices are located in the United States, followed by Canada at 12% and Spain at 3%. The research further identified that 22 of these exposed PLCs were situated in cities specifically targeted during the recent wave of water utility intrusions—underscoring the direct link between internet visibility and operational compromise.

Click to Expand: Historical Exposure Trends (2020–2026)
Date Exposed Controllers (Port 44818) Change
March 2020 7,814 Peak
June 2026 4,169 -47% from peak
August 2026 4,407 +5.7% from June low

Source: Forescout Research – Vedere Labs, Shodan telemetry. While the overall trend shows a 47% reduction since 2020, the recent uptick from the June 2026 low of 4,169 to 4,407 suggests progress has stalled and may be reversing.

Market Trend: The industrial cybersecurity market was valued at $26.70 billion in 2025 and is projected to reach $61.18 billion by 2035, growing at a CAGR of 8.65% (Precedence Research). This growth is driven precisely by the kind of OT exposure incidents documented here—yet spending continues to lag behind the expansion of vulnerable attack surfaces.

How the Attacks Unfold: Anatomy of a PLC Breach

The attack chain targeting water utilities follows a disturbingly simple pattern. Malicious actors—which CISA and the FBI have linked to Iranian-affiliated advanced persistent threat (APT) groups—scan the internet for Rockwell MicroLogix 1100 and 1400 series controllers with exposed web and Telnet configuration interfaces. Leveraging default administrative credentials or the known authentication bypass vulnerability CVE-2021-22681, attackers gain full configuration access within minutes.

Step-by-Step Attack Sequence

Once connected, the adversary executes a three-phase disruption: First, they change the PLC's IP address, severing communication with operator HMIs and SCADA systems. Second, they enable or reset the device password, locking legitimate operators out entirely. Third—and most dangerously—in at least one confirmed case, attackers modified the PLC project files themselves, altering ladder logic across multiple sites. The operational consequences reported to the FBI include loss of water pressure, uncontrolled flooding, and an extended Loss of View condition that forced facilities into manual operation.

Click to Expand: Vulnerability Details – CVE-2021-22681

CVE Identifier: CVE-2021-22681

CVSS Score: 10.0 (Critical)

Affected Products: Rockwell Automation/Allen-Bradley MicroLogix 1100, MicroLogix 1400, and potentially other Logix-series controllers with exposed EtherNet/IP interfaces.

Exploit Mechanism: Authentication bypass via EtherNet/IP port 44818, allowing unauthenticated remote attackers to read and modify controller configuration, including ladder logic, IP settings, and password parameters.

CISA KEV Addition: March 5, 2026 — added to CISA's Known Exploited Vulnerabilities catalog.

Patch Status: Rockwell has issued firmware updates and mitigation guidance. However, the primary defense remains removing devices from direct internet exposure entirely.

Regulatory Response: FBI and EPA Joint Advisory

The FBI and Environmental Protection Agency (EPA) issued a joint Public Service Announcement (PSA) warning critical infrastructure operators that malicious cyber actors are systematically targeting internet-exposed Rockwell PLCs. The advisory explicitly names the MicroLogix 1100 and 1400 series and extends caution to other branded controllers including Schneider Electric and Siemens devices.

Simultaneously, CISA released advisory AA26-097A, co-authored with the FBI, NSA, EPA, DOE, CNMF, and Treasury, confirming Iranian IRGC-affiliated actors are exploiting CVE-2021-22681 at scale. The multi-agency response signals that the threat has crossed the threshold from isolated incident to national security concern.

Analyst Insight: The FBI-EPA joint advisory represents a rare intersection of law enforcement and environmental regulatory authority. For the first time, water utility operators face not only cybersecurity risk but also potential EPA enforcement consequences if due diligence—specifically disconnecting PLCs from the internet—is demonstrably absent. This dual-pressure framework is likely to accelerate compliance across the sector.

Global PLC Exposure and Industrial Automation Risk Landscape

Beyond Rockwell, the broader picture of industrial controller exposure remains alarming. Forescout's longitudinal research shows that nearly half of all reported vulnerable PLCs retained the same open ports one year after initial CISA notification—without any protective measures implemented. Only 30% were fully removed from internet exposure, while 20% remained exposed but had closed the specific OT port under scrutiny. This demonstrates that awareness alone does not drive remediation; enforceable standards and active monitoring are essential.

Why Legacy PLCs Remain Internet-Facing

The persistence of internet-exposed PLCs is not solely a technical problem—it is an organizational and procurement failure. Many water utilities and municipal facilities operate on constrained budgets with minimal cybersecurity staffing. Remote access was historically configured for vendor maintenance convenience, often without VPN gateways, and subsequently forgotten. Compounding this, legacy controllers like the MicroLogix 1100—first introduced over two decades ago—lack modern authentication mechanisms and encryption capabilities, making them fundamentally indefensible when placed on a public network.

Click to Expand: Recommended Mitigations – CISA & FBI Guidance
  • Immediate Disconnection: Remove all PLCs and OT devices from direct public internet access. This is the single highest-impact action an asset owner can take.
  • VPN-Only Remote Access: Route all vendor and operator remote access through properly configured VPN gateways with multi-factor authentication (MFA).
  • Password Enforcement: Change all default credentials immediately and implement strong, unique passwords for every device.
  • Network Segmentation: Isolate OT/ICS networks from IT and internet-facing networks using firewalls, DMZs, and unidirectional gateways where appropriate.
  • Project File Integrity Checks: Use vendor-provided integrity verification tools to compare running controller logic against known-good baseline configurations. Manually inspect Add-On Instructions (AOIs) for anomalous modifications.
  • Continuous Monitoring: Deploy passive OT-aware network monitoring to detect unauthorized configuration changes, abnormal protocol traffic, and new device connections in real time.
  • Incident Reporting: Report suspicious activity to the FBI's Internet Crime Complaint Center (IC3), local FBI field offices, or CISA's 24/7 Operations Center.

Water Utility Cyberattacks: A Recurring National Emergency

The current campaign against Rockwell PLCs did not emerge in isolation. U.S. utilities experienced 1,162 cyberattacks in 2024—a nearly 70% year-over-year increase from 689 attacks in 2023. By Q3 2024, weekly incidents averaged 1,339, representing a staggering 234% annual surge according to Check Point Research. Earlier intrusions targeting Unitronics PLCs at water facilities demonstrated the same core vulnerability: internet-exposed controllers with default credentials, exploited by hacktivist groups claiming geopolitical motivations.

The geographic spread now encompasses at least seven states, with Minnesota emerging as a focal point where over 30 systems were targeted simultaneously—suggesting either a shared technology dependency, a common service provider, or a coordinated state-level IT backbone that attackers exploited at scale.

Global Perspective: This is not a U.S.-only phenomenon. Britain's Drinking Water Inspectorate received 15 cyberattack reports from water suppliers between January 2024 and October 2025. The Canadian Centre for Cyber Security has issued parallel alerts on internet-accessible ICS abuse by hacktivists. Utilities worldwide sit at the intersection of aging infrastructure and escalating cyber conflict between established and emerging powers.

The Economics of PLC Exposure: Industrial Cybersecurity Market Dynamics

The industrial automation market faces a stark economic reality: the cost of securing legacy PLC infrastructure is dwarfed by the potential financial and public health consequences of a successful attack. Water system disruptions can contaminate drinking supplies, cause property damage through flooding, and erode public trust—each carrying seven-figure remediation costs. Yet many municipal operators continue to rely on flat network architectures designed before cybersecurity entered the operational lexicon.

The industrial cybersecurity market's projected growth to $61.18 billion by 2035 reflects a belated but accelerating recognition that OT environments require purpose-built defenses. Traditional IT security tools cannot inspect EtherNet/IP, Modbus, or DNP3 traffic with sufficient granularity to detect the subtle configuration changes characteristic of PLC-targeted intrusions. This capability gap is driving investment in OT-aware monitoring platforms from vendors including Dragos, Claroty, Nozomi Networks, and Forescout itself.

Click to Expand: Frequently Asked Questions

Q: Are all Rockwell PLCs vulnerable to these attacks?
Only internet-exposed controllers are directly at risk. The attacks specifically target MicroLogix 1100 and 1400 series devices with exposed EtherNet/IP (port 44818) or web interfaces. Controllers isolated behind properly configured firewalls with no direct internet access are not reachable through this attack vector. However, CISA notes that similar considerations apply to Schneider Electric, Siemens, and other branded PLCs.

Q: What is the most important immediate action for PLC asset owners?
Disconnect any PLC directly accessible from the public internet. This single step eliminates the attack surface these threat actors are actively exploiting. If remote access is operationally required, route it exclusively through a VPN gateway with multi-factor authentication.

Q: How can I check if my Rockwell PLCs are exposed online?
Conduct an external network scan of your public IP ranges for open port 44818 (EtherNet/IP). Complement this with a Shodan search for your organization's IP space. Forescout and other OT security vendors also offer exposure assessment services.

Q: Has Rockwell Automation issued patches for CVE-2021-22681?
Yes, Rockwell has published firmware updates and detailed mitigation guidance. However, patching alone is insufficient if devices remain internet-accessible. Rockwell's March 2026 advisory reiterates that controllers should never be connected directly to the internet.

Looking Ahead: From Awareness to Enforcement

The Forescout findings represent a watershed moment for industrial automation security. With over 4,400 Rockwell PLCs still exposed and threat actors actively exploiting this vulnerability at scale, the era of voluntary compliance is giving way to regulatory enforcement. The EPA's involvement signals that water quality and public health regulators now view cybersecurity as integral to operational integrity—not a separate IT function.

For the global industrial automation community—systems integrators, OEMs, and end-users alike—the path forward requires fundamental architectural change: zero-trust network segmentation, continuous OT-aware monitoring, and procurement policies that mandate secure-by-design controller configurations. The exposed devices documented by Forescout are not anomalies; they are the visible edge of a systemic vulnerability that extends across every sector of critical infrastructure.

Related Articles

Regresar al blog