Forescout: 4,407 Rockwell PLCs Exposed; 22 in Attack Cities

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Forescout's August 3 scan counted 4,407 internet-exposed Rockwell Automation controllers worldwide, including 2,844 in the United States and 22 in cities hit by recent water-utility attacks, 19 of which shared the same mobile carrier network; the firm could not confirm any had been compromised.
- Attackers didn't need a vulnerability exploit to hit the water utilities — they changed IP addresses and set passwords on already-reachable controllers, stripping operators of visibility and, in some cases, control of connected equipment.
- The FBI and EPA said on July 30 that water and wastewater utilities in at least seven states had reported incidents since July 27, though Forescout's reading of the same announcement puts the count at 12 states; no agency has attributed the campaign.
- CVE-2017-16740, a Modbus TCP buffer overflow scored 8.6 by Rockwell, was present in firmware on 19 of the 22 controllers in attacked cities; the bug affects MicroLogix 1400 Series B and C running firmware 21.002 or earlier, which Rockwell patched in revision 21.003.
- MicroLogix 1400 devices made up 50% of Forescout's exposed-controller results and MicroLogix 1100 devices 8%; Rockwell discontinued the 1100 on April 30, 2022.
- The FBI said at least one victim discovered modified PLC project files after spotting ladder-logic discrepancies across several sites, warning that shared third-party network setups could let attackers replay successful compromises across customers with identical configurations.
Why it matters: No agency has attributed the campaign hitting water utilities in at least seven states since July 27, and Forescout found 4,407 Rockwell controllers still publicly reachable — over 70% on mobile carrier networks — giving attackers low-friction paths to critical infrastructure. The immediate lever is pulling exposed PLCs offline rather than waiting for an attribution or a patch.




