Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
August 6, 2026
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Critical Flaws in Anthropic, Google, OpenAI Coding Agents Allow RCE
August 6, 2026
Home/CyberSecurity News/Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
CyberSecurity News

Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks

Key Takeaways Thousands of Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) remain directly exposed to the internet, particularly in critical water and wastewater...

David kimber
David kimber
August 6, 2026 3 Min Read
4 0

Key Takeaways

  • Thousands of Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) remain directly exposed to the internet, particularly in critical water and wastewater infrastructure.
  • A recent wave of cyberattacks has targeted U.S. water systems, exploiting these internet-facing PLCs and causing operational disruptions.
  • The attacks have leveraged vulnerabilities in specific MicroLogix models, with threat actors modifying PLC logic or locking out operators.
  • Immediate action is required for critical infrastructure operators to secure PLCs, implement robust remote access controls, and upgrade or replace vulnerable equipment.

Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks

Recent cyberattacks against U.S. water and wastewater utilities have reignited concerns regarding the widespread exposure of industrial control systems to the public internet. New analysis reveals thousands of critical devices are readily accessible, creating a significant attack surface for malicious actors.

Table Of Content

  • Key Takeaways
  • Critical Rockwell Automation Flaw Exposes Water Systems to Cyberattacks
  • Widespread Exposure of Rockwell PLCs
  • Coordinated Attacks Target Water Utilities
  • Vulnerable Devices and Attack Vectors
  • What You Should Do

Widespread Exposure of Rockwell PLCs

Research conducted by Forescout has identified 4,407 Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs) that are directly reachable from the internet, exposing port 44818, which is used by the EtherNet/IP engineering protocol. A staggering 65% of these exposed devices are located in the United States, with Canada accounting for 12% and Spain for 3%.

While this figure represents a 47% reduction from a peak of 7,814 exposed devices in March 2020, and a low of 4,169 in June 2026, the sheer volume of accessible systems continues to leave vital infrastructure vulnerable to compromise.

Coordinated Attacks Target Water Utilities

On July 28, Minnesota IT Services (MNIT) reported a coordinated cyberattack impacting over 30 water systems across the state. While no instances of degraded water quality were confirmed, operational disruptions were reported in cities including Plymouth, South St. Paul, Maple Plain, and Braham.

Braham authorities indicated that attackers utilized malware delivered via a wireless connection to disable water plant controls. Plymouth reported that the affected equipment, which included two water towers and 14 sewer lift stations, was connected through cellular routers.

Just two days later, the FBI and EPA issued a joint advisory, confirming similar incidents in at least 12 states since July 27, with Michigan, South Dakota, and Georgia later identified as affected regions.

Vulnerable Devices and Attack Vectors

The advisory disclosed that threat actors specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. In some cases, attackers modified PLC logic or remotely altered IP addresses and passwords, effectively locking out legitimate operators. Reported consequences included pressure loss and flooding, raising serious concerns about the potential for untreated groundwater to contaminate drinking water supplies.

Analysis shows that MicroLogix 1400 devices constitute approximately 50% of the exposed controllers, followed by CompactLogix 1769 at 22%. MicroLogix 1100 and ControlLogix 5590 each account for 8%. Notably, over 70% of U.S.-based controllers are situated within major mobile carrier networks, connected via cellular routers, a configuration that aligns with the access method described in the FBI/EPA advisory.

Among 22 exposed hosts identified in cities targeted during the recent campaign, 86% shared the same mobile carrier network. Although no specific CVE has been definitively linked as the exploitation vector in these attacks, firmware analysis revealed that 19 of these 22 hosts were susceptible to CVE-2017-16740, a Modbus TCP denial-of-service vulnerability.

Forescout researchers also uncovered additional vulnerabilities such as expired certificates, abandoned remote-access hostnames, and forgotten servers associated with municipal utilities. This evidence points to incomplete asset visibility, exacerbating the overall risk beyond just the PLCs themselves.

What You Should Do

  • Disconnect PLCs from the Public Internet: Ensure that all Programmable Logic Controllers are not directly accessible from the internet.
  • Disable Unused Services: Deactivate unnecessary services, such as SNMP, on all industrial control devices.
  • Restrict Port Access: Implement strict allowlists to control access to Modbus TCP and port 44818.
  • Secure Cellular Gateways: Move cellular gateways to private carrier APNs or protect them with VPNs. Disable public administration interfaces.
  • Enforce Multi-Factor Authentication: Mandate individual accounts with multi-factor authentication for all remote access.
  • Plan Firmware Upgrades: Schedule and perform firmware upgrades for MicroLogix 1400 devices.
  • Prioritize Replacement of End-of-Life Equipment: Replace MicroLogix 1100 devices, which Rockwell discontinued in April 2022.
  • Implement Secure Remote Access (SRA) Gateways: Utilize SRA gateways to isolate user sessions from direct protocol access, providing a crucial layer of protection for remote operations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Vanta Stealer Drains Browser, Crypto, and Gaming Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Paperclip Flaws Let Attackers Gain Admin Access
August 6, 2026
Fake Movie Download Exposes Passwords, Payments, Crypto Assets
August 6, 2026
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us