A coordinated cyber campaign targeting internet-facing programmable logic controllers (PLCs) has disrupted water and wastewater operations across the United States, raising concerns about the vulnerabilities in exposed operational technology (OT).
These incidents highlight how publicly accessible industrial controllers can enable attackers to alter configurations, disrupt system visibility, and affect essential services.
Hackers Target Internet-Exposed Rockwell PLCs
On July 28, Minnesota IT Services reported attacks against more than 30 water systems. While no water quality degradation was reported, several municipalities confirmed operational impacts.
In Braham, attackers reportedly used malware delivered through a wireless connection to shut down water-plant controls. In Plymouth, affected water towers and sewer lift stations relied on cellular connectivity.
The FBI and the Environmental Protection Agency later warned that similar activities had affected water and wastewater utilities in at least 12 states since July 27.
Threat actors reportedly targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and MicroLogix 1400 PLCs, changing IP addresses and passwords remotely to lock legitimate operators out of monitoring and control functions. At least one victim experienced unauthorized modifications of PLC logic.
Forescout’s Vedere Labs identified 4,407 internet-facing Rockwell Automation/Allen-Bradley controllers exposing port 44818, which is used by the EtherNet/IP industrial protocol. Of these devices, 65% are located in the United States, followed by Canada at 12% and Spain at 3%.
Although the number of exposed controllers has decreased by 47% from 7,814 systems in March 2020 to 4,169 in June 2026, the remaining footprint still presents a significant attack surface.
More than 70% of exposed devices in the U.S. were found on large mobile carrier networks, suggesting extensive use of cellular routers for OT connectivity.
MicroLogix 1400 devices account for 50% of the exposed population, followed by CompactLogix 1769 systems at 22%. MicroLogix 1100 and ControlLogix 5590 devices each represent approximately 8% of observed hosts.
Researchers also identified 22 exposed systems in cities affected by the current campaign. However, there is no evidence confirming that those specific devices were compromised.
No specific CVE has been confirmed as the initial access vector in the recent attacks. However, Forescout found that 19 of the 22 exposed hosts in affected cities appeared susceptible to CVE-2017-16740, a denial-of-service issue for MicroLogix 1400 that requires Modbus TCP to be enabled, although this service exposure has not been confirmed.
Other risks include outdated firmware, hardcoded SNMP community strings, cleartext credentials, weak password protections, and end-of-life assets. Rockwell discontinued the MicroLogix 1100 in April 2022, leaving operators without future patches for that product family.
Researchers also identified expired certificates, abandoned remote-access infrastructure, and stale utility-related hostnames, indicating that incomplete asset inventories may extend beyond PLCs.
Water-sector operators should immediately remove PLCs from direct internet exposure and restrict EtherNet/IP and Modbus TCP through explicit allowlists.
It is crucial to implement secure remote-access gateways or VPNs, individual accounts, multi-factor authentication (MFA), network segmentation, and to turn off unused management services as critical control measures.
Organizations should also maintain offline backups of controller programs, monitor PLC writes and mode changes, audit cellular gateways and remote-access services, and establish replacement plans for unsupported devices. Direct public exposure of industrial controllers remains unsafe, even where no confirmed exploit is involved.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





