Affected Systems
Rockwell Automation programmable logic controllers (PLCs) globally: 4,407 exposed devices (2,844 in US). Primary models: MicroLogix 1400 (50%) and MicroLogix 1100 (8%). 22 controllers found in US cities recently targeted in water utility cyberattacks. Over 70% of US-exposed controllers on mobile carrier networks (Verizon, AT&T, T-Mobile). MicroLogix 1100 discontinued April 2022.
Exploitation Status
Active exploitation confirmed in recent water utility attacks across at least 7 US states since July 27, 2026. Attackers changed IP addresses and set passwords on exposed controllers without exploiting vulnerabilities. 19 of 22 controllers in affected cities run firmware vulnerable to CVE-2017-16740 (Modbus TCP buffer overflow, CVSS 8.6, patched in firmware 21.003), though exploitation of this CVE not confirmed. No attribution yet.
Business Impact
Critical infrastructure controllers directly reachable from the internet allow unauthenticated attackers to identify devices and potentially write settings via EtherNet/IP port 44818. Successful attacks cause loss of visibility and control over connected equipment. Water utilities in 7+ states already impacted. Attackers can lock out operators by setting passwords. Recovery requires physical access and offline backup of controller logic. Third-party network configurations may enable repeatable attacks across multiple customers.
Urgency
đź”´ Immediate
Recommended Actions
- Remove all Rockwell PLCs from direct internet exposure immediately; isolate remote access behind VPN, private APN, or equivalent architecture
- Audit mobile carrier connections (Verizon Business, AT&T Mobility, T-Mobile USA) for exposed EtherNet/IP services on port 44818 and disable public access
- Update MicroLogix 1400 Series B and C firmware to revision 21.003 or later to address CVE-2017-16740; verify Modbus TCP is disabled if not required
- Implement strong authentication and logging on all cellular modems used for PLC remote access; review third-party network provider configurations
- Maintain current offline backups of all PLC project files and ladder logic to enable rapid recovery if controllers are locked out or modified
---
# Geopolitical Context
Geopolitical Context
The discovery of 4,407 internet-facing Rockwell Automation PLCs—including 2,844 in the United States—underscores persistent operational technology (OT) security gaps in critical infrastructure. Forescout's identification of 22 exposed controllers in cities recently targeted by water utility cyberattacks highlights the intersection of systemic misconfiguration and active threat campaigns. The attacks, affecting utilities in at least seven states since July 27, 2026, exploited controllers already reachable via the public internet, requiring no vulnerability exploit to alter IP addresses and passwords, thereby denying operators visibility and control. The FBI and EPA have issued public service announcements but have not attributed the campaign. The concentration of 70% of US-exposed controllers on major mobile carrier networks (Verizon Business, AT&T Mobility, T-Mobile USA) points to widespread reliance on cellular connectivity without adequate segmentation or authentication. The presence of legacy devices—50% MicroLogix 1400, 8% MicroLogix 1100 (discontinued April 2022)—and firmware vulnerable to CVE-2017-16740 (a Modbus TCP buffer overflow patched in 2017) illustrates deferred maintenance and lifecycle management challenges endemic to water and wastewater sectors. This incident reflects broader trends in critical infrastructure targeting, where adversaries exploit publicly accessible OT assets rather than sophisticated zero-day vulnerabilities, lowering the barrier to disruptive operations.
State Actor Alignment
No attribution has been provided by US federal agencies. The FBI and EPA joint advisory of July 30, 2026, confirmed incidents across multiple states but did not link the campaign to any state or non-state actor. The attack methodology—exploiting internet-exposed PLCs without requiring vulnerability exploits—is consistent with both opportunistic cybercriminal activity and state-aligned reconnaissance or disruption operations. The FBI noted that at least one victim discovered modified PLC project files and ladder logic discrepancies across multiple sites, and warned that similar third-party network configurations may enable attackers to replicate compromises across customers sharing vulnerable setups. This pattern suggests either a coordinated campaign or shared infrastructure vulnerabilities being exploited by a single actor or group. Absent formal attribution, the incident remains within the broader context of heightened US critical infrastructure threat warnings, including ongoing concerns about state-sponsored targeting of water, energy, and transportation sectors by actors linked to China, Russia, Iran, and North Korea.
Business Impacty pro region
While the immediate impact is concentrated in the United States, the global exposure of 4,407 Rockwell PLCs—with significant numbers outside the US—indicates that similar vulnerabilities exist across allied and partner nations' critical infrastructure. European water utilities, many of which also rely on legacy Rockwell Automation and Allen-Bradley controllers, face comparable risks from internet-exposed OT devices. The reliance on mobile carrier networks for remote PLC access is not unique to North America; European and Asia-Pacific utilities increasingly deploy cellular connectivity for distributed assets, often without private APNs, VPNs, or robust segmentation. The incident may prompt regulatory scrutiny under the EU's NIS2 Directive and critical infrastructure protection frameworks in NATO member states, particularly as water and wastewater systems are designated essential services. The lack of attribution complicates coordinated response but underscores the need for transatlantic cooperation on OT security standards, threat intelligence sharing, and incident disclosure. The FBI's warning that third-party network providers may enable lateral movement across customers has implications for managed service providers and system integrators operating in multiple jurisdictions, potentially triggering supply chain security reviews in Europe and beyond.
Forecast
If US federal agencies issue formal attribution linking the water utility attacks to a state actor, expect coordinated sanctions, diplomatic responses, and heightened critical infrastructure protection mandates, particularly targeting OT internet exposure and mobile carrier segmentation. If the campaign remains unattributed or is assessed as opportunistic, regulatory focus will likely shift toward enforcing baseline OT hygiene—removing PLCs from public internet access, mandating firmware updates, and requiring private network architectures for remote access. The concentration of exposed devices on major US mobile carriers may prompt Federal Communications Commission (FCC) or Cybersecurity and Infrastructure Security Agency (CISA) guidance on carrier-provided security controls for critical infrastructure customers. If additional water utilities report incidents or if the campaign expands to other sectors (energy, transportation), expect emergency directives under CISA authorities and accelerated adoption of OT asset discovery and network segmentation tools. European regulators may reference this incident in NIS2 enforcement actions, particularly for water utilities failing to inventory and secure internet-facing OT assets. If proof emerges that attackers leveraged shared third-party network configurations to move laterally across utilities, expect increased scrutiny of managed service providers and potential liability or certification requirements for OT system integrators.
