Thousands of Rockwell Controllers Sit Exposed Online, With 22 in US Water Attack Cities
Security firm Forescout counted 4,407 industrial controllers reachable from the open internet, and found a small cluster in the same towns recently hit by attacks on water systems.

Key points - Forescout found 4,407 Rockwell Automation industrial controllers exposed to the open internet in an August 3 scan. - The United States accounted for 2,844 of those exposed devices, the largest share of any country. - Researchers spotted 22 exposed controllers in US cities that had recently suffered cyberattacks on water utilities. - Nineteen of those 22 devices shared the same mobile carrier network, suggesting a single contractor or vendor set them up. - Forescout could not confirm any of the exposed devices were actually broken into.
Security firm Forescout says thousands of the small computers that run water plants and factories are sitting on the open internet, where anyone can find them.
The company scanned the web on August 3 and counted 4,407 Rockwell Automation programmable logic controllers, or PLCs, reachable without a password prompt. A PLC is the industrial equivalent of a car's engine control unit: a hardened little computer that opens valves, starts motors and manages pressure on a schedule. Most of them, 2,844, were in the United States.
Why does this matter for water and power?
These are the boxes that physically move water and electricity. If a criminal or a foreign intelligence service can talk to one directly over the internet, they can, in theory, change how it behaves.
Forescout's researchers looked at US cities that had already reported cyberattacks on water utilities in recent months. They found 22 exposed Rockwell controllers in those same cities. Nineteen of the 22 connected through the same mobile carrier's network, a pattern that usually points to a single contractor setting them all up the same way, probably using cellular modems for remote access.
Forescout was careful about what it did not find. The firm couldn't confirm that any of the 4,407 devices had actually been broken into. Exposure isn't the same as intrusion. It just means the front door is visible from the street.
Who is Rockwell Automation?
Rockwell is one of the largest makers of industrial control equipment in the world. Its controllers, sold under brand names like Allen-Bradley, sit inside a large share of American factories and utilities. If you've drunk tap water in the US today, there's a fair chance a Rockwell PLC helped deliver it.
That scale is what makes the exposure numbers uncomfortable. The finding, first reported by The Hacker News, lands while US officials have been warning water utilities about state-linked hackers probing their networks. We've tracked that pressure since CISA flagged active intrusions on 30 July, and our 4 August report on the Minnesota attacks found hackers hit more than 30 small utilities in two days.
The numbers at a glance
| Figure | Detail |
|---|---|
| 4,407 | Rockwell PLCs exposed worldwide (Aug 3 scan) |
| 2,844 | Exposed devices located in the United States |
| 22 | Exposed devices in US cities recently hit by water utility attacks |
| 0 | Confirmed as broken into by Forescout |
Should ordinary customers worry about their tap water?
Not today, and not because of this report alone. Forescout found no evidence that any water utility's controller had been tampered with, and most US water systems have manual overrides and staff who'd notice odd behaviour quickly.
The bigger worry is the pattern. Small utilities often outsource their industrial IT to contractors who set up cellular modems for convenience, then move on. Those modems can end up quietly listed on search engines that catalogue exposed devices, waiting for someone curious to knock.
If you work for a utility using Rockwell gear, check whether any of your controllers are reachable from outside your own network. They shouldn't be. Put them behind a VPN or a firewall, and turn off any remote access feature you're not actively using.



