4,400 Rockwell PLCs Are Sitting on the Internet — 22 of Them in Cities Already Under Attack
A Forescout scan found thousands of internet-facing Rockwell controllers worldwide, with a small cluster in US cities that recently suffered water utility attacks. Exposure isn't compromise, but it's the precondition for it.
Forescout’s numbers from its August 3 scan are the kind that get shared widely and then argued about: 4,407 Rockwell Automation PLCs reachable from the internet worldwide, 2,844 of them in the United States. The headline detail is smaller but sharper — 22 of those exposed controllers sit in cities that recently experienced cyberattacks against water utilities, and 19 of those 22 ride on the same mobile carrier network. Forescout is careful to say it found no evidence any of them were actually compromised. That caveat matters, but it shouldn’t be the takeaway.
Exposed doesn’t mean breached. It means the door is unlocked, not that someone walked through it. The gap between those two facts is where a lot of ICS risk assessment goes wrong, in both directions. Some teams see an exposure count like this and panic, treating every internet-facing PLC as an active incident. Others see “no evidence of compromise” and file it under someone else’s problem. Neither reaction is useful. The right response is to treat exposure as the precondition for compromise and go find out what actually happens if someone tries.
The cellular pattern is the real story
The detail worth sitting with is the shared mobile carrier. Nineteen controllers on one network, clustered geographically with attacked utilities, strongly suggests a common integration pattern rather than coincidence — probably cellular routers deployed by the same systems integrator, vendor, or regional utility cooperative for remote monitoring or support access. That’s a familiar shape in water and wastewater. A contractor sets up cellular remote access to a PLC for maintenance convenience, the project ends, the access stays, and five years later nobody on staff remembers it’s there or who has the credentials. Multiply that pattern across dozens of small utilities using the same integrator and you get exactly the kind of correlated exposure Forescout is describing.
This is why small water systems keep showing up in these reports. They don’t lack security awareness so much as they lack headcount — one person often manages IT, OT, and physical plant maintenance, and remote access exists because there’s no other way to get support at 2am when a pump fails. The fix isn’t “get better people,” it’s closing off avoidable exposure paths (VPN instead of directly routable cellular IPs, for a start) and, just as important, verifying that the controllers behind that access actually enforce the authentication and logic-protection settings they’re supposed to.
What a scan can’t tell you
A network scan tells you a controller answers on a port. It doesn’t tell you whether that controller’s default credentials were ever changed, whether its firmware accepts unauthenticated logic uploads, or whether an attacker who reaches it can actually manipulate a process safely away from operator notice. Those are different questions, and they require actually trying — safely, against a validated model or a maintenance window, not against live production. Rockwell has published guidance for years on locking down remote access and controller configuration; the gap is rarely knowledge, it’s confirmation that the guidance was actually implemented and still holds after the last three change requests.
Forescout’s count is useful as a wake-up call. It’s not a substitute for asking each utility on that list the only question that matters: if someone reaches that PLC right now, what can they actually do?
Source: https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html