Validated Containment Architectures are here. →Explore

Executive Summary

In August 2026, Forescout identified 4,407 internet-exposed Rockwell Automation programmable logic controllers (PLCs) worldwide, with 2,844 located in the United States. Notably, 22 of these exposed PLCs were found in cities recently targeted by cyberattacks on U.S. water utilities, with 19 utilizing the same mobile carrier network. Attackers exploited these vulnerabilities by altering IP addresses and setting passwords on accessible controllers, leading to operators losing visibility and control over connected equipment. This incident underscores the critical need for securing industrial control systems against unauthorized internet exposure.

The prevalence of internet-exposed PLCs highlights a significant security gap in critical infrastructure, particularly within the water sector. The ease with which attackers can manipulate these systems without exploiting specific vulnerabilities emphasizes the urgency for organizations to implement robust network segmentation, remove unnecessary internet exposure, and enforce strong authentication measures to protect against potential disruptions and threats to public safety.

Why This Matters Now

The widespread exposure of critical industrial control systems to the internet presents an immediate and significant risk to essential services, including water utilities. Recent cyberattacks exploiting these vulnerabilities demonstrate the potential for operational disruptions and threats to public safety. It is imperative for organizations to promptly assess and secure their control systems to prevent further incidents.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The exposure resulted from inadequate network segmentation and security measures, allowing these industrial control systems to be accessible directly from the internet without proper authentication.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely have constrained the attacker's ability to exploit internet-exposed Rockwell PLCs, thereby reducing the blast radius and limiting lateral movement within the network.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit internet-exposed PLCs would likely have been constrained, reducing the initial access points available.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges by modifying PLC configurations would likely have been constrained, reducing unauthorized control over systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally through interconnected systems would likely have been constrained, reducing the spread of the attack.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control through unauthorized remote access would likely have been constrained, reducing external control over compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive operational data would likely have been constrained, reducing data loss.

Impact (Mitigations)

The operational disruptions and loss of control over water treatment processes would likely have been constrained, reducing the overall impact of the attack.

Impact at a Glance

Affected Business Functions

  • Water Treatment Operations
  • Distribution System Monitoring
  • SCADA System Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Operational data related to water treatment processes and distribution systems.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access to critical systems and enforce least privilege.
  • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
  • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Establish Multicloud Visibility & Control to detect and respond to anomalous activities across environments.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns targeting PLCs.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image