Tuesday, September 22, 2026

Hackers Target Internet-Exposed Rockwell PLCs in U.S. Water Systems

A coordinated cyber campaign targeting internet-facing programmable logic controllers (PLCs) has disrupted water and wastewater operations across the United States, raising concerns about the vulnerabilities in exposed operational technology (OT).

These incidents highlight how publicly accessible industrial controllers can enable attackers to alter configurations, disrupt system visibility, and affect essential services.

Hackers Target Internet-Exposed Rockwell PLCs

On July 28, Minnesota IT Services reported attacks against more than 30 water systems. While no water quality degradation was reported, several municipalities confirmed operational impacts.

In Braham, attackers reportedly used malware delivered through a wireless connection to shut down water-plant controls. In Plymouth, affected water towers and sewer lift stations relied on cellular connectivity.

The FBI and the Environmental Protection Agency later warned that similar activities had affected water and wastewater utilities in at least 12 states since July 27.

Threat actors reportedly targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and MicroLogix 1400 PLCs, changing IP addresses and passwords remotely to lock legitimate operators out of monitoring and control functions. At least one victim experienced unauthorized modifications of PLC logic.

Forescout’s Vedere Labs identified 4,407 internet-facing Rockwell Automation/Allen-Bradley controllers exposing port 44818, which is used by the EtherNet/IP industrial protocol. Of these devices, 65% are located in the United States, followed by Canada at 12% and Spain at 3%.

Although the number of exposed controllers has decreased by 47% from 7,814 systems in March 2020 to 4,169 in June 2026, the remaining footprint still presents a significant attack surface.

More than 70% of exposed devices in the U.S. were found on large mobile carrier networks, suggesting extensive use of cellular routers for OT connectivity.

MicroLogix 1400 devices account for 50% of the exposed population, followed by CompactLogix 1769 systems at 22%. MicroLogix 1100 and ControlLogix 5590 devices each represent approximately 8% of observed hosts.

Researchers also identified 22 exposed systems in cities affected by the current campaign. However, there is no evidence confirming that those specific devices were compromised.

No specific CVE has been confirmed as the initial access vector in the recent attacks. However, Forescout found that 19 of the 22 exposed hosts in affected cities appeared susceptible to CVE-2017-16740, a denial-of-service issue for MicroLogix 1400 that requires Modbus TCP to be enabled, although this service exposure has not been confirmed.

Other risks include outdated firmware, hardcoded SNMP community strings, cleartext credentials, weak password protections, and end-of-life assets. Rockwell discontinued the MicroLogix 1100 in April 2022, leaving operators without future patches for that product family.

Researchers also identified expired certificates, abandoned remote-access infrastructure, and stale utility-related hostnames, indicating that incomplete asset inventories may extend beyond PLCs.

Water-sector operators should immediately remove PLCs from direct internet exposure and restrict EtherNet/IP and Modbus TCP through explicit allowlists.

It is crucial to implement secure remote-access gateways or VPNs, individual accounts, multi-factor authentication (MFA), network segmentation, and to turn off unused management services as critical control measures.

Organizations should also maintain offline backups of controller programs, monitor PLC writes and mode changes, audit cellular gateways and remote-access services, and establish replacement plans for unsupported devices. Direct public exposure of industrial controllers remains unsafe, even where no confirmed exploit is involved.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers

NightEagle, an espionage-focused threat group also tracked as APT-Q-95,...

10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads

A sophisticated npm supply-chain campaign has been linked to...

New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools

A newly identified information-stealing campaign, tracked as Rapuncel, is...

BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates

A recently published proof-of-concept project named BigDiskBuster claims to...

Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords

Threat actors are increasingly abusing Microsoft Teams' external chat...

New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches

Security researchers have unveiled a cache poisoning technique called...

Related Articles

Recent News