Water utilities discover the hard way that 'plugged directly into the internet' is not a security strategy
Forescout identified 4,407 internet-facing Rockwell PLCs worldwide, including 2,844 in the US, with 22 located in cities hit by recent coordinated cyberattacks on water utilities. Most exposed controllers sit on large mobile carrier networks, and attackers needed no zero-day—just unauthenticated EtherNet/IP access on port 44818 to change IP addresses and set passwords, severing operator visibility and control. Over half are MicroLogix 1400/1100 devices, many running firmware susceptible to a 2017 vulnerability, though Forescout stresses that firmware updates alone don't make public PLC exposure acceptable. The FBI and EPA recommend isolating remote access via VPN or private APN, and Rockwell has published factory-reset recovery guidance for locked-out operators.