
Forescout found 2,844 MicroLogix PLCs in the U.S. directly accessible from the internet without authentication. Eight years of vendor warnings did not fix the exposure.
Alpha Score of 48 reflects weak overall profile with moderate momentum, weak value, moderate quality. Based on 3 of 4 signals – score is capped at 90 until remaining data ingests.
Attackers hit municipal water systems in at least 12 states beginning July 27, altering IP addresses and passwords on internet-facing programmable logic controllers. The FBI said at least one victim’s PLC programming was modified. Minnesota IT Services reported a coordinated attack against more than 30 water systems in that state on July 28.
Two days later, the FBI and EPA identified the hardware: MicroLogix 1100 and 1400 series PLCs, sold under the Allen-Bradley brand by Rockwell Automation. Forescout queried Shodan on August 3 and found 4,407 similar devices worldwide exposing EtherNet/IP on port 44818. Of those, 2,844 controllers were in the United States. More than 70% of the U.S. devices connected via mobile carrier networks behind cellular routers, apparently without a private access point name or a properly configured inbound firewall.
EtherNet/IP requires no authentication. An exposed port on the internet is an open door. Rockwell has told customers not to expose controllers directly to the internet – in September 2018, May 2024, and March 2026. Forescout found no confirmation of any common vulnerability or exploit. The problem was simple internet exposure.
The question is why nobody followed the vendor’s guidance. In one case, the customer is a town of 1,800 with no IT staff or network engineer. An integrator likely specified the connectivity scheme, installed the automation equipment, and handed over a working system. Nobody had an obligation to maintain and update the equipment in perpetuity. Nobody took corrective action.
This pattern spans the whole spectrum of industrial automation: legacy controllers, cellular gateways, remote access built by an integrator, no ongoing asset upgrades, and an operator with thin technical staff. You’ll find similar situations in factory automation, power generation and distribution, oil and gas, and the building systems that keep hospitals and datacenters alive. Forescout has published similar findings for solar inverters and serial-to-Ethernet converters.
The problem looks set to scale up. Many edge AI and robotics vendors now provide remote fleet management as a headline feature, through similar integrator channels, to operators with thin security staffing. These new edge compute systems are far more capable than PLCs, with a larger attack surface and a similar service lifespan.
Companies buying automation systems should nail down who owns each product’s network connections, remote access, security infrastructure, and long-term software maintenance over its 10- to 15-year life. For the massive industrial installed base, brownfield systems with weak security or wide-open ports belong behind solid firewalls with secure, authenticated access. That carries a cost. It’s cheaper than the alternative.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.