Thousands of Rockwell Industrial Controllers Found Exposed Online, Including Near Water Utility Attacks
Cybersecurity firm Forescout has identified 4,407 Rockwell Automation programmable logic controllers (PLCs) exposed directly to the internet as of an August 3 scan, with 2,844 of these located in the United States. PLCs are specialised devices used to control machinery and processes in factories, water treatment plants, and other critical infrastructure.
Of particular concern, 22 of these exposed devices were found in cities that recently experienced cyberattacks targeting US water utilities. Notably, 19 of these controllers were connected through the same mobile carrier network, suggesting a possible common point of vulnerability or shared infrastructure provider. However, Forescout has not confirmed that any of these specific devices were actually compromised in the attacks.
While this research focuses on Rockwell Automation equipment and US infrastructure, it highlights a broader issue relevant to any business using internet-connected industrial or operational technology: devices left exposed online without proper safeguards can become entry points for attackers, even if no breach has yet been confirmed. Businesses relying on connected control systems, whether for manufacturing, utilities, or other operations, should treat this as a reminder to review their exposure.