OT / ICS · 53 days ago
Internet-exposed PLCs are the real control plane here. If a Rockwell controller is reachable from the internet, an attacker may be able to change its settings or lock operators out without first breaking a vulnerability, and that failure mode can spread across sites that share the same access pattern.
Forescout counted 4,407 exposed Rockwell PLCs worldwide on August 3, including 2,844 in the U.S., and found 22 in cities that had reported water-utility incidents. Nineteen of those 22 used the same mobile carrier network, which turns a local exposure problem into a grouped one.
The risk is not limited to any one site or flaw. Standard OT defenses that look for malware or a product bug can miss direct device access, and firmware fixes do not remove the exposure created by a public management path.
2 sources covering this story
New research reveals over 4,000 Rockwell Automation controllers exposed online, including 22 in cities recently targeted by cyberattacks on U.S.
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 exposed Rockwell PLCs in cities hit by water attacks; direct access can let attackers change settings without exploiting a flaw.
Part of the PlainSec briefing for 2026-08-07