Forescout finds 4,407 internet-exposed Rockwell PLCs worldwide

Forescout counted 4,407 internet-facing Rockwell Automation programmable logic controllers on 3 August 2026, including 2,844 in the United States. Its scan also located 22 exposed controllers in cities affected by recent cyber incidents involving US water utilities, although the company said it could not confirm that any of those devices had been compromised.
The figures describe reachable controllers, not the number of water utilities exposed or confirmed victims. Water and wastewater utilities in at least seven states have reported incidents since 27 July, the FBI and Environmental Protection Agency said in a 30 July public service announcement. Forescout’s post referred to at least 12 states, while the FBI page cited seven.
Public EtherNet/IP exposure creates a direct operational risk
Forescout said the publicly described outcomes did not require exploitation of a software vulnerability. Attackers changed controller IP addresses and set passwords on already reachable systems, causing operators to lose visibility and, in some cases, control of connected equipment. Neither government alerts nor Forescout’s analysis explains how targets were found, selected or initially accessed.
Exposing EtherNet/IP on port 44818 creates an unauthenticated route that may allow an attacker to identify a controller or write settings, depending on its configuration. More than 70% of the US-based controllers in Forescout’s results were found on large mobile carrier networks. A 30 July Censys snapshot identified 4,148 exposed Rockwell or Allen-Bradley EtherNet/IP hosts; Verizon Business, AT&T Mobility and T-Mobile USA represented 59% of that total. The two datasets use different tools, queries and dates, so their totals are not directly comparable.
Older MicroLogix devices require both recovery planning and isolation
MicroLogix 1400 devices represented 50% of Forescout’s results, while MicroLogix 1100 devices accounted for 8%. The FBI and EPA named both families. Nineteen of the 22 controllers found in affected cities ran firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow with a Rockwell CVSS score of 8.6.
The flaw affects MicroLogix 1400 Series B and C controllers running firmware 21.002 or earlier; Rockwell fixed it in revision 21.003. Exploitation requires Modbus TCP to be enabled, a condition Forescout could not verify on the exposed hosts. Rockwell discontinued MicroLogix 1100 on 30 April 2022.
Rockwell advisory SD1790 provides recovery instructions for operators locked out after an attacker sets a password: reset a MicroLogix 1400 or 1100 to factory defaults and reload a known-good project file. This need for trustworthy recovery materials echoes attacker-controlled changes exploiting operational access in environments where attacker-controlled changes can exploit established operational access, while the advisory also makes clear that an offline logic copy is essential.
Actions for utility and industrial operators
The FBI and EPA recommend strong authentication, modem updates and logging, with remote connectivity isolated through a private APN, VPN or comparable architecture. At least one victim identified modified PLC project files after finding ladder-logic discrepancies at several sites. Operators should therefore remove controllers from public exposure, retain current offline project files and examine shared third-party network arrangements that could repeat a successful intrusion across customers.

