Cybercrime
4,400 Exposed Rockwell PLCs — The Water Utility Attacks Didn't Need a Zero-Day
Andrew Mason
August 14, 2026
Summary
Forescout's Vedere Labs identified 4,407 internet-exposed Rockwell Automation/Allen-Bradley PLCs in an August 2026 scan, including 22 in cities affected by coordinated attacks on US water utilities. Attackers achieved disruption without exploiting any vulnerability: they changed IP addresses and set passwords on controllers that were already publicly reachable.

4,400 Exposed Rockwell PLCs — The Water Utility Attacks Didn't Need a Zero-Day

In recent years, cybersecurity has taken on a new level of importance across all industries. However, the rise in cyber attacks within critical infrastructure sectors, such as water utilities, highlights a particularly worrying trend. The discovery of 4,400 exposed Rockwell PLCs (Programmable Logic Controllers) serves as a stark reminder of the vulnerabilities facing these systems. This article delves into how these exposures occurred, the implications for water utilities, and what steps can be taken to mitigate such risks.

Understanding PLCs and Their Role in Water Utilities

PLCs are digital computers used to control manufacturing processes, such as those found in factory assembly lines or infrastructure facilities. In water utilities, PLCs are crucial as they manage tasks like water purification, distribution, and monitoring. They are designed for real-time use, an essential factor for safe and efficient utility operation.

PLC systems should ideally be shielded from external network threats. However, an increasing number of these systems are being connected to the internet, often without adequate security measures, which leaves them vulnerable to cyber attacks.

The Significance of Exposing 4,400 Rockwell PLCs

Rockwell Automation is a renowned manufacturer of PLCs. The revelation that 4,400 of these systems were exposed to possible security breaches without a zero-day vulnerability being exploited is alarming. A zero-day attack involves a newly discovered vulnerability that hackers exploit before developers can issue a fix. The fact that this attack vector was unnecessary emphasises a serious lapse in existing security protocols.

How the Exposures Occurred

These exposures were not the result of extraordinarily sophisticated hacking tactics. Instead, basic security oversights played a significant role.

1. Inadequate Network Segmentation: Many utility providers failed to implement network segmentation effectively. This allowed attackers to access PLCs through less secure parts of the network.

2. Default Configurations and Passwords: A disturbingly common issue was the reliance on default configurations and passwords. These defaults are often well-documented publicly, providing an easy entry point for attackers.

3. Lack of Regular Security Audits: Many utilities did not conduct regular security audits, which could have identified vulnerabilities and exposures early.

Similar Incidents in Other Critical Sectors

This situation is not unique to water utilities. Various sectors reliant on industrial control systems (ICS), such as energy and transport, have faced similar challenges. For example, the Colonial Pipeline ransomware attack underscored vulnerabilities in critical energy infrastructure, where basic security measures were overlooked.

Consequences of the Exposed PLCs

The exposure of these Rockwell PLCs has several dire implications:

  • Compromised Water Quality: Attackers could manipulate PLCs to alter water purification processes, jeopardising water quality and public health.
  • Disruption of Services: Disruption of water supply is another potential outcome, impacting both residential areas and industries that rely on constant water supply.
  • Economic Impact: The financial consequences could be severe, with costs arising from remedial measures, legal liabilities, and loss of public trust.

Lessons Learned

The incident highlights several crucial lessons for water utilities and other ICS-dependent sectors:

  1. Prioritise Cybersecurity Education and Training: Understanding risks and training all staff, from ground employees to executives, in cybersecurity best practices is vital.
  2. Implementing Advanced Security Measures: Rockwell PLCs should be secured with layers of protection, including firewalls, intrusion detection systems, and regular software updates. DarkInvader’s Asset Monitoring provides essential tools for monitoring and securing digital assets, ensuring that exposures are identified swiftly.
  3. Conducting Routine Security Audits: Regular checks and updates are critical. Vulnerability scanning tools, such as OSINT monitoring, can help in identifying potential threats before they are exploited.
  4. Collaboration and Information Sharing: Utilities must adopt a culture of open collaboration with cybersecurity experts and share information about threats and incidents to bolster collective security efforts.

Conclusion

The exposure of 4,400 Rockwell PLCs illustrates the pressing need for a comprehensive approach to cybersecurity within critical infrastructure. Although no zero-day exploit was needed, the consequences of so many systems being exposed are potentially devastating. It underscores the importance of implementing foundational security practices and ensuring that every component, from digital assets to physical systems, is protected against evolving threats.

FAQs

How can water utilities protect PLCs from cyber attacks?

Water utilities can protect PLCs by conducting rigorous security audits, updating and patching systems regularly, using strong, unique passwords, and ensuring proper network segmentation. DarkInvader's Vulnerability Scanning service can provide early warning and defence against potential exposures.

What impact could exposed PLCs have on water quality?

Exposed PLCs could lead to an intentional or accidental modification of water treatment processes, potentially compromising water quality and posing health risks.

Why is it important to secure industrial control systems?

Securing ICS is crucial as they manage critical infrastructure services like power, water, and transport. Any disruption or manipulation can have widespread, severe impacts on public safety and economic stability.

What role does DarkInvader play in preventing cyber threats to critical infrastructure?

DarkInvader offers a suite of monitoring and security tools designed to protect digital assets from exposure, providing essential support in identifying weaknesses and defending against cyber threats.

Andrew Mason

Andrew is an entrepreneur and technology leader with a strong track record of building, scaling, and exiting high-growth technology businesses. He is the founder of several award-winning companies including RandomStorm, Data Protection People, RapidSpike, Pentest People, and DarkInvader, each operating at the forefront of cybersecurity, risk management, and digital resilience. Across these ventures, Andrew has consistently focused on creating commercially successful businesses grounded in deep technical capability and clear market need.

Sign Up for Your Free Account

Unlock full visibility of your external attack surface with DarkInvader’s continuous, real-time monitoring. Create your free account to discover unknown assets, detect emerging risks and stay ahead of potential threats before attackers can exploit them.

Create My Free Account