Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Overview
Forescout has identified a significant number of Rockwell Automation programmable logic controllers (PLCs) that are exposed to the internet, with a total of 4,407 found globally. Among these, 2,844 are located in the United States, including 22 in cities that have recently experienced cyberattacks on water utilities. Notably, 19 of these controllers are using the same mobile carrier network. While Forescout's scan raised concerns about the potential risks, they could not confirm any instances of these devices being compromised. This situation is alarming as it highlights the vulnerabilities in critical infrastructure, particularly in areas that have already been targeted by cyber threats, raising questions about the security measures in place to protect essential services.
Key Takeaways
- Affected Systems: Rockwell Automation programmable logic controllers (PLCs)
- Action Required: Organizations should ensure proper network segmentation, implement firewalls, and regularly update their systems to prevent unauthorized access.
- Timeline: Newly disclosed
Original Article Summary
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed
Impact
Rockwell Automation programmable logic controllers (PLCs)
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Organizations should ensure proper network segmentation, implement firewalls, and regularly update their systems to prevent unauthorized access.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Critical.