A new scan found more than 4,000 Rockwell Automation and Allen-Bradley controllers exposed to the public internet, including 22 located in cities that federal agencies say have experienced recent cyberattacks on water and wastewater systems.
Forescout’s Vedere Labs scan, Shodan, and the geography of exposure
Forescout’s Vedere Labs published the findings Wednesday after running a Shodan search on Monday. The researchers identified over 4,000 internet-exposed controllers that use EtherNet/IP, the industrial protocol that links control equipment, engineering workstations and other systems. Of those devices, 2,844 — 65% — were located in the United States.
Which controllers are exposed and how common each model is
The most common family observed was the MicroLogix 1400, which made up half of the exposed devices. Allen‑Bradley’s CompactLogix 1769 controllers accounted for 22% of the set. MicroLogix 1100 and ControlLogix 5590 devices each represented roughly 8% of the exposed hosts. The advisory from federal authorities specifically identified MicroLogix 1100 and 1400 models as targets in the recent attacks.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleThe FBI–EPA advisory and reported operational impacts
A joint advisory from the FBI and the Environmental Protection Agency, issued last week, confirmed attacks at water and wastewater utilities in at least 12 states since July 27. Officials have named Michigan, South Dakota and Georgia among the affected states; the advisory reported nine systems hit in Michigan and one wastewater lift station hit in South Dakota. In at least one case, attackers reached controllers remotely, changed their IP addresses and passwords, and thereby cut off the utility’s view and control of the equipment. The advisory states those actions caused pressure loss and flooding.
Vulnerabilities, protocols, and evidence about how attackers operated
Forescout’s researchers noted that many exposed devices appear, by firmware version, to be open to CVE-2017-16740, a remote code execution vulnerability disclosed in 2017 that affects MicroLogix 1400 devices. Nineteen of the 22 hosts found in recently targeted cities showed firmware consistent with that CVE, but the researchers could not confirm whether Modbus TCP — a requirement to exploit that flaw in practice — was enabled on the systems observed.
Sai Molige, senior manager of threat hunting at Forescout, emphasized the company’s caution on attribution: “The evidence supports opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices,” he told CyberScoop. “The scale and speed of the activity are more consistent with mass scanning and enumeration than with zero-day exploitation, a months-long intrusion campaign, or custom malware.”
Digital hygiene problems beyond controllers: certificates, remote-access URLs, abandoned servers
Beyond exposed controllers, Vedere Labs documented a range of stale or neglected services tied to utilities. The researchers found expired certificates, remote-access web addresses left unrenewed for months or years, and servers that appear abandoned — including one that has served only a default Microsoft webpage since April 2019. Forescout warned that such stale services can increase the attack surface, though the company said it has not yet confirmed precisely how the observed attacks occurred.
Manufacturers and vendors have long warned against placing controllers on the public internet: Rockwell Automation and other industrial equipment makers issued guidance at least as far back as 2018 advising customers not to expose controllers directly to the internet.
What this means for technologists, policymakers, and utilities
- Technologists and security teams — Watch for internet-facing EtherNet/IP ports, check firmware versions against CVE-2017-16740, and confirm whether Modbus TCP is enabled on exposed devices; many of the controllers identified are common Allen‑Bradley models that the advisory named directly.
- Policymakers and federal agencies — The FBI–EPA joint advisory and Forescout’s scan underline that federal warning and incident notification mechanisms are active; authorities now face a question about whether and how to broaden guidance or require mitigation given documented, public exposure of controllers.
- Utilities and operators — The advisory documents real operational impacts — pressure loss and flooding — after attackers changed IP addresses and passwords on controllers. Operators will need to verify remote-access endpoints, renew or revoke expired certificates, and identify any default or abandoned servers tied to operational networks.
The record compiled by Forescout and the joint federal advisory presents a focused but unsettling fact pattern: thousands of controllers are reachable from the public internet, dozens sit in municipalities already flagged by federal investigators, and a majority of those devices in the U.S. are common models whose vendors have long warned against internet exposure. Forescout has not attributed the activity to any actor, and researchers could not confirm whether specific exploitation paths — such as Modbus TCP-enabled CVE-2017-16740 attacks — were used. The next concrete test will be whether operators can remove controllers from direct internet access, validate their remote‑access configurations, and close the gap between public scans and confirmed defensive remediation.




