Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Cybersecurity researchers have uncovered a staggering number of Rockwell Automation Programmable Logic Controllers (PLCs) exposed online, leaving over 4,400 industrial control systems vulnerable to cyber attacks. What’s more alarming is that at least 22 of these compromised devices are located in cities that have been the target of water attacks in the past, raising concerns about the potential for devastating consequences.

Rockwell Automation PLCs are widely used in industries such as manufacturing, oil and gas, and power generation to control and automate processes. They are connected to the internet, making them accessible remotely, but also creating a potential entry point for hackers. The exposed devices were discovered through a reconnaissance scan of publicly facing IP addresses associated with Rockwell Automation systems. While it’s unclear how long these devices have been exposed, experts warn that this is just the tip of the iceberg.

The vulnerability stems from poor configuration and management practices, which allow unauthorized access to the PLCs’ control interfaces. Once inside, an attacker can manipulate system settings, inject malicious code, or even take control of the entire network. The severity of this issue lies in its potential for cross-domain privilege escalation, allowing hackers to jump from one compromised device to another, creating a cascade of breaches. This scenario is eerily reminiscent of previous water attacks, where attackers exploited vulnerabilities in industrial control systems to gain access to critical infrastructure.

The fact that 22 of these exposed devices are located in cities targeted by water attacks is particularly concerning. These cities include Flint, Michigan; Newark, New Jersey; and Baltimore, Maryland – all of which have experienced devastating consequences from compromised water supplies. While it’s unclear whether the exposed PLCs were directly involved in these incidents, their presence raises questions about the resilience of industrial control systems against sophisticated cyber threats.

The discovery of this massive exposure highlights the urgent need for better security practices within industries that rely on connected systems. Organizations must adopt a proactive approach to identifying and addressing vulnerabilities, including implementing robust network segmentation, regular software updates, and thorough system configuration reviews. By doing so, they can minimize the risk of attacks and protect their operations from potential disruptions.

As the industrial landscape continues to shift towards greater connectivity and automation, it’s crucial that we address the associated cybersecurity risks head-on. The exposed Rockwell Automation PLCs are a stark reminder that even the most critical infrastructure is not immune to cyber threats. By prioritizing security and adopting best practices, industries can mitigate the impact of attacks and safeguard their operations against potential breaches.


Source: The Hacker News — 2026-08-06