Forescout: 22 Rockwell PLCs Exposed in Hacked US Water Cities

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Forescout found 22 internet-facing Rockwell Automation PLCs in US water cities hit by recent cyberattacks, with 19 of 22 sharing the same mobile carrier network.
- Forescout's August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the US, though the firm said it could not confirm any were compromised.
- The researchers concluded the publicly described effects were achieved without exploiting a vulnerability — attackers changed IP addresses and set passwords on already-reachable controllers, stripping operators of visibility and, in some cases, control of connected equipment.
- The FBI and EPA reported water and wastewater utility incidents in at least seven states since July 27 in a July 30 public service announcement, while Forescout's post cited 12 states; no agency has attributed the campaign.
- MicroLogix 1400 devices made up 50% of Forescout's exposed-controller results, and 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740, an 8.6-CVSS Modbus TCP buffer overflow that Rockwell patched in firmware revision 21.003.
- The FBI warned that at least one victim found modified PLC project files after spotting ladder logic discrepancies across multiple sites, and that similar third-party network setups could let attackers repeat successful compromises across customers sharing vulnerable configurations.
- Rockwell discontinued the MicroLogix 1100 on April 30, 2022, and published Advisory SD1790 as recovery guidance for password-locked devices — a fix that requires operators to hold a current offline copy of the controller logic.
Why it matters: Water utilities across at least seven states have reported incidents since July 27 with no attribution, yet 19 of 22 exposed Rockwell controllers in hacked cities shared a single mobile carrier network and ran firmware vulnerable to flaws patched in 2017 — meaning the immediate remedy is simply to take the controllers off the public internet.




