22 Rockwell PLCs Found in Water Attack Cities: What That Means for Critical Infrastructure

·
Listen to this article~6 min
22 Rockwell PLCs Found in Water Attack Cities: What That Means for Critical Infrastructure

Forescout found 22 exposed Rockwell PLCs in cities hit by water utility attacks, with 19 on the same mobile network. Over 4,400 controllers are exposed worldwide.

When you think about cybersecurity threats, your mind probably jumps to data breaches, ransomware, or stolen credit cards. But there's a quieter, scarier problem lurking in the background: the industrial control systems that keep our water flowing, power running, and cities functioning. A recent discovery by Forescout just put a spotlight on that exact issue, and it's one that should concern anyone who cares about critical infrastructure. Here's the short version: Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) sitting in cities that were recently hit by cyberattacks on US water utilities. Nineteen of those controllers were using the same mobile carrier network. That's a striking pattern, and it raises some serious questions about how vulnerable our water systems really are. ### What Did Forescout Actually Find? On August 3, Forescout ran a scan that counted 4,407 exposed Rockwell controllers worldwide. Of those, 2,844 were in the United States. That's a massive number. But here's the important caveat: Forescout could not confirm that any of those controllers were actually compromised. The exposure itself doesn't mean an attack happened. It just means the door was open, and that's a big deal. The fact that 22 of those exposed controllers were in cities that had already been targeted by water utility attacks is what makes this story so unsettling. It's not just a theoretical risk anymore. These are places where attackers have already shown interest, and the infrastructure is sitting there, connected to the internet. ### Why Should You Care About Exposed PLCs? PLCs are the workhorses of industrial automation. They control everything from water treatment processes to assembly lines. When a PLC is exposed to the internet, it's like leaving the keys in the ignition of a car in a high-crime neighborhood. It doesn't mean someone will steal it, but it certainly increases the odds. For water utilities, the stakes are even higher. A compromised PLC could potentially disrupt water treatment, alter chemical dosing, or even shut down pumps. In the worst-case scenario, that could affect drinking water quality or availability. That's not just a technical problem. That's a public safety issue. ### The Mobile Carrier Connection One of the most interesting details from the Forescout scan is that 19 of the 22 controllers found in attack-hit cities were on the same mobile carrier network. That suggests a pattern. It could mean these systems are deployed in a similar way, perhaps using the same kind of cellular modem or network configuration. It also means an attacker who figures out how to exploit one could potentially target the others with ease. This is a classic case of common attack surface. When systems share the same network infrastructure, they become a more attractive target. One vulnerability could cascade across multiple sites. That's why network segmentation and monitoring are so critical for industrial environments. ### What This Means for Industrial Security The takeaway here isn't just about Rockwell or PLCs. It's about the broader state of industrial cybersecurity. Many of these systems were designed decades ago, long before internet connectivity was even a consideration. They were built for reliability and uptime, not security. That's a dangerous combination in today's connected world. Here are a few things that need to happen to address this risk: - **Inventory and exposure checks:** Utilities need to know exactly what's connected to the internet and why. - **Network segmentation:** Critical systems should never be directly reachable from the public internet. - **Regular patching:** Many of these controllers run outdated firmware with known vulnerabilities. - **Monitoring for anomalies:** If a PLC starts behaving oddly, that's a red flag worth investigating immediately. ### The Bottom Line The Forescout findings are a wake-up call. We have thousands of industrial controllers exposed online, and some of them are in places where attackers have already struck. That's not a coincidence. It's a pattern that demands attention. Whether you work in cybersecurity, run a utility, or just care about having safe drinking water, this matters. The good news is that exposure doesn't equal compromise. The bad news is that it only takes one successful attack to cause real damage. The time to act is now, before another headline forces the issue. If you're responsible for any kind of industrial infrastructure, take a hard look at your own systems. Ask yourself: Are my PLCs exposed? Could I detect an intrusion? If the answer isn't a confident yes, it's time to make some changes. The water in your community might depend on it.