Forescout researchers discovered 22 internet-facing Rockwell Automation programmable logic controllers in US cities targeted by recent water utility cyberattacks. Nineteen of the exposed devices operated on the same mobile carrier network, raising concerns about infrastructure vulnerability during active threat operations.
The August 3 scan identified 4,407 exposed Rockwell controllers globally, with 2,844 located in the United States. Forescout found no evidence these specific devices were actively compromised, but the presence of internet-connected industrial control systems in water sector attack zones underscores persistent operational technology security gaps.
Rockwell Automation PLCs control critical infrastructure operations including water treatment and distribution. Direct internet exposure violates fundamental ICS security practices and creates entry points for attackers targeting essential services. The coincidence of exposed controllers in cities experiencing active water utility intrusions suggests either pre-existing reconnaissance or post-compromise persistence infrastructure.
The concentration of 19 devices on a single mobile carrier network indicates possible shared network infrastructure or configuration patterns. This clustering increases the risk of lateral movement if attackers gain foothold access to one device. Water utilities typically lack the network segmentation and air-gapping standard in other critical infrastructure sectors.
Forescout's scan methodology identifies devices through fingerprinting industrial protocols and web interfaces. The inability to confirm active compromise reflects the passive nature of network scanning and the difficulty detecting stealthy persistence in OT environments. Water utilities often lack robust endpoint detection capabilities or security monitoring on legacy systems.
The 4,407 exposed controller count worldwide represents a persistent vulnerability class. Many organizations leave industrial systems internet-accessible for remote maintenance or fail to deploy proper firewall rules. Ransomware gangs and nation-state actors routinely exploit this configuration mistake to access operational technology networks.
Water sector attacks in 2024 have targeted treatment facilities and distribution systems. Exposed PLCs
