Thousands of Rockwell Controllers Sit Exposed Online, With 22 in US Water Attack Cities
Security firm Forescout counted 4,407 industrial controllers reachable from the open internet, and found a small cluster in the same towns recently hit by attacks on water systems.

Key points
- Forescout found 4,407 Rockwell Automation industrial controllers exposed to the open internet in an August 3 scan.
- The United States accounted for 2,844 of those exposed devices, the largest share of any country.
- Researchers spotted 22 exposed controllers in US cities that had recently suffered cyberattacks on water utilities.
- Nineteen of those 22 devices sat on the same mobile carrier network, suggesting a shared setup by a contractor or vendor.
- Forescout could not confirm any of the exposed devices were actually broken into.
Security firm Forescout says thousands of the small computers that run factories, pipelines and water plants are sitting on the open internet, where anyone with a browser can find them.
The company scanned the web on August 3 and counted 4,407 Rockwell Automation programmable logic controllers, or PLCs, reachable without a password prompt. A PLC is the industrial equivalent of a car's engine control unit: a hardened little computer that opens valves, spins pumps and starts motors on a schedule.
Most of them, 2,844, were in the United States.
Why does this matter for water and power?
Because these are the boxes that physically move water, sewage and electricity. If a criminal or a foreign intelligence service can talk to one directly over the internet, they can, in theory, change how it behaves.
Forescout's researchers looked specifically at US cities that had already reported cyberattacks on their water utilities in recent months. They found 22 exposed Rockwell controllers sitting in those same cities.
Nineteen of the 22 were connected through the same mobile phone carrier's network. That pattern usually means a single contractor or equipment vendor set them all up the same way, probably using cellular modems for remote access.
Forescout was careful about what it did not find. The firm could not confirm that any of the 4,407 devices had actually been broken into. Exposure is not the same as intrusion. It just means the front door is visible from the street.
Who is Rockwell Automation?
Rockwell is one of the largest makers of industrial control equipment in the world. Its controllers, sold under brand names like Allen-Bradley, sit inside a huge share of American factories, food plants and utilities. If you have drunk tap water in the US today, there is a fair chance a Rockwell PLC helped deliver it.
That scale is what makes the exposure numbers uncomfortable. The finding, first reported by The Hacker News, lands at a moment when US officials have been warning water utilities specifically about state-linked hackers probing their networks.
The numbers at a glance
| Figure | Detail |
|---|---|
| 4,407 | Rockwell PLCs exposed worldwide (Aug 3 scan) |
| 2,844 | Exposed devices located in the United States |
| 22 | Exposed devices in US cities recently hit by water utility attacks |
| 19 of 22 | Sharing the same mobile carrier network |
| 0 | Confirmed as broken into by Forescout |
Should ordinary customers worry about their tap water?
Not today, and not because of this report alone. Forescout did not find evidence that any water utility's controller had been tampered with, and most US water systems have manual overrides, chlorine checks and staff who would notice odd behaviour quickly.
The bigger worry is the pattern. Small utilities often outsource their industrial IT to contractors who set up cellular modems for convenience, then move on. Those modems can end up quietly listed on search engines that catalogue exposed devices, waiting for someone curious to knock.
If you work for a utility using Rockwell gear, the practical step is to check whether any of your controllers are reachable from outside your own network. They should not be. Put them behind a VPN, a firewall, or both, and turn off any remote access feature you are not actively using.



