A string of cyberattacks against water and wastewater utilities across the United States has put fresh attention on a persistent problem in the sector: industrial controllers that remain directly reachable from the public internet.
New research from Forescout has identified 4,407 internet-facing Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs) exposing port 44818, the EtherNet/IP protocol used for engineering access. Roughly 65% of these devices sit in the United States, with Canada and Spain accounting for another 15% combined. While that total marks a meaningful drop from a peak of 7,814 exposed devices back in March 2020, the researchers argue the remaining exposure is still large enough to leave critical infrastructure at real risk.
A Coordinated Campaign Against Water Systems
The exposure numbers took on new urgency after Minnesota IT Services reported a coordinated cyberattack on more than 30 water systems statewide on July 28. Although officials said no city reported degraded water quality, several municipalities including Plymouth, South St. Paul, Maple Plain, and Braham confirmed operational disruptions. Braham said attackers used malware delivered over a wireless connection to shut down water plant controls, while Plymouth reported that the affected equipment — two water towers and 14 sewer lift stations — was reachable through cellular routers.
Two days later, the FBI and Environmental Protection Agency issued a joint advisory confirming similar incidents across at least a dozen states since July 27, later naming Michigan, South Dakota, and Georgia among the affected states. According to the advisory, attackers specifically targeted Rockwell Automation MicroLogix 1100 and 1400 PLCs, in some cases modifying controller logic or remotely changing IP addresses and passwords to lock legitimate operators out of their own systems. Reported consequences included pressure loss and flooding, raising concern about the possibility of untreated groundwater entering drinking-water pipes.
Which Devices Are Most at Risk
Forescout’s exposure data shows MicroLogix 1400 controllers account for roughly half of all exposed devices, followed by CompactLogix 1769 at 22%, and MicroLogix 1100 and ControlLogix 5590 each around 8%. A striking detail from the research: more than 70% of exposed U.S. controllers sit inside large mobile carrier networks, connected via cellular routers — the same access path described in the FBI and EPA advisory.
Among 22 exposed hosts identified in cities hit during the recent campaign, 86% shared the same mobile carrier network, suggesting attackers may have scanned across a specific carrier’s address space to find targets. While no single CVE has been confirmed as the exploitation method in this particular wave, firmware analysis found that 19 of those 22 hosts were vulnerable to CVE-2017-16740, a Modbus TCP denial-of-service flaw dating back nearly a decade.
Forescout’s broader scan also turned up expired certificates, abandoned remote-access hostnames, and forgotten servers tied to municipal utilities — evidence, researchers say, of incomplete asset visibility that compounds risk well beyond the PLCs themselves.
Recommended Defensive Steps
Security researchers are urging utilities to treat direct internet exposure of industrial controllers as an emergency-level fix rather than a routine hardening task. Recommended actions include:
- Disconnecting PLCs from the public internet and disabling unused services such as SNMP
- Restricting Modbus TCP and port 44818 access with strict allowlists
- Moving cellular gateways to private carrier APNs or VPNs with public administration disabled
- Requiring individual accounts with multi-factor authentication for all remote access
- Prioritizing firmware upgrades for MicroLogix 1400 devices and replacement of the end-of-life MicroLogix 1100 line, which Rockwell discontinued in April 2022
Secure remote access gateways that isolate user sessions from direct protocol access are also cited as a practical middle ground, allowing utilities to maintain necessary remote operations without leaving engineering protocols exposed to anyone who finds them with a simple internet scan.
The incidents underscore a recurring theme in industrial cybersecurity: attackers increasingly don’t need a sophisticated zero-day to cause real-world disruption. An exposed cellular router, a default or reused password, and a well-known protocol port are often enough.
Leave a Reply