U.S. Water Utility Attacks Expose 4,407 Internet-Facing PLCs Nationwide

U.S. Water Utility Attacks Expose 4,407 Internet-Facing PLCs Nationwide

Why This Matters Now

In late July 2026, a coordinated cyber campaign struck more than 30 community water systems across Minnesota in a single weekend. Within days, the FBI confirmed incidents in at least seven states—and subsequent reporting has pushed that number to 12. The attack vector was not a sophisticated zero-day exploit. It was something far more fundamental: thousands of programmable logic controllers (PLCs) sitting on the public internet, accepting unauthenticated commands on a well-known industrial protocol port.

The message from federal agencies has been unambiguous. "Disconnect the PLC from the internet," CISA urged in its July 30 alert. "Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC." For roughly 50,000 small water utilities across the United States—most without dedicated cybersecurity staff—that guidance is easier issued than executed.

Analyst Insight: The core vulnerability is architectural, not technical. Port 44818—the EtherNet/IP protocol used by Rockwell Automation Allen-Bradley controllers—accepts CIP connections without authentication in standard operating mode. This means any actor who can reach the port can enumerate device identity, read tag values, monitor I/O status, and potentially modify the ladder logic governing pumps, valves, and pressure management. The attack surface is not theoretical; it is measured and catalogued.

The Scale of Exposure: 4,407 Controllers and Counting

Forescout Vedere Labs researchers queried the Shodan search engine for devices exposing port 44818 and identified 4,407 Allen-Bradley controllers accessible worldwide. Sixty-five percent—approximately 2,865 units—are located in the United States. These are not devices hidden behind layers of network segmentation; they are directly reachable from any internet connection.

Forescout Exposure Data at a Glance
  • Total internet-exposed Allen-Bradley controllers (global): 4,407
  • Percentage located in the United States: 65% (~2,865 units)
  • Peak historical exposure (March 2020): 7,814 devices
  • Decline from peak: 47%
  • Protocol/Port: EtherNet/IP on TCP Port 44818
  • Primary manufacturers affected: Rockwell Automation/Allen-Bradley (MicroLogix 1100, MicroLogix 1400, CompactLogix, ControlLogix families)

The 47% decline from the March 2020 peak signals progress, but in critical infrastructure terms, the remaining exposure remains catastrophic. As one Forescout researcher noted, utilities "cannot secure what they cannot see"—and asset discovery remains the single greatest blind spot for small and mid-sized operators.

Attack Mechanics: How the Intrusions Unfolded

The FBI and EPA joint Public Service Announcement, issued July 30, 2026, detailed the specific Tactics, Techniques, and Procedures (TTPs) observed across victim organizations. After gaining remote access to internet-facing PLCs, threat actors systematically:

  • Changed device IP addresses to disconnect controllers from supervisory systems
  • Set new passwords, locking out legitimate operators
  • Modified PLC project files, introducing ladder logic discrepancies across multiple sites
  • Caused physical consequences including pressure loss and flooding at affected facilities

Several utilities were forced to revert to manual operation—a fallback mode that is labor-intensive, imprecise, and unsustainable for extended periods. Boil water notices were issued in multiple jurisdictions.

Targeted PLC Models and Their Vulnerability Profile

The FBI specifically identified Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs as the primary targets. Both models share critical risk characteristics:

  • MicroLogix 1100: End-of-life hardware. No longer receives firmware updates or security patches from Rockwell Automation. CVE-2021-33012 documents a remote, unauthenticated denial-of-service vulnerability that can fault the controller when switched to RUN mode.
  • MicroLogix 1400: Still supported but shares the same EtherNet/IP architecture. In standard mode, port 44818 accepts CIP (Common Industrial Protocol) connections with zero authentication requirements.
  • Broader exposure: The FBI explicitly warned that "similar considerations should also be made with other branded PLCs," noting that CompactLogix, Micro850, and controllers from Schneider Electric and Siemens have been targeted in related campaigns documented in Joint Advisory AA26-097A.
Market Trend: The targeting of end-of-life hardware is an accelerating pattern across industrial control system attacks. Threat actors recognize that EOL devices carry known, unpatched vulnerabilities and are disproportionately deployed in budget-constrained environments—exactly the profile of small U.S. water utilities. Replacement cycles measured in decades collide with threat evolution measured in days.

The Attribution Puzzle

No formal attribution has been made for the July 2026 water utility attacks. However, the activity coincides with Joint Cybersecurity Advisory AA26-097A—issued April 7 and revised July 22 with the U.S. Treasury Department added as a co-author—which documented an Iranian-affiliated operational technology campaign targeting PLCs across government services, water systems, and energy infrastructure since at least March 2026.

LevelBlue's threat intelligence team noted that the MicroLogix 1100 and 1400 models represent a shift in targeted hardware from the CompactLogix and Micro850 families documented in the April advisory, suggesting either an expansion in targeting, a separate actor, or broader opportunistic scanning.

Federal Response and the Resource Gap

The joint FBI-EPA advisory outlined core mitigations: disconnect PLCs from the public internet, use complex unique passwords, implement IP allowlisting, and mediate all remote access through VPNs or secure gateways. CISA reinforced these measures with its own alert on the same day.

For large municipal systems with in-house OT security teams, these are achievable directives. For the roughly 50,000 small water utilities across the United States, the gap between prescription and execution is vast. Most operate with no cybersecurity personnel, aging hardware, and limited capital budgets.

DEF CON Franklin: The Volunteer Firewall—By the Numbers
  • Program name: DEF CON Franklin (named after Benjamin Franklin's volunteer fire department model, est. 1736)
  • Volunteers deployed: 27 cybersecurity professionals
  • Utilities served: 21 water systems across 7 states
  • Volunteer qualification threshold: Minimum 10 years of cybersecurity experience; many are former government workers with security clearances or Fortune 500 OT security team members
  • Services provided (free of charge): OT asset mapping, password protocol hardening, vulnerability assessments, incident response planning, best-practice guidance
  • Demand-supply gap: 21 utilities served out of approximately 50,000 small systems nationwide—coverage of 0.042%

The Franklin initiative represents one of the most creative responses to the critical infrastructure cybersecurity deficit, but the program's founder has been explicit: the U.S. government should eventually step in and fund sophisticated tools deployable at every water utility. Until then, the model remains a volunteer fire department confronting a five-alarm blaze.

Beyond Port 44818: The Broader OT Exposure Landscape

While the immediate crisis centers on EtherNet/IP and Rockwell controllers, the underlying problem is systemic. Forescout's 2026H1 Threat Review documented a 51% year-over-year increase in new vulnerabilities, surging ransomware activity, and continued targeting of specialized devices—PLCs, HMIs, automatic tank gauges, and cellular remote-access gateways that bridge IT and OT environments.

The July attacks also highlighted a recurring pattern: compromised cellular modems serving as the internet gateway to otherwise isolated control networks. In several cases, attackers did not breach a corporate firewall; they simply connected through an unsecured cellular modem with default credentials, gaining direct access to the PLC on the other side.

Mitigation Framework: CISA & FBI Recommendations
  1. Disconnect PLCs from the public-facing internet. If remote access is required, route it through a VPN or secure gateway—never directly to the controller.
  2. Change all default passwords. Implement complex, unique credentials on every OT device, and enforce multi-factor authentication for all remote administrative access.
  3. Implement IP allowlisting. Restrict access to known engineering workstations and authorized OT assets only.
  4. Secure cellular gateways. Use private APNs or encrypted VPNs; never expose a PLC directly through a cellular modem.
  5. Replace end-of-life hardware. MicroLogix 1100 and other EOL devices that no longer receive security patches must be prioritized for replacement.
  6. Segment IT from OT. Enforce zones and conduits to ensure a compromised business network cannot reach the process network.
  7. Block unnecessary ports. Restrict access to TCP/UDP ports 2222 and 44818 at the manufacturing zone boundary using firewalls or UTM appliances with CIP message filtering capability.
Analyst Insight: The decline from 7,814 exposed controllers in 2020 to 4,407 in 2026 represents a 47% improvement over six years—an average reduction of roughly 570 devices per year. At that pace, eliminating the remaining exposure would take nearly eight more years. With nation-state actors, criminal ransomware groups, and hacktivists all actively scanning for port 44818, the critical infrastructure sector does not have that kind of time. The convergence of EOL hardware, budget-constrained operators, and an expanding threat actor ecosystem makes water utilities the soft underbelly of U.S. critical infrastructure cybersecurity.

What Comes Next

The EPA has signaled that cybersecurity assessments may become part of sanitary survey inspections, and industry associations including the AWWA are accelerating guidance for small-system operators. But regulation moves slowly, and threat actors move fast. The immediate priority for any utility operator reading this is a single, no-cost action: verify whether your PLCs, HMIs, or SCADA servers respond on a public IP address. If they do, remove them. The next attack campaign is not a question of if—it is a question of when, and whether your devices are still visible when the scanning begins.

Related Articles

Kembali ke blog