Executive Summary
In August 2026, Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) worldwide, with 2,844 located in the United States. Notably, 22 of these exposed PLCs were found in cities recently targeted by cyberattacks on U.S. water utilities, with 19 utilizing the same mobile carrier network. Attackers exploited these vulnerabilities by altering IP addresses and setting passwords on accessible controllers, leading to operators losing visibility and control over connected equipment. This incident underscores the critical need for securing industrial control systems against unauthorized internet exposure.
The prevalence of internet-exposed PLCs highlights a significant security gap in critical infrastructure, particularly within the water sector. The ease with which attackers can manipulate these systems without exploiting specific vulnerabilities emphasizes the urgency for organizations to implement robust network segmentation, remove unnecessary internet exposure, and enforce strong authentication measures to protect against potential disruptions and threats to public safety.
Why This Matters Now
The widespread exposure of critical industrial control systems to the internet presents an immediate and significant risk to essential services, including water utilities. Recent cyberattacks exploiting these vulnerabilities demonstrate the potential for operational disruptions and threats to public safety. It is imperative for organizations to promptly assess and secure their control systems to prevent further incidents.
Attack Path Analysis
Attackers exploited internet-exposed Rockwell PLCs lacking authentication to gain initial access. They escalated privileges by modifying PLC configurations and setting passwords, locking out operators. Lateral movement was achieved by leveraging interconnected systems to propagate the attack. Command and control were established through unauthorized remote access to the PLCs. Data exfiltration involved extracting sensitive operational data from the compromised systems. The impact included operational disruptions and loss of control over water treatment processes.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited internet-exposed Rockwell PLCs lacking authentication to gain initial access.
Related CVEs
CVE-2017-16740
CVSS 10A stack-based buffer overflow vulnerability in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier, may allow remote code execution.
Affected Products:
Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers – Series B and C Versions 21.002 and earlier
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Resource Hijacking
Network Denial of Service
Modify Control Logic
Denial of Control
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Access Enforcement
Control ID: AC-3
PCI DSS 4.0 – Limit Access to System Components and Cardholder Data
Control ID: 7.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Water utilities face direct exposure to Rockwell PLC attacks targeting industrial control systems, requiring immediate segmentation and vulnerability patching measures.
Industrial Automation
Widespread Rockwell PLC vulnerabilities create critical risks for industrial automation systems, demanding zero trust segmentation and encrypted traffic controls.
Government Administration
Municipal water system attacks demonstrate government infrastructure vulnerabilities to industrial control system breaches requiring enhanced monitoring and policy enforcement.
Telecommunications
Mobile carrier networks hosting majority of exposed PLCs create attack vectors requiring secure hybrid connectivity and egress security implementations.
Sources
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Citieshttps://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.htmlVerified
- MicroLogix 1400 Modbus TCP Buffer Overflow Denial of Servicehttps://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1010.htmlVerified
- CVE-2017-16740 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2017-16740Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit internet-exposed Rockwell PLCs, thereby reducing the blast radius and limiting lateral movement within the network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit internet-exposed PLCs would likely have been constrained, reducing the initial access points available.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by modifying PLC configurations would likely have been constrained, reducing unauthorized control over systems.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally through interconnected systems would likely have been constrained, reducing the spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control through unauthorized remote access would likely have been constrained, reducing external control over compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive operational data would likely have been constrained, reducing data loss.
The operational disruptions and loss of control over water treatment processes would likely have been constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Water Treatment Operations
- Distribution System Monitoring
- SCADA System Management
Estimated downtime: 3 days
Estimated loss: $50,000
Operational data related to water treatment processes and distribution systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to critical systems and enforce least privilege.
- • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns targeting PLCs.



