Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-08 ยท updated: 2026-08-08 ยท tags: [incident, ics, ot, plc, critical-infrastructure, exposure, sector-energy] ยท confidence: high ยท affected_sectors: [energy, utilities] ยท au_impact: true

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout's scan (3 Aug) counted 4,407 internet-exposed Rockwell Automation PLCs worldwide (2,844 in the US), including 22 in cities hit by recent US water-sector attacks โ€” 19 on the same mobile carrier network.

Key Details

  • Source: The Hacker News
  • Date: 2026-08-06
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Nature: OT/ICS exposure in the water-sector attack campaign context

Summary

  • More than 70% of US-exposed controllers sit on large mobile carrier networks
  • Exposing EtherNet/IP on port 44818 creates an unauthenticated path letting attackers change IP settings or set passwords
  • Matches the no-exploit effect seen in the water campaign
  • Censys independently found 4,148 exposed Rockwell/Allen-Bradley hosts

Analysis

Relevant to Australian critical infrastructure: the PLC scan reinforces ACSC's ISP/OT cross-sector router and OT hygiene guidance. Also matters to NZ operators and utilities under the NCSC critical-infrastructure framework โ€” audit internet-facing OT.

Sources: raw/digests/Cyber-Digest-2026-08-08