4,407 — that is the number Forescout reported on August 3 for Rockwell Automation programmable logic controllers (PLCs) it found exposed to the public internet, including 2,844 in the United States.
Forescout’s August 3 scan: scale and concentration
Forescout’s August 3 snapshot counted 4,407 internet-facing Rockwell controllers worldwide; the firm noted 2,844 of those were in the United States. The company also identified 22 internet-facing Rockwell PLCs located in cities that have reported recent cyber incidents against water utilities, and said 19 of those 22 “used the same mobile carrier network.” Forescout cautioned that its numbers document exposed controllers, not confirmed compromises, and that it could not verify whether any particular controller had been compromised.
How exposure can be exploited without new software flaws
Researchers warned that the publicly described operational effects against water utilities could be achieved without exploiting a software vulnerability. According to Forescout, attackers changed IP addresses and set passwords on controllers that were already reachable, which in some cases caused operators to lose visibility — and in some cases control — of connected equipment. Exposing EtherNet/IP on port 44818 creates “an unauthenticated path” that, depending on device configuration, can let an attacker identify a controller or write settings to it, the firm said.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCVE-2017-16740, MicroLogix firmware, and recovery guidance
Forescout found that MicroLogix 1400 devices made up roughly 50% of its results and MicroLogix 1100 devices about 8%. Nineteen of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow that affects MicroLogix 1400 Series B and C running firmware 21.002 and earlier. Rockwell fixed that issue in revision 21.003. Forescout noted that exploitation requires Modbus TCP to be enabled, which the firm could not verify on the exposed hosts.
Rockwell discontinued the MicroLogix 1100 on April 30, 2022. Advisory SD1790 from Rockwell provides operators a recovery path to reset a MicroLogix 1400 or 1100 to factory defaults and redownload a known-good project file when an attacker-set password has locked them out; the advisory carries no CVE because it is recovery guidance rather than a vulnerability disclosure. That recovery process requires a current offline copy of the controller logic — a point underscored by the FBI’s observation that at least one victim found modified PLC project files after detecting ladder logic discrepancies across multiple sites.
Cellular carrier concentration and federal recommendations
Both Forescout and a July 30 Censys snapshot showed large carrier involvement among exposed hosts. Forescout reported more than 70% of the U.S.-based exposed controllers were on large mobile carrier networks. Censys’ July 30 snapshot found 4,148 exposed Rockwell/Allen‑Bradley EtherNet/IP hosts and attributed 59% of those to Verizon Business, AT&T Mobility and T‑Mobile USA. In response to the incidents, the FBI and EPA recommended strong authentication, firmware updates, and logging for cellular modems, and they advised isolating remote access through a private APN, a VPN, or a similar architecture.
FBI and EPA notices, incident counts, and repeatable third‑party risk
The FBI and EPA said in a July 30 public service announcement that water and wastewater utilities in at least seven states had reported incidents since July 27. Reporting is inconsistent: The Hacker News noted on August 6 that Forescout’s post references at least 12 states while the FBI page cites seven. No agency has attributed the campaign. The FBI also warned that similar third‑party network setups may allow attackers to repeat successful compromises across customers that share vulnerable configurations.
What this means for water utilities, security teams, and Rockwell operators
- Water utilities: Operators should check for internet-exposed EtherNet/IP services (port 44818) and ensure controllers are not directly reachable from the public internet; the source guidance explicitly says defenders can act now by taking controllers off the public internet.
- Security teams and network engineers: Agencies recommend strong authentication and logging for cellular modems and isolating remote access via private APN, VPN, or similar. Teams should verify whether Modbus TCP is enabled on exposed MicroLogix devices and confirm firmware revisions (MicroLogix 1400 revision 21.003 addresses CVE-2017-16740).
- Rockwell operators and integrators: Maintain current offline copies of controller logic because Rockwell’s SD1790 recovery guidance depends on those backups; the FBI’s field finding that modified project files were observed underscores that recovery without an offline known-good project can be difficult.
Forescout’s historical series shows the community’s exposure has fluctuated: its June 2026 low was 4,169 exposed controllers, down 47% from 7,814 in March 2020, yet the August 3 snapshot rose to 4,407. Whatever the precise tally of affected cities or the final incident count, the record in this reporting is straightforward: internet-exposed Rockwell PLCs remain measurable in the thousands, many sit behind major mobile carriers, and simple misconfiguration or accessible services can produce the operational effects reported against U.S. water utilities. Taking controllers off the public internet and hardening cellular remote access are concrete steps agencies and vendors are explicitly urging now.
Source: The Hacker News — Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities




