Recent cyber threats targeting U.S. water and wastewater facilities have highlighted the widespread exposure of industrial controllers accessible via the internet. A Forescout study has revealed that 4,407 Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) are openly reachable online, using port 44818, the EtherNet/IP protocol. A significant 65% of these devices are found in the United States, with Canada hosting 12% and Spain 3%.
Current Exposure and Historical Trends
The current number of exposed devices represents a decline of 47% from a previous high of 7,814 in March 2020, reaching a low of 4,169 by June 2026. Despite the reduction, the level of exposure continues to pose a serious risk to essential infrastructure, making them susceptible to cyber intrusions.
On July 28, a coordinated cyberattack affected more than 30 water systems throughout Minnesota. Although water quality remained unaffected, operational disruptions were reported in cities such as Plymouth, South St. Paul, Maple Plain, and Braham. Braham experienced control shutdowns due to malware, while Plymouth’s equipment issues stemmed from connections through cellular routers.
Scope of Cyber Threats and Affected Devices
By July 30, the FBI and EPA issued a joint warning about similar attacks across 12 states since July 27, including Michigan, South Dakota, and Georgia. The attackers specifically targeted Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs, causing issues like pressure drops and potential flooding, which could lead to groundwater contamination in drinking supplies.
MicroLogix 1400 PLCs make up about 50% of these exposed devices, followed by CompactLogix 1769 at 22%, with MicroLogix 1100 and ControlLogix 5590 each at 8%. Notably, over 70% of the U.S.-based controllers are linked to large mobile networks via cellular routers, mirroring the access points mentioned in the advisory.
Recommendations for Mitigating Risks
Security experts recommend disconnecting PLCs from the internet, disabling unused services like SNMP, and enforcing strict allowlists for Modbus TCP and port 44818. Cellular gateways should transition to private carrier APNs or VPNs, with public administration disabled, and remote access should be secured with individual accounts and multi-factor authentication.
Organizations are advised to upgrade MicroLogix 1400 firmware and prioritize replacing the discontinued MicroLogix 1100 models. Secure remote access (SRA) gateways, which isolate user sessions from direct protocol access, can offer additional protection while facilitating necessary remote operations.
Ensuring robust cybersecurity measures is crucial for safeguarding water systems, and organizations must act swiftly to address existing vulnerabilities and protect these critical infrastructures from escalating cyber threats.
