Interestana
Home/News/4,407 Rockwell PLCs Exposed Online; 22 in Water Attack Cities
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

4,407 Rockwell PLCs Exposed Online; 22 in Water Attack Cities

4,407 Rockwell PLCs Exposed Online; 22 in Water Attack Cities

Forescout researchers identified 4,407 internet-facing Rockwell Automation programmable logic controllers (PLCs) globally during an August 3 scan, with 2,844 of these located in the United States. Notably, 22 of these exposed controllers were found in cities that have recently experienced cyberattacks targeting their water utilities. Nineteen of these 22 controllers in affected cities were utilizing the same mobile carrier network, suggesting a potential common vulnerability or attack vector. While Forescout confirmed the exposure of these devices, they were unable to verify if any of them had been compromised.

Programmable Logic Controllers (PLCs) are industrial computers that are critical for automating and controlling manufacturing processes and infrastructure. Rockwell Automation is a prominent provider of industrial automation and information solutions, including PLCs used in a wide range of sectors, from manufacturing to utilities. The exposure of these devices to the internet, rather than being secured within private industrial control system (ICS) networks, significantly increases their vulnerability to cyber threats. Such exposure can allow malicious actors to gain unauthorized access, disrupt operations, or even cause physical damage.

The discovery highlights ongoing risks within the Industrial Internet of Things (IIoT) and critical infrastructure security. The fact that some exposed PLCs are located in municipalities that have recently been victims of cyberattacks on their water systems raises particular concern. These attacks can have severe consequences, including the potential contamination of water supplies or the disruption of essential services. The specific mention of a shared mobile carrier network among some of the exposed controllers in affected cities could indicate a pathway for attackers to exploit vulnerabilities across multiple targets simultaneously, possibly through a compromised network infrastructure or a shared service provider.

Forescout's findings underscore the persistent challenge of securing operational technology (OT) environments. Many legacy industrial systems were not designed with modern cybersecurity threats in mind, and their integration into the internet-connected world, often for remote monitoring or management, creates new attack surfaces. The company's scan aimed to quantify the extent of this exposure, providing a snapshot of devices that are potentially accessible from anywhere in the world. The absence of confirmed compromises in this specific scan does not negate the inherent risk; it simply means that active exploitation was not detected at the time of the scan. Continued vigilance and proactive security measures are essential to protect these critical systems from potential future attacks.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next